Identity, for people and for agents.
Practical guidance on IAM fundamentals and the AI identity questions most organizations are only starting to ask.
MCP and the New Access Control Problem
Model Context Protocol makes it trivial to connect an agent to a dozen tools in an afternoon. Here's why that's an access control problem before it's anything else, and how to scope it correctly.
AI Agent Lifecycle Management: A Practical Framework
Provisioning, reviewing, and retiring agent identities with the same discipline you'd apply to a privileged employee account, not less.
Passwordless Authentication in 2026: What Actually Works
Passkeys, FIDO2, and WebAuthn have moved from "emerging" to "the standard." What to roll out first, and what to retire.
Building Accountability Into Autonomous Systems
An agent's action is only as accountable as the identity behind it. A framework for making sure every autonomous action traces back to a real owner.
Identity Verification in the Age of AI-Generated Fraud
Deepfake video calls and AI-generated documents have made "is this person who they say they are" a much harder question. What actually holds up.
Non-Human Identity: The IAM Blind Spot Growing Faster Than Anyone Planned For
Most organizations now run more machine and agent identities than human ones. Most access-review processes were never built to include them.