Identity security guides

SHORT ANSWER

Three practical guides that sit behind the topic pages: what zero trust asks of identity, how an AI agent should authenticate, and a hygiene checklist for people, machines and agents.

Editorial assessment · Desk research from public vendor material · Reviewed 2026-09-29

Zero trust identity: what NIST SP 800-207 asks of the identity layer

Zero trust makes identity the checkpoint for every request. In practice that means three things: decide access per request rather than per network, authenticate with methods that resist phishing, and protect the tokens that carry the decision once it is made.

2026-09-29 · 4 min read

AI agent authentication, step by step

An AI agent should authenticate as itself, on behalf of a named person, with a short-lived token that is valid for one resource. The MCP specification sets the rules for tool calls; vendors add agent identities, per-call checks and credential brokering on top.

2026-08-04 · 3 min read

An identity hygiene checklist for people, machines and agents

Identity hygiene is removing access that should not exist. Work in this order: inventory everything, give each identity an owner, remove what is stale, close MFA and SSO gaps, replace long-lived secrets, then put AI agents under the same rules from day one.

2026-07-21 · 3 min read

The guides are also part of the university tracks.