API keys in Slack threads. .env files committed to forks. Service accounts with overly broad permissions spun up faster than security teams can review them. These are not edge cases. They are the default state of secrets management at most engineering organizations, and AI agents are accelerating every one of these failure modes simultaneously.
In this interview on TFiR, Amber Britton, CEO at Doppler, breaks down how secret sprawl forms, why agentic workflows are collapsing legacy assumptions around provisioning and scoping, and how Doppler provides a single secrets control plane that covers the full credential lifecycle without creating friction for developers.
Guest: Amber Britton, CEO at Doppler
Show: TFiR
Here is what every platform engineer, DevSecOps practitioner, and engineering leader needs to know.
Technical Deep Dive
Q: What is Doppler and what problem does it solve?
Amber Britton, CEO at Doppler, explains that Doppler is a cloud-based secrets management platform that has been focused on solving this problem for developers for approximately eight years. The core problem it addresses is not that teams lack a place to store secrets, but that secrets end up scattered across Slack threads, email chains, .env files, and disconnected tools, creating what Doppler calls secret sprawl. Doppler provides a single control plane that sits on top of wherever secrets are stored, managing the full lifecycle including provisioning, rotation, access control, and audit logging.
“The problem is that people have an ‘all my secrets are everywhere’ problem, which is what we call secret sprawl.” — Amber Britton, CEO, Doppler
Q: How does secret sprawl form and why does it get worse over time?
Britton explains that no team sets out to manage secrets badly. The problem accumulates incrementally: a new hire asks for a key over Slack, config drifts between staging and production, a secret gets accidentally committed and revoked but remains in a fork. Without a central source of truth, each of these small failures compounds. The problem becomes visible only during a security incident, which is the worst possible moment to begin untangling it.
“No one actually sets out to do secrets management badly. It’s something that happens over time. The problem just starts to sprawl.” — Amber Britton, CEO, Doppler
Q: Why should teams use a dedicated secrets management platform instead of handling it themselves?
Britton argues that without a dedicated solution, engineering teams gradually become de facto secrets management companies, diverting time and talent away from their actual product. She cites a customer case study in which Ada, an AI customer service company, had begun spending disproportionate engineering resources on secrets management until it displaced work on their core product. A dedicated platform allows teams to reclaim that time and rely on specialists to handle the complexity.
“We are not a secrets management company. We are an AI customer service company.” — Amber Britton, CEO, Doppler
Q: How does Doppler actually work for day-to-day developer workflows?
Britton describes a project-environment-config structure that mirrors GitHub’s repository model, making it immediately familiar to developers. Teams import secrets from existing sources, including .env files and cloud provider vaults, via sync integrations. Developers then use the Doppler CLI or VSCode extension to inject secrets at runtime without directly exposing the values. Granular roles and permissions, group management, and integrations with identity providers allow team leads to control exactly who has access to what, and the UI provides full visibility into that access without requiring developers to interact with it daily.
“For the day-to-day developer, you just get to work how you want to work and you’re injecting those secrets as you need them.” — Amber Britton, CEO, Doppler
Q: What compliance and audit capabilities does Doppler provide?
Britton explains that Doppler captures full audit logs including who read a secret, the IP address, and the device used. Change request workflows make every addition, deletion, and modification to a secret visible as a diff and logged for compliance review. These logs can be exported to any external provider. For sharing secrets securely between team members, Doppler Share generates auto-expiring links accessible through a Slack integration built into the product.
“Every who read a secret, what IP they read it from, what device it was on, all of that is in our logs.” — Amber Britton, CEO, Doppler
Q: How is Doppler different from AWS Secrets Manager and other cloud-native secrets tools?
Britton does not position AWS Secrets Manager or GCP Secrets Manager as direct competitors. Instead, Doppler integrates with them: teams that have already invested in those tools can connect them to Doppler, which then treats the cloud provider vault as a read replica while Doppler becomes the authoritative management layer. She notes that cloud-native tools do not address multicloud environments or local development workflows, and that many dedicated competitors are either too complex to maintain without a dedicated internal team or not designed around individual developer workflows.
“You’re likely not a single cloud company. You want to be able to use secrets in local development, and that wouldn’t be possible with AWS alone.” — Amber Britton, CEO, Doppler
Q: How does Doppler’s pricing model reflect its approach to agentic use cases?
