Agents are redefining sensitive access...P0 is using AI to extend coverage just as fast

AI agents

The identity risks of vibe coding

6 mins

The identity risks of vibe coding

Vibe coding changes the relationship between a developer and the code they ship. It does not change the fact that code carries identity and access decisions, and that those decisions have consequences.
Claude didn’t go rogue. Permissions did.

5 mins

Claude didn’t go rogue. Permissions did.

The PocketOS incident is being told as a story about a coding agent that went off the rails, but that is not the true extent of the tale. It is a story about a long-lived API token with no scoping, no expiry, no approval gate, and no separation between production and backup, sitting where any sufficiently curious actor could find it.
When your Snowflake AI agent can query everything you can query

4 mins

When your Snowflake AI agent can query everything you can query

Snowflake Cortex is a powerful addition to the modern data platform, and the use cases are real. But every Cortex Agent deployment is also an identity governance event. The agent does not audit itself. It queries what it can query, surfaces what it can surface, and connects to what it is given access to.
2026 SACR report

2026 SACR report

A new SACR report shows the shift from vault-led PAM to identity-native, just-in-time access. The maturity model will feel familiar. It builds on ideas Shashwat Sehgal has pushed for years.
No results found.