Identity security guides
SHORT ANSWER
Editorial assessment · Desk research from public vendor material · Reviewed 2026-09-29
Zero trust identity: what NIST SP 800-207 asks of the identity layer
Zero trust makes identity the checkpoint for every request. In practice that means three things: decide access per request rather than per network, authenticate with methods that resist phishing, and protect the tokens that carry the decision once it is made.
2026-09-29 · 4 min read
AI agent authentication, step by step
An AI agent should authenticate as itself, on behalf of a named person, with a short-lived token that is valid for one resource. The MCP specification sets the rules for tool calls; vendors add agent identities, per-call checks and credential brokering on top.
2026-08-04 · 3 min read
An identity hygiene checklist for people, machines and agents
Identity hygiene is removing access that should not exist. Work in this order: inventory everything, give each identity an owner, remove what is stale, close MFA and SSO gaps, replace long-lived secrets, then put AI agents under the same rules from day one.
2026-07-21 · 3 min read