Britton explains that Doppler charges per human seat only. Machine identities, including service accounts used by AI agents, are not charged. A team of 50 developers pays for up to 50 seats and can create unlimited agentic service accounts at no additional cost. Service accounts for agents are configured with OIDC support within the product.
“You can spin up all the agentic use cases you want. We don’t charge for machine identities.” — Amber Britton, CEO, Doppler
Q: How has the rise of AI agents changed secrets management?
Britton identifies two core assumptions that agentic workflows break. First, provisioning was historically human-paced, meaning access requests moved slowly enough for security teams to review them. Developers can now spin up dozens or hundreds of agents in an afternoon, outpacing any manual governance process. Second, scoping previously relied on reading code to determine which service needed access to what. Agents determine what they need at runtime, which leads teams to grant overly broad access so agents are not blocked, creating a significantly larger blast radius if something goes wrong.
“The agent decides what it needs at runtime. What results is people giving agents really broad access so it doesn’t get blocked and can do its job.” — Amber Britton, CEO, Doppler
Q: Why can’t you remove a secret from an AI agent’s context window, and why does that matter?
Britton explains that once a credential is passed directly into an agent’s prompt or context window, it persists in that session’s logs indefinitely. There is no mechanism to revoke it from the context the way you can rotate or delete a secret from a vault. This makes direct credential injection into agent contexts a permanently elevated risk. The recommended approach is to avoid giving agents long-standing credentials directly, instead using just-in-time, narrowly scoped access that does not persist in prompts.
“You can’t unprompt a secret. Once it’s in their context window, it’s in there forever and it’s going to be in those logs.” — Amber Britton, CEO, Doppler
Q: What is the security risk posed by MCP servers and why is it being overlooked?
Britton warns that nearly every software vendor now ships an MCP server, and teams are connecting them without treating them as new integrations requiring their own security review. The original vendor review covered the base product, not the MCP server’s access scope. Because MCP servers can connect to systems and grant access to data that the base vendor integration never touched, they represent a new and distinct attack vector. Britton states that her own default at Doppler when an MCP server installation is requested is either extensive questioning or a flat refusal until the risk is fully understood.
“We should be treating MCP servers like new integrations because they are now being connected to systems and giving access that didn’t happen before.” — Amber Britton, CEO, Doppler
Q: What is the current state of machine identity governance and where is it headed?
Britton observes that human identity management has benefited from a decade of investment, regulation, and security compliance tooling, while machine identity has been treated as an afterthought, often consisting of credentials dropped into a vault and left static. Attackers are increasingly walking through unlocked doors by logging in with valid, long-standing machine credentials rather than forcing entry. She expects machine identity to enter the same regulatory scrutiny and compliance maturity cycle that human identity management has already undergone.
“Human identity has had a decade of investment and lots of regulation. We’re going to start to see the same thing around machine identity.” — Amber Britton, CEO, Doppler
Q: How should teams govern AI agents the same way they govern human team members?
Britton argues that agents require the same operational rigor applied to human employees: monitoring logs, understanding what each agent can access, setting policies that prevent unauthorized privilege escalation, and reviewing alerts when unusual behavior occurs. She points to a recent breach in which one agent convinced another agent to grant it elevated access, which would have been preventable with proper activity monitoring and access policies in place.
“You have to give agents the same rigor you would with human seats, monitoring what they’re doing and what’s happening.” — Amber Britton, CEO, Doppler
Q: How do you make the business case for secrets management investment internally?
Britton recommends two angles. The first is breach evidence: publicly documented incidents caused by leaked credentials provide concrete proof points that leadership can evaluate against their own risk tolerance. The second is developer productivity: Doppler customers have quantified and eliminated the time spent onboarding and offboarding engineers, tracking down credentials, and managing access manually. She also notes that vendor security posture matters, and that organizations should verify whether their own vendors have a secrets management solution in place, since a vendor breach can expose customer data.
“There’s a huge developer productivity time savings. Teams have quantified what it took to onboard new engineers and were able to drop that to nothing.” — Amber Britton, CEO, Doppler
Q: How does Doppler serve teams in regulated or compliance-heavy industries?
Britton explains that historically Doppler was cloud-only, which excluded organizations that required secrets to remain within their own infrastructure for compliance reasons. Following sustained demand from regulated industries, Doppler released a self-hosted, on-premises version in June. This allows organizations in heavily regulated sectors to use Doppler’s management capabilities while keeping secrets inside their own infrastructure perimeter.
