Skip to content

Leadership1 publisher2 min readPublished

Ping Identity brings password resets and access changes into Gemini Enterprise chat

Ping Identity has launched three agents that let Gemini Enterprise administrators reset passwords, end sessions and change access by typing a request. IT teams now have to decide whether a confirmation inside a chat window meets their change-control and audit rules.

The Board Room · Leadership desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying Ping Identity brings password resets and access changes into Gemini Enterprise chat
Generated illustration

What happened

  • The three agents are available now through Google Cloud Marketplace for organisations running Gemini Enterprise.
  • An employee-facing PingID agent lets signed-in staff pair a replacement phone, rename or remove devices and choose a default authenticator.
  • Two administrator agents, for PingOne and PingOne Advanced Identity Cloud, also manage MFA enrollment and let admins review user activity.
  • Ping says each request maps to a defined identity action through its APIs, inside the requesting user's boundaries of authority.

Compiled by The Board RoomSomething wrong?How this is made

Why it matters

  • decision Identity teams have to rule on whether a confirmation click inside Gemini Enterprise counts as approval under their change-control policy, or whether a second sign-off is still required.
  • constraint Ping describes different safeguards for different agents, so a deployment of all three has to be reviewed agent by agent against the organisation's own controls.
  • exposure An administrator's Gemini Enterprise session becomes a route to password resets and session terminations, bounded only by the permissions that admin role already holds.

An access change that starts as a sentence in a chat window still needs an owner and an approval record. Ping's chief executive puts ownership with the person typing. "Identity can't remain trapped behind a separate console," Andre Durand, Ping's founder and CEO, said [5]. The agents put "identity into the flow of how people work, while keeping every action tied to the authority of the person behind it," he said [6].

The safeguards Ping describes differ by agent. Two of the three agents are for administrators [1]. The PingID Device Management Agent holds no standing credentials and acts only on direction from an authenticated user, according to the company [9]. Both administrator agents work inside their assigned access controls and administrative permissions [10][11]. Ping says only approved operators can make changes in the Advanced Identity Cloud product, where the agent requires "explicit confirmation" before taking any action [12]. The report attaches that confirmation step to the Advanced Identity Cloud product.

The trade-off is speed against the shape of the audit trail. Administrators can now reset a password or end a session without leaving Gemini Enterprise for a separate identity console [3][4]. Because each request resolves to a defined action through Ping's APIs [7], the change itself still runs in the identity platform. The announcement does not describe how those changes are logged, or whether the conversation that prompted them is kept alongside the identity system's own record.

A confirmation prompt is a thin control for someone who confirms requests all day. Ping's design puts the weight on the operator's existing permissions, since the agent acts within them [11]. Dai Vu, Google Cloud's managing director of marketplace and ISV GTM programs, said the agents help employees and administrators "operate within established identity controls more efficiently" [13]. An admin role with more permissions than it needs keeps them when the request arrives through chat.

In my view the order of rollout follows from Ping's own descriptions. The device agent lets employees manage their own authenticators, with no standing credentials behind it [8][9]. I'd start there. The administrator agents change other people's passwords, sessions and access [4]. Those are the changes an access review exists to check.

This quarter's choice is whether administrators get the agents before the identity team has matched Ping's confirmation step to its own approval rules. If they do, next quarter's access review will have to reconcile changes executed in the identity platform with approvals given in a conversation.

What to watch

  • Whether Ping publishes how agent-initiated changes appear in PingOne and Advanced Identity Cloud audit logs, including any link back to the Gemini Enterprise conversation.
  • Whether the PingOne Administrator Agent gets the same approved-operator list and explicit-confirmation step Ping described for Advanced Identity Cloud.
  • Whether other identity vendors ship comparable administration agents for Gemini Enterprise through Google Cloud Marketplace.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories