Blog
Agent provenance is ambitious, so let’s get the hard parts right
Agent provenance is a useful stress test for whether your agent security stack can actually deliver accountability. It requires more than discovery or observability. You need an immutable chain of events, blended human-agent identity, runtime policy enforcement, and enough context to determine whether an agent’s actions stayed within the originator’s intent.
No results found.

8 min
Agent provenance is a useful stress test for whether your agent security stack can actually deliver accountability. It requires more than discovery or observability. You need an immutable chain of events, blended human-agent identity, runtime policy enforcement, and enough context to determine whether an agent’s actions stayed within the originator’s intent.

4 mins
Developers must restrict agent access, mandate human code reviews, and sanitize inputs to mitigate unauthorized repo takeovers.

4 mins
If you are running agents in evaluation, production, or anywhere in between, do not only ask whether the model will stay inside its sandbox. Ask whether your identity and authorization controls can stop the model after it finds a way out.

4 mins
P0 now supports connectors for Salesforce, Cloudflare, Grafana Cloud and Datadog, extending Zero Standing Privilege controls for users and agents beyond cloud infrastructure into broader workforce application coverage.

3 mins
Logging can tell you something happened. But none of that alone determines whether the action should be allowed, given the full chain of authority behind it.

7 min
Tool-level filtering alone is not access control.

6 mins
"Just in Time (JIT) access" is a simple concept but can be architected in multiple ways with significant ...

5 mins
Salesforce Agentforce and Snowflake Cortex have quietly become two of the largest agentic deployment platforms in the enterprise.

4 mins
The Composio breach was not only about agentic AI, leaked credentials or sandbox execution. It was about trusted internal systems with enough standing privilege to become an attack path.

5 mins
The future of agentic security will not be determined by model quality alone. It will be determined by how well organizations govern human authority, delegation and operational identity before autonomous systems begin operating at AI scale.

6 mins
Vibe coding changes the relationship between a developer and the code they ship. It does not change the fact that code carries identity and access decisions, and that those decisions have consequences.

5 mins
The PocketOS incident is being told as a story about a coding agent that went off the rails, but that is not the true extent of the tale. It is a story about a long-lived API token with no scoping, no expiry, no approval gate, and no separation between production and backup, sitting where any sufficiently curious actor could find it.

4 mins
Snowflake Cortex is a powerful addition to the modern data platform, and the use cases are real. But every Cortex Agent deployment is also an identity governance event. The agent does not audit itself. It queries what it can query, surfaces what it can surface, and connects to what it is given access to.

3 mins
I see a pattern in early-stage companies that is easy to miss because it looks like maturity. Teams borrow processes that work later, when an organization is larger and roles are more specialized, and they apply them far too early.

4 mins
By shifting toward a model of Zero Standing Privileges and implementing just-enough and Just-in-Time access for AI-driven workflows, security teams can empower their developers without turning their most productive tools into their greatest identity risks.

3 mins
Connectivity and authentication have become increasingly commoditized. Most organizations can point to mature tooling, common best practices and a set of controls that are at least defensible.

3 mins
If “governing privileged access” still means vaulting static credentials and shared jump-host accounts, you’re solving yesterday’s problem with yesterday’s tools.

3 mins
OAuth scopes solve an important part of the authorization puzzle: delegated capability. But they are only one piece. To do MCP authorization properly, you need scopes for the big picture and server-side RBAC for least-privilege enforcement.

3 mins
The ServiceNow breach is a wake-up call. As we deploy more autonomous agents with access to critical business systems, we need authorization architectures designed specifically for the agentic paradigm not retrofitted from traditional security models.

5 mins
Azure AI Studio and Azure OpenAI offer transformative capabilities, but their integration into the Azure ecosystem brings unique identity security considerations.

8 mins
The P0 Authz Control Plane for Agents lets developer and security teams control access for agentic applications that connect to internal data sources, such as a Postgres, Snowflake, Mongo database through a chat interface.

6 mins
Recently, I wrote about the governance challenges and risks associated with Amazon Bedrock and today I’ll explore how the same principles apply to Google Vertex.

3 mins
Agentic systems are accelerating everything. They increase the number of access paths, expand the impact of bad permissions and highlight the limits of tools built for manual control.

6 mins
This is the final of a three-part series taking a look at modern privileged access management and how its evolution to the protection of more systems and more identities leads to both security and productivity improvements.

5 mins
AI agents are increasingly playing a part in how modern developer teams build, automate, and scale.

3 mins
Today’s privileged access challenges demand a shift from static, siloed controls to identity-centric, Just-in-Time (JIT) models that improve security while accelerating deployment and engineering workflows.