“We had a barrage of requests from folks in those industries loving what we do but needing a self hosted version. So we created that back in June.” — Amber Britton, CEO, Doppler
Q: Does Doppler offer a free tier, and who is it designed for?
Britton confirms that Doppler has always maintained a free entry point and plans to keep it. The free tier is intentionally designed for students learning to code and developers with personal or side projects. The reasoning is that it is better to establish good secrets management habits from the start of a developer’s career than to remediate bad practices later. As those developers join or build funded startups with larger teams, Doppler offers additional feature tiers that address the more complex problems that come with scale.
“I’d rather you code with a secrets manager and learn how to do that at the beginning than later.” — Amber Britton, CEO, Doppler
Resources & Documentation
- Doppler, secrets management platform for teams, with CLI, VSCode extension, sync integrations, audit logging, and on-premises deployment options
- Doppler Share, free tool for sharing any piece of sensitive data via auto-expiring, access-controlled links
- Doppler Documentation, official docs covering CLI, OIDC service accounts, integrations, roles and permissions, and change request workflows
***
👇 Click to Read Full Raw Transcript
Swapnil Bhartiya: Now, when it comes to security, you may think that your biggest security risk is a clever attacker, but in most cases, it’s your own API keys sitting in some slack message or a forken .env file. We have all done it and actually we continue to do that. And now when we start using AI agents to write code, deploy code, clean the code, they make things even worse because every agent needs credentials. And then they multiply, they hallucinate it, they will leave it somewhere, they will save it. Some, sometimes they will warn you, but they are also kind of becoming part of the problem. Which also means that the attack, attack surface or to be able to track is also getting bigger and bigger. And by the time you notice a leak, the damage is already done. Now Doppler is here to give teams one secure place to manage every secret. And today we have with us Amber Britton, CEO of Doppler, to break it down for us. First of all, Amber, it’s great to have you on the show.
Amber Britton: Thank you so much. I’m really excited to be here.
Swapnil Bhartiya: Same here. And this is, to be honest with you, this is not problem specific to the security team. It is actually everybody’s problem because the credential, they are part of what we do today. Before we talk about what do you folks do, what problem you’re trying to solve, I want to understand the problem area that it comes to or if possible, or if you are interested, tell a bit about the company itself. Talk about your own background because this is the first time I’ve talked to Doppler and since this is a serious problem. So I also want our audience to know who we are talking to today.
Amber Britton: Yeah. Yeah. Well, as you said, I’m amber. I’m the CEO of Doppler. My background is for over 10 years I’ve been in startups. I’ve been at Doppler for several of those years. But, but my background is all in product management and in marketing. And so product growth kind of became my sweet spot, which is how I came to Doppler and over a few years of our growth and things that I was doing here, that led to me kind of taking over the CEO role.
Swapnil Bhartiya: Awesome. Thank you. Can you now talk about Doppler, what they are doing? How old is the company? Did they start with solving this problem or they started solving another problem? But as the, the industry market is evolving because of AI, they are focusing on credential security. Talk about the evolution of the company.
Amber Britton: Yeah. So Doppler is about 8 years old and we’ve always done this We’ve always been focused on solving secrets management for developers. And to that end to what you said kind of before on, you know, Secrets isn’t just like company problem, it’s all developers have this problem. It’s why we always and as far as I, I plan to always have a free entry point for students learning how to code. I’d rather, we’d rather you code with a Secrets manager and learn how to do that at the beginning than, than later. And developers have a lot of hobby projects, there’s people aside projects and so we always want you to have a free place to be able to store and manage your secrets. And then when you become a, you know, startup gets funded, you start taking it off and getting a bigger team. There’s different features and different, you know, sets of problems that you’ll have to solve that we want to be there to do. But we’ve always been a secrets management platform. We’ve always been a cloud based secrets management platform. That’s that shifted recently. We now have an on prem version as we’ve moved up market. But the basic problem we solve is that to your point, every team, every person, but focusing on teams has credentials somewhere. You’ve got them in .env files, they might be in Slack threads or emails or this tool or that tool. And not everyone has has a single place to manage them. And when you don’t want to encounter that problem is when you’re having the worst day of your life in the event of some sort of a breach. That’s when you don’t want to have to figure out where did this credential come from? Where, how do I rotate it? Who all has access? Where is it going to break? Having a place to let you fully manage the kind of this control plane that sits on top of wherever you’re storing them, storing them as part one. But then having a way to manage the life cycle of that secret for everyone that’s supposed to have access to makes that potential disaster much easier to deal with and much less of a headache and probably one that doesn’t happen in the first place. And I think to another thing you said earlier. We typically are focused on the developer experience and selling into our being a product that developers use. But lately agents are starting to outnumber individual developers and that’s definitely changing the game a little bit in how Secrets are used. But we pride ourselves on being kind of the security tool that engineers actually love to use.
Swapnil Bhartiya: We all need credential secrets and sometimes managing it does become challenge. Most cases it Becomes a big mess. And sometimes organizations, teams, they look for solutions and sometimes market is overwhelming solution. We always, you know, vet one solution, other solution. But this is something, you know, sometimes it becomes sticky once you have moved a secret somewhere. You don’t want to keep moving it, you know, around because it becomes once again the fragmented mess. Can you talk about the importance of teams that why they should have dedicated platform for managing secrets versus a whole fragmentation?
Amber Britton: Yeah, I think you know when you think about a solution like us, you think that the problem is I don’t have a place to put secrets and that’s not necessarily the problem to solve. The problem is that people have a all my secrets are everywhere problem which is what we call a secret sprawl. So somebody’s onboarding on the team and they’re slacking like hey can I get this key for this or this key for that? And so you’re giving those via slack or email and then you’ve got config drift between staging and production because things are changing. Or maybe someone manually accidentally committed a secret and that gets pushed and then revoked but it’s still in a fork somewhere. And without like that, that central place that everything is coming from, that problem just gets worse and worse. I no one actually sets out to like we want to do secrets management badly in our team. That’s not anyone’s goal. It’s something that happens over time. It just this problem just starts to sprawl and all of a sudden there’s some incident or event or security issue that really sheds light on it in a way. You don’t want there to be light shed on a problem like that. So it’s about solving it before it gets there. But most organizations have this problem in some way and they come to us when it’s like we’re spending too much time and energy trying to solve this and that’s taking away from our core competency of whatever product we serve. One of our customers Ada said in a case study to us, they said for about themselves we are not a secrets management company. We are an AI customer service company. And they had started to become a secrets management company because they were spending so much time trying to solve this problem. Right. So that that’s a big reason why it’s better to have a dedicated solution this so you don’t have to become and continue to be the expert in
Swapnil Bhartiya: this other thing as you rightly mentioned. And we have done it ourselves. Somebody, an employee quickly needs something you will share the key secret credentials on Slack or whatever messages and now it is there. Now you cannot revoke that message. It is out there. Talk a bit about how does Doppler actually work? How are no keys shared, managed? Who I mean, who has access to it? Also revoking a key can also break a lot of services as well. You cannot just turn it off. So can you just if possible, talk a bit about the inner working? So when developers secure teams, they look at it, they’re like, you know what, that does make sense.
Amber Britton: Yeah, I think that kind of goes into what makes us different and makes us unique is our approach is very much centered around the developer experience and how they work. There’s a lot of security tools that are meant to be used by developers but aren’t built for them. Built for some security executive who wants a dashboard and then to use it is cumbersome and engineers are an efficient group of folks and they are going to find a way around it if it is painful and difficult to use. So we pride ourselves very much on the developer experience and that extends all the way to. Even our pricing is very clear and easy to understand. You don’t need some complex calculator.
Swapnil Bhartiya: So the.
