IDENTITY & ACCESS MANAGEMENT

Manny Flores

Senior Systems Engineer · Corporate Systems lead, Robinhood

Identity has been my whole career: who gets in, what they can touch, and how access ends when they leave. Ten years of that across fintech and healthcare. Lately the newest users on the network are not people, so the job now is making sure AI tools live by the same rules as everyone else: who, and what, can do what.

Portrait of Manny Flores
SF Bay Area · since 2024
SCOPE

Access domains.

The identity, cloud, and collaboration stack the company runs on. The mandate: harden the foundation, make AI tooling adoptable, keep sprawl down.

Identity & Access Architecture

Authentication flows in Okta: SAML, OAuth 2.0, OIDC, plus SCIM for downstream provisioning. The full user lifecycle: birthright access, joiners, movers, leavers, rehires, service accounts, and the edge cases SCIM can't reach.

operating

Identity Governance & Audit

Led the Okta Identity Governance rollout: access certification campaigns and policy-driven lifecycle controls. Audit responses across SOX controls, access reviews, and service accounts, working directly with external auditors. Identity changes ship through technical reviews I author.

operating

AI Tooling Governance

The identity side of Claude Code, ChatGPT, Cursor, and Gemini Enterprise: rollout review, access controls, and MCP integration enablement across the SaaS stack. Agents get identities, scopes, and an audit trail. Service accounts authenticate through brokered credentials, checked out from the vault programmatically and returned, never held.

expanding

Cloud Governance (GCP)

Terraform-managed IAM and project structure, so engineers move AI workloads from prototype to production without creating sprawl.

operating

Collaboration Security

The surface where everyone works. Hardened, audited, and watched.

hardening
TRAJECTORY

The access plan.

A decade of identity work, written the way this audience reads change. Every line is on the .

SHIPPED & SHIPPING

Current focus.

Operating

Terraform Okta: Identity as Code

Okta config lives in Terraform now, not in clicks. Config drift is gone, changes get reviewed like code, and policy stays consistent across the tenant.

OktaTerraformIaCIdentity Infrastructure
Operating

Secure GCP for AI Workloads

A paved road from local prototype to hosted service. Project factories, IAM bindings, and access controls all live in Terraform, so shipping an AI-assisted tool to production is a reviewed change, not a hand-built exception.

GCPTerraformIAMAI Enablement
Building

Google Workspace Security Hardening

Tightening Google Workspace: access policies, DLP, third-party OAuth, audit coverage. The attack surface gets bigger every time someone installs a new AI tool, and that's the part I'm watching.

Google WorkspaceDLPOAuth GovernanceSecurity
CAPABILITY

Stack.

Identity & Access
Okta OIEOIGEntra IDSAML 2.0OAuth 2.0OIDCSCIMRBACZero Trust
Automation & IaC
PythonBashOkta WorkflowsTerraformGCP IAMAPIs & Integrations
Corp Apps Infra
GCPGoogle WorkspaceOktaSlackJiraWorkday
AI & Governance
MCPClaude CodeChatGPTCursorGemini EnterpriseLLM Access Controls