4 mins
Broken access control has topped the OWASP Top 10 again — exposing the limits of traditional IAM. Learn why it persists in hybrid and multi-cloud environments and how continuous authorization governance helps close the gap.

5 mins
Generative AI enablers like Amazon Bedrock unlock the innovation potential of AI across the enterprises, but they also significantly expand the identity attack surface.

2 mins
Generative AI has fully entered the enterprise mainstream and platforms like Amazon Bedrock allow organisations to build and scale AI use cases with Foundational Models

2 mins
To wrap up our five-part series on Non-Human Identity (NHI) Governance, we’re sharing a practical self-assessment framework to help teams pinpoint where they stand on the Modern Access Management Maturity Curve.

3 mins
In Part 4 of our Non-Human Identity (NHI) Governance series, Kelsey Brazill explains why this blind spot persists, and what good governance really looks like when extended to machines.

5 mins
Modern-PAM needs to support more systems, more accounts, a hybrid deployment landscape and have the functionality available to a broader array of integrating technologies via modular, composable and API-first capabilities.

6 mins
In Part 3 of our Non-Human Identity (NHI) Governance series, Kelsey Brazill breaks down why vaulting isn’t enough, what true governance looks like, and how to move from static credentials to ephemeral, just-in-time access.

3 mins
Learn why vaults and jump servers can’t keep up, and how an API-led model delivers just-in-time access, automates least privilege, and strengthens security without slowing developers down.

3 mins
Learn how security teams can evolve identity programs to manage risk, reduce exposure paths, and prepare for the next wave of AI-driven access.

5 mins
In Part 2 of our Non-Human Identity (NHI) Governance series, Kelsey Brazill explores what happens when machine access goes ungoverned AND how to fix it.

4 mins
In Part 1 of our Non-Human Identity (NHI) Governance series, Kelsey Brazill exposes the cloud’s most overlooked attack surface - machine identities - and explains why traditional IAM tools can’t keep up.
How security, identity, and governance practices must evolve for autonomous software agents
Agentic AI ...

3 mins
Discover the key differences between Non-Human Identities (NHIs) and machine identities. Learn best practices to secure service accounts, API keys, and cloud assets.

2 mins
Whether you call them machine identities, service accounts, or workload principals, the fact remains: NHIs are now everywhere, and they need rigorous governance.

3
How to gain visibility into all human + NHI, securing JIT access, and automating access review through dev-friendly workflows.

5 minutes
A practical field guide to help assess your identity posture across cloud platforms. Built by practitioners, not vendors.

3 mins
I'm excited to kick off a series on rethinking cloud identity for the machine-driven er..

3 mins
Join P0 at Identity Management Day 2025 to learn best practices for securing all identities.

3 mins
Enterprises upgrade to next-gen PAM for secure, agentless cloud access and compliance

4 mins
Hear from some of the leading voices in cloud security as we explore emerging trends, threats, and solutions in identity management.

3 mins
Learn how a leading insurance provider scaled GCP governance, securing 40K+ service accounts efficiently

3 mins
Securing all identities is key: insights on scalable governance from Paychex’s CISO.

2 mins
To strengthen access governance for both human and non-human identitie...

3 mins
P0 Security has secured $15 million in Series A funding, totaling $20 ...

4 mins
The p0 approach to just-in-time ephemeral database access streamlines ...

2 mins
We’re honored and thrilled to announce that P0 Security has been named...

3 mins
Divvy Homes migrates from a cumbersome legacy PAM solution, gaining co...

3 mins
To adhere to SOC2 and other certifications, Applied Intuition enforced...

2 mins
Announcing P0’s general availability! P0 is the first unified offering...

4 mins
Enhancing the security of PostgreSQL cloud databases through the adopt...

4 mins
A real-world guide for setting up federated identity using OpenID Conn...

3 mins
Transitive access via service accounts is a common security vulnerabil...

3 mins
Google announced that as of January 15, 2024, Policy Intelligence will...

3 mins
This blog post provides detailed instructions on investigating service...

2 mins
Afresh faced security and operational challenges with their IAM set up...

4 mins
P0's Kubernetes integration grants temporary access to sensitive resou...

4 mins
Granting temporary access in Google Cloud with conditional IAM improve...

4 mins
This blog post explores the concept of granting temporary access to an...

3 mins
P0 helps cloud security engineers control entitlements for their devel...

4 mins
P0 automates least-privilege access for customers by integrating with ...

4 mins
P0's integration with AWS allow security engineers to implement least ...

4 mins
P0's integration with Google Cloud projects allow security engineers t...

3 mins
The Uber breach highlights the unique security challenges posed by clo...
No results found.