Amber Britton: But the way it works is especially. I’m going to talk about more about like when it’s set up and working properly, you know, you can import all of your secrets into Doppler. So we will write to wherever you want to read from. But at first you can set up all the syncs. We have integrations with all the providers you would expect. You can set up all of your syncs to populate secrets from wherever you have right into Doppler. You can import .env files and then you can, you know, there’s lots of granular roles and permissions, but we follow like a project environment config structure very similar to, you know, how GitHub mirrors their repo structure. So it’s very familiar to developers from day one. Usually you’re going to set up your projects in terms of like different applications or different services. Every company does it different. Some can have hundreds and hundreds of projects, but you’ll set those up, you’ll set your syncs up and then you’ll bring your team in and you can have really granular roles and permissions per team. You can have groups. You can also integrate with, you know, different providers to just like auto import whatever users you want and assign them access to the secrets that they need. Most people aren’t going to be in the Doppler UI every day. Maybe like you’re manager of Your team is your leader of your team to configure access or make sure things are rotated. But the end user is going to likely download our cli, maybe our VScode extension, connect their accounts, you know, make sure that they’re all connected to GitHub and they’re going to inject secrets at runtime so that they are working on whatever they’re working on. They’re building out your product and they’re just injecting secrets as they need them without ever needing to see the secret for those that need to see it. You can definitely do a lot of pretty much everything through our cli. But you can also go into the product. You can create service accounts for agents, use cases configured with oidc. You can set up a change request workflow so that any addition deletion change to a secret, that whole diff is visible and logged. For compliance reasons. You can take all of our audit logs which track every who read a secret, what IP they read it from, like what device it was on, all of that is in our logs. For compliance reasons you can port all of that to whatever provider you like, which is really good for your security teams to have in the event that you need any of that. But for the day to day developer, you just get to work how you want to work and you’re injecting those secrets as you need them. And then for your team lead, for your security lead, for your head of engineering, you’re able to make sure that secrets are regularly rotated, that stale configs are removed or provisioned. If you need to share a secret with someone else who might not have access, we have Doppler share built into the product which is basically a free tool that we offer anyway outside of our product to share any piece of data securely. But we have a Slack integration for that and that is built into the product itself. So if you go to share a secret, it’s not just in Slack. You have to have access to that link and it auto expires and there’s some other criteria around that and that’s, that’s overall, that’s the gist, that singular place to use secrets as you need them. But then to also fully understand who has access to these immediately provision, immediately deprovision and rotate everything someone touched. When you deprovision, make sure the right people have access at the right time and that everything is logged for compliance reasons.
Swapnil Bhartiya: And how is your approach different from your competitors? Because this secret management is, you know, even whether it’s your aws, big cloud providers Also offer it and then there are specific player. They are one password. I mean there are so many players in this space. How is your approach different? And as you also mentioned it’s more focused on understanding not only developers pain point but also how clever developers are that you know, they want to find the easiest solution, easiest way to solve a solution and sometimes it can lead to some compromises. So talk about your approach and how is it different from others.
Amber Britton: Yeah, it really is that developer experience that from the moment you like interact with our marketing it goes all the way from that beginning. Right. We I don’t ever want someone to read one of our landing pages on our marketing site and be like I have no idea what that I just read. Like we don’t want it to be fluffy and verbose for no reason. We want to speak to developers, use the terminology that they use be in the places that they operate in that they want to discover tools in. And once you sign up for the product that’s really evident right away. So that is a really important concept. And there are lots of competitors out there agentic use cases. I feel like everyone’s trying to vibe code a new solution to another software every day. There’s a cost to that, to maintaining those for sure. And I am the first one to tell you if that competitor is better for you. I’m not going to try to force someone to use Doppler if it’s not a good fit for them and they wouldn’t be happy here. In terms of AWS Secrets Manager, we have a lot of companies that come to us and they’re like oh, I’m using AWS Secrets Manager or GCP Secrets Manager. I don’t consider them competitors. We integrate with them. Some people have done a lot of work to set those up and want their security team wants them to be using the way that was set up and that’s fine. We can connect with AWS Secrets Manager because you’re likely not a single cloud company, you’re likely multicloud and and you want to be able to use Secrets in local development so you can integrate with AWS Secrets Manager, pull all those secrets into Doppler. That AWS instance now becomes a read replica. We’ll keep that up to date. But Doppler becomes the place that you update and change and like manage your secrets day to day and your team that has access to those secrets along with all of the other places that you have secrets that wouldn’t be possible with AWS and some of the other tools that are out there that are competitors to us are just not built for the individual developer. They’re not built for their workflows and they’re not as flexible to their workflows or they’re really expensive to maintain. But if you’ve got your organization has the money to spend and wants to have more complex product that has a dedicated team that they hire to just maintain that piece of software, by all means, if that’s a better solution for you, go for it. We pride ourselves on being a tool that you don’t need to have that for. You get to invest that money and staffing back into your own company and feel really confident in our approach handling that for you. And like I said, it extends to our pricing. Even being per seat, like human seat, we don’t charge for machine identities. So if you have 50 developers, you need 50 seats. Right. And you may not even need all 50. But typically if they need to ingest secrets, they need a seat. And you can spin up all the agentic use cases you want. We don’t charge for machine identities.
