PGA of America Overhauls Identity Security to Manage AI Sprawl
The PGA of America has revamped its technology infrastructure to prioritize identity security and AI governance. By eliminating traditional layers like data centers and VPNs, the organization relies on Okta and Auth0 to streamline access and manage AI agents securely. This approach highlights the importance of cross-functional collaboration and hands-on evaluation in enterprise AI adoption.
LazyFounders

The PGA of America has revamped its technology infrastructure to prioritize identity security and AI governance. By eliminating traditional layers like data centers and VPNs, the organization relies on Okta and Auth0 to streamline access and manage AI agents securely. This approach highlights the importance of cross-functional collaboration and hands-on evaluation in enterprise AI adoption.
30 SEC SUMMARY
- The PGA of America has eliminated traditional infrastructure layers like data centers and VPNs to simplify identity security using Okta and Auth0.
- AI agents at the PGA are centralized to prevent sprawl, with identity controls like MCP and agent gateways managing access.
- Finance, HR, legal, and technology teams collaborate on AI deployment decisions, ensuring oversight and governance.
- An internal council reviews new AI tools and use cases, emphasizing human oversight in the process.
- Hands-on experience with AI helps the PGA evaluate vendors and make build-or-buy decisions.
TABLE OF CONTENTS
- Streamlined Identity Security Architecture
- Okta and Auth0 as Core Platforms
- Centralized AI Agent Management
- Cross-Functional AI Governance
- Hands-On AI Evaluation
- Context: AI and Identity Security in the Enterprise
- What this means
- Key takeaways
- FAQ
- Sources
KEY HIGHLIGHTS
- The PGA of America has eliminated data centers, VPNs, and Active Directory to simplify identity security.
- Okta and Auth0 are used to centralize identity management and secure AI agent deployments.
- Finance, HR, legal, and technology teams collaborate on AI deployment decisions.
- An internal council reviews new AI tools and use cases with human oversight.
- Hands-on AI experience guides vendor evaluations and build-or-buy decisions.
Streamlined Identity Security Architecture
The PGA of America has overhauled its identity security architecture by eliminating traditional infrastructure layers, according to reports from SiliconANGLE. The organization has removed data centers, VPNs, Active Directory, and corporate networks, replacing them with a streamlined system centered on identity controls.
Okta and Auth0 as Core Platforms
The PGA now relies on Okta and its Auth0 platform for identity management and security. This shift reduces potential security gaps across user populations, including employees, contractors, and AI agents operating within enterprise systems.
Centralized AI Agent Management
AI agents at the PGA are designed to access enterprise tools and data on behalf of employees, adding complexity to identity security. To manage this, the organization uses centralized controls like MCP (likely a policy or management framework) and agent gateways to prevent AI sprawl and ensure secure interactions.
Cross-Functional AI Governance
AI deployment decisions at the PGA involve collaboration across multiple departments. Finance, HR, legal, and technology teams work together to evaluate risks, compliance, and operational needs before approving new tools or use cases.
New AI tools and use cases are reviewed by an internal council, which maintains human oversight throughout the process. This approach ensures alignment with organizational goals and mitigates unintended consequences.
Hands-On AI Evaluation
The PGA’s approach to AI vendor evaluations emphasizes hands-on experience. Teams test and interact with AI technologies directly to assess their capabilities, usability, and fit for specific use cases before making build-or-buy decisions.
Context: AI and Identity Security in the Enterprise
Enterprise AI adoption often involves navigating legacy infrastructure, security risks, and governance challenges. The PGA’s shift away from traditional data centers and VPNs reflects a broader trend of simplifying technology stacks to support modern use cases like AI.
Recent advancements in identity management platforms, such as Okta and Auth0, have made it easier for organizations to centralize security controls. This is particularly relevant for managing AI agents, which require dynamic and secure access to enterprise systems.
What this means
LazyFounders analysis — our interpretation, not reported fact.
For founders and operators, the PGA of America’s approach to identity security and AI governance offers a practical blueprint for balancing innovation with control.
Eliminating legacy infrastructure like VPNs and Active Directory isn’t just about reducing complexity—it’s about creating a foundation where AI agents can operate safely and efficiently. Centralizing identity controls through platforms like Okta and Auth0 ensures that security scales with adoption, rather than becoming a bottleneck.
The PGA’s cross-functional collaboration on AI deployment—bringing together finance, HR, legal, and technology teams—highlights the importance of governance in enterprise AI. For startups, this isn’t just about compliance; it’s about building trust with stakeholders and avoiding the pitfalls of unchecked AI sprawl.
Finally, the emphasis on hands-on experience with AI tools is a reminder that vendor evaluations and build-or-buy decisions shouldn’t be made in a vacuum. Founders should prioritize experimentation to understand what truly works for their use cases, rather than relying solely on marketing promises.
Key takeaways
- The PGA of America has replaced traditional infrastructure like data centers and VPNs with Okta and Auth0 for identity security.
- AI agents are managed centrally to prevent sprawl, using identity controls and agent gateways.
- Cross-functional teams—including finance, HR, legal, and technology—collaborate on AI deployment decisions.
- New AI tools and use cases undergo review by an internal council with human oversight.
- Hands-on experience with AI technology informs vendor evaluations and build-or-buy decisions.
FAQ
Why did the PGA of America eliminate data centers and VPNs?
The organization replaced these traditional infrastructure layers to reduce complexity, improve security, and create a more scalable foundation for AI and identity management.
How does the PGA manage AI agent sprawl?
AI agents are centralized using identity controls like MCP and agent gateways, which ensure secure and controlled access to enterprise tools and data.
Who is involved in AI deployment decisions at the PGA?
Finance, HR, legal, and technology teams collaborate on AI deployment decisions, with an internal council providing human oversight for new tools and use cases.
What role does hands-on experience play in the PGA’s AI strategy?
Hands-on experience helps teams evaluate AI vendors and technologies, ensuring that build-or-buy decisions are informed by direct testing and usability assessments.
Related on LazyFounders
Sources
- SiliconANGLE · 2026-09-24
The PGA of America limits AI sprawl with a streamlined identity architecture
This story is an original summary and analysis written by LazyFounders from the reporting listed above. Facts are attributed to their original publishers; sections marked as analysis are LazyFounders's opinion. Where a source is in another language, facts were machine-translated and quotations are reported, not reproduced. Read the original coverage via the links.


