The Password Was Never the Point: PAM’s Shift From Managing Accounts to Governing Access to Privilege

Vaulting secures credentials at rest, but breaches happen in use. PAM’s real shift is governing sessions, not accounts, for humans and AI agents alike.
First-Class or Ephemeral Is the Wrong Fight

AI agents need a governed identity and a scoped, disposable credential — not one or the other. Your auditor, not a vendor roadmap, settles the definition.
We Didn’t Close the Skills Gap. We Financed It.

AI agents didn’t close the cybersecurity skills gap, they financed it. The collateral is insecure code and unowned agent identities, and identity is on track to become the new COBOL.
How to Extend Entra Provisioning to Apps Without SCIM or API

You’ve built your identity program around Microsoft Entra ID. It’s your authority for users. It handles authentication. For apps with SCIM support, it automates the entire identity lifecycle: provisioning, authentication, access reviews, deprovisioning. But not every app supports SCIM. Not every app has a usable API. And the Entra gallery doesn’t have a connector for […]
AI Use Cases for IAM and the Pending Risk Wall

Over the last few months of 2025, I had several conversations with CISOs and Identity teams about AI and IAM use cases. Teams are rapidly trying to support their organizations as they adopt or enable AI in different areas and are struggling with how to secure it, use it to automate Identity tasks, and translate […]
The Next IGA Revolution: How IGA is Going to Change in 2026 to Scale Faster and Easier

You may be looking at your 2026 budget and trying to plan your Identity Governance and Administration (IGA) priorities. If you’re a few years into your IGA deployment, you may be finding it increasingly challenging to keep attention and executive support, while still facing a large backlog of applications that are not covered. Or, you […]
It’s time we had a chat….

It’s funny, whenever I hear that I have flashbacks to someone getting ready to tell me I’m in trouble for something. No, I’m not going to tell you you’re in trouble, but I do feel we’re reaching a point where the pace of new features, technologies, and capabilities is quickly outpacing the ability of IAM […]
My Agentic Journey: The journey to seamless, secure AI / Identity integration
Over the last 3-6 months, I’ve had a ton of conversations around Secrets and Non-Human Identities (NHI), governance, authentication, and authorization with many of them leading to the inevitable AI overlay of the same topic. Now, I say it that way because we’re getting more mature when it comes to building and securing interactive and […]
Identity Week 2025 Recap
What a week! My first time attending, and being able to speak, at Identity Week was awesome. I met so many IAM practitioners, visionaries, leaders and vendors in attendance and had a ton of great conversations. As I sit and get ready for the weekend and work on some presentations and content, I am reflecting […]
Simplifying the Complex for Dynamic Authorization: Just ask the question to get a response

As we go into 2025, I’ve seen a number of different articles and posts around what is going to be critical this year in IAM. I think a lot of what I have been seeing and consensus has been Non-Human Identity, passwordless / adaptive authentication, identity verification, and (interestingly) dynamic authorization. I could see everything […]