Access management

When your coding agent can commit everything you can commit
By Neha Duggal
Developers must restrict agent access, mandate human code reviews, and sanitize inputs to mitigate unauthorized repo takeovers.

Agents are redefining sensitive access and P0 is leveraging AI to extend coverage just as fast
P0 now supports connectors for Salesforce, Cloudflare, Grafana Cloud and Datadog, extending Zero Standing Privilege controls for users and agents beyond cloud infrastructure into broader workforce application coverage.

Why Authentication Is Not Enough For Agents
Logging can tell you something happened. But none of that alone determines whether the action should be allowed, given the full chain of authority behind it.

From MCP Tool Filtering to Runtime Access Control
Tool-level filtering alone is not access control.

The identity risks of vibe coding
By Neha Duggal
Vibe coding changes the relationship between a developer and the code they ship. It does not change the fact that code carries identity and access decisions, and that those decisions have consequences.

Claude didn’t go rogue. Permissions did.
By Neha Duggal
The PocketOS incident is being told as a story about a coding agent that went off the rails, but that is not the true extent of the tale. It is a story about a long-lived API token with no scoping, no expiry, no approval gate, and no separation between production and backup, sitting where any sufficiently curious actor could find it.

Every era has its “worked great” tech. Then the environment changes.
If “governing privileged access” still means vaulting static credentials and shared jump-host accounts, you’re solving yesterday’s problem with yesterday’s tools.

Why broken access control still tops the OWASP Top 10 and what it means for identity security in the era of hybrid cloud
Broken access control has topped the OWASP Top 10 again — exposing the limits of traditional IAM. Learn why it persists in hybrid and multi-cloud environments and how continuous authorization governance helps close the gap.

Access in control: AWS Bedrock
By Neha Duggal
Generative AI enablers like Amazon Bedrock unlock the innovation potential of AI across the enterprises, but they also significantly expand the identity attack surface.

Governing Access in Amazon Bedrock
By Neha Duggal
Generative AI has fully entered the enterprise mainstream and platforms like Amazon Bedrock allow organisations to build and scale AI use cases with Foundational Models

Outnumbered and Underprotected: The Hidden Risk of Non-Human Identities
In Part 1 of our Non-Human Identity (NHI) Governance series, Kelsey Brazill exposes the cloud’s most overlooked attack surface – machine identities – and explains why traditional IAM tools can’t keep up.

Strengthening Access Governance for Human and Machine Identities
To strengthen access governance for both human and non-human identitie…