Join our Newsletter — 33% off our NHI Course

Kong Developer Summit 2026 in Los Angeles: what IAM teams should watch

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Keynotes, workshops, and technical sessions will come together in Los Angeles from September 30 to October 1, with certification training starting September 29 and limited seats for the full experience, according to Kong. For identity teams, the real value is seeing how API, workload, and agent-access patterns are being packaged for builders rather than governance owners.

Editorial analysis by NHI Mgmt Group, based on content published by Kong: “# Venue”.

By the numbers:

  • The full experience pricing runs from $249 in Early Bird to $549 in Last Chance.
  • The certification training add-on is limited to 100 seats.

Key questions

Q: How should IAM teams govern API access patterns that are designed for developers first?

A: Treat developer-facing API patterns as identity design decisions, not just application plumbing.

Q: What breaks when workload identities are not lifecycle-managed?

A: Ownership becomes unclear, credentials linger after the original use case ends, and access reviews lose meaning because they are checking entitlements that no longer match reality.

Practitioner guidance

  • Map summit-era API patterns to your identity control baseline Review whether the API and token patterns likely to be discussed would fit your current authentication, authorisation, and logging standards, or whether they create exceptions that need explicit governance.
  • Classify workload identities by lifecycle owner Assign clear ownership for issuance, rotation, reuse, and retirement of service and application identities so the deployment pipeline does not become the de facto governance model.
  • Separate autonomous behaviour from ordinary automation Use a classification rule that distinguishes governed workload activity from systems that independently choose actions and timing, so controls are applied to the right actor type.

Bottom line: This summit is relevant to IAM because it surfaces how API, workload, and agent-access patterns are being operationalised for builders before governance teams have fully standardised them.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 9 hours ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21503
 

Developer conferences are governance events in disguise. The access models normalised in builder communities often become the default control assumptions later seen in production systems. That means IAM teams are not just governing current behaviour, they are also reacting to patterns already taught, copied, and scaled by engineering organisations. Practitioners should read summit agendas as indicators of where identity risk will emerge next.

A few things that frame the scale:

  • The average estimated time to remediate a leaked secret is 27 days, despite 75% of organisations expressing strong confidence in their secrets management capabilities, according to The State of Secrets in AppSec.
  • Only 44% of developers are reported to follow security best practices for secrets management, exposing a significant developer behaviour gap.

A question worth separating out:

Q: What should organisations do after a summit focused on platform engineering and access?

A: They should convert the event’s themes into review items for service accounts, secrets, and privilege scope. The most useful outcome is a short list of patterns that need policy, ownership, or lifecycle control before they become default practice across environments.

👉 Read our full editorial: Kong Developer Summit 2026 in Los Angeles: identity implications



   
ReplyQuote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21503
 

Developer conferences are governance events in disguise. The access models normalised in builder communities often become the default control assumptions later seen in production systems. That means IAM teams are not just governing current behaviour, they are also reacting to patterns already taught, copied, and scaled by engineering organisations. Practitioners should read summit agendas as indicators of where identity risk will emerge next.

A few things that frame the scale:

  • The average estimated time to remediate a leaked secret is 27 days, despite 75% of organisations expressing strong confidence in their secrets management capabilities, according to The State of Secrets in AppSec.
  • Only 44% of developers are reported to follow security best practices for secrets management, exposing a significant developer behaviour gap.

A question worth separating out:

Q: What should organisations do after a summit focused on platform engineering and access?

A: They should convert the event’s themes into review items for service accounts, secrets, and privilege scope. The most useful outcome is a short list of patterns that need policy, ownership, or lifecycle control before they become default practice across environments.

👉 Read our full editorial: Kong Developer Summit 2026 in Los Angeles: identity implications



   
ReplyQuote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21503
 

Developer-first identity programmes are setting control expectations before governance teams formalise them. Summits like this are useful because they expose which access patterns are becoming default implementation choices in the field. By the time those patterns appear in policy decks, the technical assumptions are often already embedded in code and platform design. The practitioner conclusion is simple: governance has to engage earlier in the build lifecycle, not after the access model is already live.

A question worth separating out:

Q: How do identity teams keep builder-led access patterns from outpacing governance?

A: By reviewing new implementation guidance before it becomes default practice, and by requiring explicit ownership for any credential, token, or workload identity pattern that is introduced through developer tooling or workshops.

👉 Read our full editorial: Kong Developer Summit 2026 in Los Angeles: identity implications


This post was modified 9 hours ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.