Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Identity Security for AI

What's scarier than an engineer with prod access? An agent with the same access that never sleeps, never asks, and runs a thousand sessions while you're at lunch. Last year we solved the problem of visibility in the Identity Chain, the concept is that identities are fragmented and it’s hard to get a view from Identity Providers to Infrastructure. Within a year, two things have changed. First, teams are using LLMs & Tools to perform actions on their behalf - fully delegating work to AI Agents.

Why deepfakes are scared of mobile devices

Voice cloning is fooling grandparents into wiring money to "grandchildren." Vendor impersonation is rerouting accounts payable. And fraud rings are using AI to change their accents mid-scam when their first attempt raises suspicion. In this webinar, PJ Rohul (co-founder, About Fraud) talks with Laurel Sykes (chief risk officer, American Riviera Bank) and Brandon Chen (product marketing manager, Persona) about why mobile device-based verifications are becoming fraud teams' strongest defense against sophisticated attacks.

IGA vs. IAM: Key Differences and Why Enterprises Need Both

Identity has become the new security perimeter. With over 80% of breaches involving compromised credentials, how organizations manage and govern identities is now the defining factor in both security posture and regulatory compliance. The stakes have risen sharply. Cloud adoption, remote workforces, AI-driven automation, and expanding third-party ecosystems have multiplied the volume of identities organizations must manage, and the consequences of mismanaged access have never been more severe.

Governing non-human identities with Identity Manager 10.0

Most organizations today have more non-human identities than human identities. These NHIs often hold privileged access, operate continuously and are difficult to track. Get a handle on every identity in your environment with Identity Manager by One Identity.

DPDP Act Penalties: Fines for Non-Compliance Explained

The Digital Personal Data Protection (DPDP) Act, 2023, has shifted data privacy from a regulatory obligation into a critical business risk. With the DPDP Rules, 2025 providing operational clarity, businesses are expected to implement reasonable security safeguards, manage consent, protect children's data, and respond promptly to personal data breaches.

Identity-Centric PAM: The Future of Privileged Access Management

Privileged Access Management (PAM) has become a cornerstone of enterprise security, but the environments it protects have changed dramatically. Organizations now manage cloud infrastructure, SaaS applications, remote workforces, third-party vendors, machine identities, and AI-driven workloads that constantly request privileged access. Security teams need to verify every identity, understand the context of each request, and grant only the minimum level of access required.

Agent verification might just be KYC/KYB

Every time a card gets issued or a payment moves, something has to decide, in milliseconds, whether it's legitimate. That's the problem Robin Gandhi, chief product officer at Lithic, solves every day. Lithic builds the programmable infrastructure behind modern card issuing and money movement for developers, digital banks, and financial institutions.

AI Agent Identity: Securing Desktop, SaaS, and Enterprise AI Agents

Your enterprise probably has a few thousand employees with managed identities. HR provisioned them, IT governs them, and your IAM platform watches them. Now count the AI agents running across your org. The Claude Code and codex instance that sit inside every dev's IDE. The Salesforce Einstein bot with access to every open deal. The Zapier AI that reads your CRM, writes to your Slack, and forwards summaries to email. You can't count, secure, or govern them with traditional IAM, can you?

SCIM & REST API Provisioning for Jira and Confluence

Wouldn't it be great if managing user accounts didn't take hours of manual effort? For many IT teams, unfortunately, that's exactly the reality. Every new employee needs access for all the apps they intend to use. When someone switches roles, permissions need updating. And when someone leaves, all their access needs to be revoked immediately. These tasks might sound simple, but they become exponentially more challenging as your company grows.