Neha Duggal

Neha Duggal is a cybersecurity product and identity security expert specializing in privileged access management (PAM), identity governance, non-human identity (NHI) security, AI agent security and cloud-native access control.

As Chief Product Officer at P0 Security, Neha focuses on building modern identity-native security platforms that help organizations govern privileged access across human, machine and AI identities in hybrid and multi-cloud environments. Her expertise spans cloud security, Zero Trust architecture, observability, application performance monitoring (APM), developer security workflows and product strategy for enterprise cybersecurity and SaaS platforms.

LinkedIn

Latest research and insights

Nobody built MCP servers to hold identity. They do anyway.

Nobody built MCP servers to hold identity. They do anyway.

The identity plane your agents run on is whatever the last MCP server someone installed decided it should be. That is not the layer to leave to chance.

When Your Coding Agent Can Commit Everything You Can Commit

When your coding agent can commit everything you can commit

Developers must restrict agent access, mandate human code reviews, and sanitize inputs to mitigate unauthorized repo takeovers.

The OpenAI agent did not go rogue. It ran out of authorization boundaries.

The OpenAI agent did not go rogue. It ran out of authorization boundaries.

If you are running agents in evaluation, production, or anywhere in between, do not only ask whether the model will stay inside its sandbox. Ask whether your identity and authorization controls can stop the model after it finds a way out.

Agentforce and Cortex aren't SaaS features. They're agent runtimes. Your security stack doesn't know the difference.

Agentforce and Cortex aren’t SaaS features, they’re agent runtimes

Salesforce Agentforce and Snowflake Cortex have quietly become two of the largest agentic deployment platforms in the enterprise.

The identity risks of vibe coding

The identity risks of vibe coding

Vibe coding changes the relationship between a developer and the code they ship. It does not change the fact that code carries identity and access decisions, and that those decisions have consequences.

Claude didn't go rogue. Permissions did.

Claude didn’t go rogue. Permissions did.

The PocketOS incident is being told as a story about a coding agent that went off the rails, but that is not the true extent of the tale. It is a story about a long-lived API token with no scoping, no expiry, no approval gate, and no separation between production and backup, sitting where any sufficiently curious actor could find it.

When your Snowflake AI agent can query everything you can query

When your Snowflake AI agent can query everything you can query

Snowflake Cortex is a powerful addition to the modern data platform, and the use cases are real. But every Cortex Agent deployment is also an identity governance event. The agent does not audit itself. It queries what it can query, surfaces what it can surface, and connects to what it is given access to.

Anthropic’s Claude Enterprise

By shifting toward a model of Zero Standing Privileges and implementing just-enough and Just-in-Time access for AI-driven workflows, security teams can empower their developers without turning their most productive tools into their greatest identity risks.

Azure AI Studio and Azure OpenAI

Azure AI Studio and Azure OpenAI offer transformative capabilities, but their integration into the Azure ecosystem brings unique identity security considerations.

Google Vertex AI

Recently, I wrote about the governance challenges and risks associated with Amazon Bedrock and today I’ll explore how the same principles apply to Google Vertex.

More than visibility: P0 introduces privileged access control for agents

AI agents are increasingly playing a part in how modern developer teams build, automate, and scale.

Access in control: AWS Bedrock

Generative AI enablers like Amazon Bedrock unlock the innovation potential of AI across the enterprises, but they also significantly expand the identity attack surface.