Agents are redefining sensitive access...P0 is using AI to extend coverage just as fast

Blog

Agent provenance is ambitious, so let’s get the hard parts right

8 min

Agent provenance is ambitious, so let’s get the hard parts right

Agent provenance is a useful stress test for whether your agent security stack can actually deliver accountability. It requires more than discovery or observability. You need an immutable chain of events, blended human-agent identity, runtime policy enforcement, and enough context to determine whether an agent’s actions stayed within the originator’s intent.
Claude didn’t go rogue. Permissions did.

5 mins

Claude didn’t go rogue. Permissions did.

The PocketOS incident is being told as a story about a coding agent that went off the rails, but that is not the true extent of the tale. It is a story about a long-lived API token with no scoping, no expiry, no approval gate, and no separation between production and backup, sitting where any sufficiently curious actor could find it.
Anthropic’s Claude Enterprise

4 mins

Anthropic’s Claude Enterprise

By shifting toward a model of Zero Standing Privileges and implementing just-enough and Just-in-Time access for AI-driven workflows, security teams can empower their developers without turning their most productive tools into their greatest identity risks.
Google Vertex AI

6 mins

Google Vertex AI

Recently, I wrote about the governance challenges and risks associated with Amazon Bedrock and today I’ll explore how the same principles apply to Google Vertex.
Why PAM Needs to Evolve

5 mins

Why PAM Needs to Evolve

Modern-PAM needs to support more systems, more accounts, a hybrid deployment landscape and have the functionality available to a broader array of integrating technologies via modular, composable and API-first capabilities.
No results found.