Swapnil Bhartiya: Excellent. Thank you. And since that’s a perfect segue that as, I mean you also mentioned that companies are wipe coding and everybody’s coding. There are pros and cons for that. But it has also changed the whole secret management because of the rise of AI agents agency. Unlike humans, you know, agents can just be all over the place. How has the kind of rise of AI agents impacted your market, your space, your approach to secrets management?
Amber Britton: Yeah, it’s definitely been an interesting point of conversation here at Doppler since it was really start for starting to pick up. Machine identities are outnumbering humans and a crazy, a crazy amount. I think it was like 42 to 1 and then 82 to 1. I’m sure it’s higher now. And I was reading something the other day, I think it was something from Gartner that predicted by 2028, so that’s what, a year and a half from now, that AI agent like abuse attacks or breaches as a result of abuse were going to be about one quarter of all breaches. And that’s pretty frightening because agents essentially are just breaking them. They’re breaking some of the assumptions that we made about secrets. One of those being provisioning is human paced. You used to have to like open a God forbid JIRA ticket to get access to a service account or get a service account created. But now a developer can spin up like a hundred agents in an afternoon. And the agentic use cases, there’s a lot of pressure from on top at organizations to use AI more and be more productive. And that is happening faster than security teams are governing access and understanding what’s happening there. So making sure that you’re doing that in a secure way is really important because the other thing that breaks is like scoping. We used to think that you could scope permissions by reading the code and who needs access to what part of it. Right. And that doesn’t work for agents because the agent decides what it needs at runtime. And so what results is people giving agents really, really broad access so that it doesn’t get blocked and can do its job. But now that’s even if you’re prompting it to like please don’t do this thing, it has access to do that thing and eventually it’s going to go do that. So being able to know what’s happening there and when something is happen happening and who, what user that’s attributed to like that’s really, really important. That is definitely changing the game. And then now there’s like another place that you didn’t initially think about where there is a new like potential leak or attack vector. Because you can’t unprompt a secret. You can’t, you can’t remove that from a prompt with an agent. So once it’s in their context window, it’s in there forever and it’s going to be in those logs and you can’t get rid of that. So knowing how to not give it that access directly, not to give it a direct credential is really important. Or give it much more scoped just in time type of access so that it doesn’t have this long standing access. Those things become more and more important
Swapnil Bhartiya: now beyond of course we talked about the whole evolution of AI and how developers are working. What are some other trends that you are seeing in cybersecurity security space that you think think that teams who are managing secrets credentials they should be aware of?
Amber Britton: Yeah, I think one, it happens here at Doppler 2 is actually just happening before I jumped on here, everybody, every product has an MCP server now. And when we vet software to bring into an organization you’re typically have, you know, you typically have some sort of security process security review for that vendor. And it’s, but it’s based on your general, you know, original use of that vendor. Now that all of these vendors have MCP servers, there’s this, there’s this push to connect them and get access to them and how it would help you be faster or whatever. And that isn’t being treated any differently. You’ve got the first initial review done on the vendor, you’ve been using it for a while. What’s the deal with the MCP server? So those are growing, that usage is growing. But we should be treating those like new integrations because they are now being connected to systems and giving access to different systems. That didn’t happen before and that now makes them a potential bigger risk. So my like this happens now and there’s not review processes specifically to MCP servers at all companies other than that initial vendor one. And it happens here at Doppler when someone will ask for, you know, us to allow an installation of an MCP server. My default is a lot of questions or no. Because I want to make sure we understand what we’re about to do here and is there a potential risk that we need to be aware of. And I don’t think that’s being talked about enough at orgs and that’s going to start to be a lot more locked down and scrutinized. And I think the other one is just about machine identities being getting more mature, that whole process. If you think about like password management, I don’t think we’re not seeing so many instances of hackers or attackers like breaking the door down anymore and getting in. They’re now just like logging in with valid credentials that they found that still work and kind of just walking through the unknown unlocked front door. And human identity has had a decade of investment and lots of regulation around that, lots of security compliance. We’re going to start to see the same thing around machine identity for sure. Because we, machine identities were just like, I guess you just put them in a, in a storage solution in some sort of a vault and call it a day. And we’re not thinking about the long term effects there. So I think we’re going to start to see a lot of regulation.
