ConceptualSeptember 9, 2026Top AI Agent Identity Management and IAM Platforms in 2026Compare 10 AI agent identity management and IAM platforms for identity, governance, non-human identity security, credentials, delegated access, and runtime authorization.SHSachin HHead of Marketing
ConceptualSeptember 6, 2026Runtime Access Control for AI Agents: Why Permissions Need to Be Enforced at Execution TimeRuntime access control for AI agents determines whether a specific agent action should be allowed when the action is attempted and before it executes.SHSachin HHead of Marketing
ConceptualSeptember 5, 2026Least Privilege for AI Agents: How to Enforce It in ProductionA practical security playbook for controlling agent identities, tools, actions, resources, delegated access, and runtime authorization.SHSachin HHead of Marketing
ConceptualSeptember 4, 2026AI Agent Permissions: How Enterprises Can Control What Agents Access and DoAI agents are moving from controlled pilots into real enterprise workflows. As they begin accessing tools, data, APIs, and business systems, permissions become core enterprise control.SHSachin HHead of Marketing
ConceptualSeptember 3, 2026AI Agent Authorization: How to Control What Agents Can DoHow to manage agent permissions, apply least privilege, and control tool and API actions at runtime.SHSachin HHead of Marketing
ConceptualSeptember 2, 2026MCP Security Best Practices for Production DeploymentsMCP ships no mandatory security. Here's the practitioner checklist: OAuth 2.1 + PKCE, per-tool authorization, vault-injected credentials, tool call validation, and tamper-evident audit logs.SKSundar KrishFounder and CEO
ConceptualSeptember 1, 2026MCP Gateway vs Embedded Proxy: Where Should Tool-Call Enforcement Run?MCP has two deployment models: local STDIO and remote gateways. Neither enforces policy at the tool-call level inside your trust boundary. Here's the architecture that does.SKSundar KrishFounder and CEO
TechnicalJuly 16, 2026Why Multi-Step Drift Isn't Required for Runtime RiskWe attempted to induce multi-step MCP agent drift across monitoring and AWS tools. The experiment didn't produce reliable chains—but it revealed why the very first unexpected tool call is already a runtime security decision.SKSundar KrishFounder and CEO
ConceptualJune 22, 2026Four Ways AI Agents Mishandle Credentials Today, and Why Each Creates an Unexpectedly Broad Blast RadiusAI agents inherit credential patterns built for humans and static workloads. Each anti-pattern looks manageable in isolation. Together, they create a blast radius that covers everything the credential can touch.SKSundar KrishFounder and CEO
ConceptualMay 29, 2026Tracing Access from Human Intent to Tool Execution: Why Every AI Agent Tool Call Needs a Complete Delegation Chain RecordEvery AI agent tool call is the end of a chain — from human intent through agent reasoning to execution. Without a record of how authority traveled that chain, authorized and unauthorized look identical after the fact.SKSundar KrishFounder and CEO
ConceptualMay 28, 2026Observability for AI Agents Starts Inside the Enforcement Layer, Not Outside ItStandard monitoring tools capture what your agents did — not whether they were allowed to do it. Here's why security observability for AI agents must start inside the enforcement layer.SKSundar KrishFounder and CEO
TechnicalMay 26, 2026I Told the Orchestrator 'Do Not Modify.' 7 of 12 Sub-agents Never Heard It.What 36 controlled runs of Claude Code's Agent primitive reveal about delegation: the user's no-modify constraint disappears at the sub-agent boundary 7 times in 12, and the sub-agent that doesn't hear it inherits 41 GitHub tools plus Bash, Edit, and Write.SKSundar KrishFounder and CEO
ConceptualMay 13, 2026MCP's Missing Authorization Layer: Why Tool Discovery and Access Control Are Not the Same ThingMCP handles tool discovery — not what happens when an agent calls one. The authorization gap that OAuth doesn't close requires enforcement at execution time.SKSundar KrishFounder and CEO
ConceptualMay 7, 2026AI Agents Are Not Your Average Identity: Here's Why They Need Their Own SystemAI agents are not service accounts or bots. They're a third identity category: non-deterministic, autonomous, and built to chain tools at machine speed. Here's what that means for IAM.SKSundar KrishFounder and CEO
ConceptualMay 1, 2026Why AI Agent Access Control Must Happen at Execution Time, Not at Configuration TimeStatic permissions assigned to AI agents at configuration time leave gaps at every tool call. This article explains why runtime access control with scoped, ephemeral credentials is essential for AI agents.SKSundar KrishFounder and CEO
TechnicalApril 30, 2026I Gave My LangChain Agent Three Tools. All Three Had Access to Every Secret in the Process.A real LangChain setup showed how Slack, SQL, and web search tools can all access the same shared secrets when there is no runtime isolation.SKSundar KrishFounder and CEO
TechnicalApril 29, 2026How a Tool Description Poisoning Attack Sent My Agent Out of ScopeHow one poisoned tool description pushed an agent out of scope and into AWSSKSundar KrishFounder and CEO
ConceptualApril 20, 2026Why Traditional IAM Fails When an AI Agent Calls a ToolAI agents violate every assumption traditional IAM was built on. This article examines four specific failures at the tool-call layer — and what runtime enforcement needs to look like when agents act at machine speed.SKSundar KrishFounder and CEO
TechnicalApril 15, 2026GitHub MCP Gave My Agent 41 Tools. A 3-Word Prompt Made It Use the Wrong Ones.How vague prompts turn read-only tasks into write attempts — and why static token scoping isn't enough to stop it.SKSundar KrishFounder and CEO
TechnicalApril 9, 2026My Agent Finished Its Job, Then Started another one out-of-scopeHow a simple monitoring task drifted into AWS infrastructureSKSundar KrishFounder and CEO