Session

The Integration That Didn't Exist: Bridging Google Chat and Okta with a Gemini Agent

Every enterprise has the same silent tax: someone locked out of their account, waiting on a helpdesk ticket for a password reset that a machine could have done in six seconds.

This session walks through a production AI agent that closed that gap for a UK energy retailer with ~8,400 users — built entirely on Google Cloud, and shipped by a two-person effort inside an existing IAM team.

There was no native Google Chat → Okta integration. We built the bridge ourselves: a Python service on Cloud Run (europe-west2), Vertex AI Gemini Flash for intent resolution, Firestore for conversation state, Pub/Sub and Secret Manager underneath, and a self-hosted static OIDC issuer feeding Workload Identity Federation so the whole thing runs keyless — no long-lived service account keys anywhere.

We'll cover:

1. The architecture, end to end
2. Guardrails for irreversible actions
3. Keyless auth on GCP via a self-hosted OIDC issuer and Workload Identity Federation
4. Observability that survives an audit
5. The honest numbers (What is improves)

Pratik Bhatt

Senior Identity Engineer · Founder, Sangyaa Consulting · Triple-certified Okta SME

Gandhinagar, India

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top