The security conversation around AI agents often focuses on what the models can do. Far less attention has been paid to how those agents are being connected to enterprise systems, what they can access once deployed, and whether organizations can actually govern that access over time. Earlier this year, Vercel disclosed a breach tied to a compromised…
Archives
-
When your Snowflake AI agent can query everything you can query
Cortex reached general availability in November 2025, with Cortex Code following in February 2026. These capabilities allow organizations to deploy AI agents that can query structured and unstructured data, execute code, call external tools, and expose Snowflake data to external systems via the Model Context Protocol (MCP). The identity risk that follows is straightforward and…
-
Claude didn’t go rogue. Permissions did.
On Friday April 25, 2026, a Cursor agent running Claude Opus 4.6 deleted PocketOS’s entire production database and all volume-level backups in a single API call to Railway. It took nine seconds. The AI agent’s own confession went viral, stating: “I violated every principle I was given.” Most of the press coverage framed the story…
-
The State of Identity Governance in 2026: Why Boards Think Access Is Under Control When It Isn’t
In many organizations, identity governance appears healthy at the executive level. Provisioning SLAs are met. Access reviews complete on time. Audit findings are addressed. Yet identity-related failures continue to surface in breach investigations, audit reports, and post-incident reviews. The issue is not that identity governance processes are inactive. It is that boards are typically shown…
-
Azure AI Studio and Azure OpenAI
The rapid evolution of AI, particularly with powerful platforms like Azure AI Studio and Azure OpenAI, presents an exciting frontier for innovation. However, as I’ve explored in previous posts on Google Vertex and AWS Bedrock, this new landscape also introduces a complex web of identity and access management (IAM) challenges that security and identity teams…
-
Self Assessment: Modern Access Management Maturity
To conclude this 5 part series on the importance of comprehensive and deliberate NHI governance, we are pleased to share this self assessment framework to help organizations understand where they are in their access management maturity journey. In case you missed it, here’s what we’ve covered so far: 1. Outnumbered and underprotected: the hidden risk…
-
New IAM Cybersecurity and PAM Tools Strategies for Higher Education
In the classroom, universities and colleges are looking towards the future with their curricula, stretching young minds around evolving concepts and advancements. The irony? Behind the scenes, these same institutions are often unprepared for the changes that developing technology brings to their campuses and networks. Recent digital disruptions, such as AI, have exposed the systems…
-
Close the NHI Governance Gap
We’ve spent the better part of the last decade tightening our grip on workforce authentication. SSO is widespread. MFA is table stakes. Access reviews, offboarding workflows, and role-based policies are now standard practice. It took time and iteration, but we got there. Now it’s time to apply that same rigor to machine identities. The service…