Swapnil Bhartiya: And how different is, you know, when you look at machine identity versus actually agents get their own identities and permissions just like people do. Because that, I mean in most cases people are, organizations are treating agents as employees.
Amber Britton: Yeah, they, they definitely need to have watch over them. You need to be monitoring logs and understanding what it can do and what it’s able to access and what can it give access to itself. That, that was something that recently came out I think in one of the breaches where the agent asked another agent and convinced it to give it access. Right. So that’s going to happen more and more if you’re not tracking exactly what’s happening if you’re not on top of what those agents are doing, looking, setting up, alerting and having policies around making sure it can’t do that or you’re at least reviewing what’s happening there. You have to give it the same rigor that you would with human seats with those on your team where you’re going to be monitoring what they’re doing and what’s happening there. You have to have that same rigor
Swapnil Bhartiya: around machines depending on who you talk to. Some organizations, some teams take it very very seriously. The whole secrets management some teams like this is okay. We are not if there is a team organization who is like you know what we need to get really serious about it before it becomes a big problem. What is your advice? Of course they can sign up with Doppler but what is your advice to because this is also not just a solutions technical problem. It also goes back to the the whole culture problem because that’s how you share things like sharing on Slack or putting something in the file. So it is also more or less like a process and culture problem as well. What advice would you have for the team or the organizations that this is how you should get started?
Amber Britton: I think one you have a lot of evidence that you can use. So secrets. Doppler is definitely an early adopter. Secrets management was a product that people knew there was a problem they wanted to solve but there were other problems that were more top of mind to solve. And now you can point to so many breaches that are the result of a leaked secret that gave someone backdoor access to something they shouldn’t and a solve for that is rotating those secrets. But it’s impossible to do if you don’t know where they all are and can’t easily do that. Some organizations rotation can take years, you know just to track all the instances down and make sure it’s provisioned right can be a crazy labor of love. So you can point to a lot of those breaches and want to make sure that doesn’t happen to you. So you want to make sure your stuff is locked down and you don’t have every industry is affected by this. If you build software you need to be concerned about this. If you have an engineering team you have secrets and you should also be concerned about your vendors. Do your vendors have a secrets management solution because that could give them the key to something that affects your data and so you want to make sure that they’re using some sort of solution and and can respond quickly in the event there is an issue and that they’re regularly rotating secrets. But internally I think you can use a lot of the breach results that have happened as some proof points of why you should do it because you don’t want to be in the news. And then there’s a huge developer productivity time savings. We have lots of case studies from our customers around that specifically the amount of time it took to onboard new engineers, offboard engineers, the amount of time they were spending tracking down credentials like we have teams that have quantified that and were able to just drop that to nothing which was way more time they’re spending on their current product made their team much more efficient and productive. That’s another huge win that you can add to that. But it’s kind of like sometimes it’s like insurance right you’re the biggest payoff is not having a breach as a result of a secret and that may, you may never see the direction, you know monetary value of that but you’ll. Because you’ll never have a breach. But so there’s also the developer productivity case you can make and get started is just like play around with some of the solutions that are out there and find one that works for your team and your workflow.
Swapnil Bhartiya: There’s also possibility that you not possibility in most cases it may be possibility that some of your customers client they also operate in heavily regulated industries or compliance industry. How, how do you meet those those requirements?
Amber Britton: Historically we didn’t if you were in like a really heavy regulated industry, you didn’t want any, you didn’t want secrets to live outside of your infrastructure. So you typically wanted a self hosted solution. And so historically we just didn’t go after those those industries. We’ve recently, you know, just had a barrage of requests from folks in those industries wanting to use Doppler, loving what we do but but needing a self hosted version. So we did create that back in June and now we are able to work with those more regulated industries who have that requirement and we are here to handhold them kind of through the process and we can meet their needs now.
Swapnil Bhartiya: Amber, thank you so much for joining us and sharing these insight with us. Of course everybody’s moving towards AI AGI agendas so this is being becoming a serious problem and Doppler is solving this problem. Thank you so much and folks for watching. Please if you want to learn more about Doppler and how they can solve your secrets management problem, please go check doppler.com and once again Amber, thank you so much and I look forward to chat with you again.
Amber Britton: Thank you so much. It was great to be here.





