Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Agent identity architectures: Delegated, bounded, and autonomous

This is the second post in a series that follows 1Password’s response to NIST’s call for input on how those principles should apply to agents. In our last post on agent identity, we introduced why the ability to reason makes agents fundamentally different from traditional machine workloads, why it breaks the assumptions traditional identity and access management was built on, and why real-time attestation establishes agent identity at runtime.

How to Appear in AI Search Results

A few years ago, the goal was simple: rank on page one of Google. If your website appeared among the first 10 blue links, people would find you. That equation is changing. Search behavior is shifting from keyword lookups to answer-led queries. Instead of scanning a list of results, more people are turning to AI-powered search tools that read across the web, consolidate information, and deliver a direct answer. ChatGPT, Google AI Overviews, Perplexity, and Claude all work this way.

Automating Identity and Access for FedRAMP 20x KSIs with Teleport

Cloud service providers preparing for FedRAMP 20x are encountering a fundamentally different authorization model than the one their compliance programs were built around. The traditional FedRAMP path produced lengthy System Security Plans, point-in-time assessments, and human-readable narrative evidence.

How we tripled Persona's Marketplace integrations in under a year

When I joined Persona's Marketplace team as the product manager in August 2025, we had around 25 integrations. Our goal was to make Persona a seamless fit in every customer's stack: easy to get started with and even easier to grow with. Less than a year later, we've tripled the size of our marketplace to include more than 75 integrations. Here's how we've approached our Marketplace strategy this year.

Least Privilege Access for AI Agents: How to Secure Autonomous Systems in 2026

AI agents are no longer just answering queries or summarizing documents. They are booking meetings, pulling customer data, triggering workflows, and even making decisions across systems. And they don’t ask for permission every time. That’s where the real problem starts. Because once an AI agent is connected to your tools, APIs, and internal systems, the question isn’t what it can do, it’s what it should be allowed to do.

New in miniOrange PAM: Bringing EPAM to Windows and macOS

Privileged access has become significantly more complex over the last few years. Security teams are managing Windows and macOS devices, administrators rely on native tools to do their jobs, network infrastructure continues to expand, and operational technology environments are becoming increasingly interconnected. At the same time, manual approval processes and fragmented controls often create more friction than protection.

Blocking USB Devices and Whitelisting Authorized Peripherals with DLP

Data Loss Prevention (DLP) is all about keeping your business data safe from getting leaked, lost, or accessed without admin permission. It protects, identifies, analyzes, and blocks unauthorized data transfers within the network and through connected devices and outbound emails. DLP enforces company policies, preventing users from sharing confidential information. It further allows organizations to set USB restrictions to protect sensitive information at every stage of operations.

DPDP Rules, 2025: A Guide to Digital Personal Data Protection

The notification of the Digital Personal Data Protection (DPDP) Rules, 2025, marks a major turning point in how businesses in India collect, use, and safeguard personal data in the digital ecosystem. Together with the Digital Personal Data Protection (DPDP) Act, 2023, these Rules create a rights-based, consent-driven framework that places citizens at the centre of data processing while still enabling responsible innovation and growth in the digital economy.

How to layer fraud checks on top of Anthropic's KYC Screener agent

Anthropic released a pre-built KYC Screener agent last month. It runs a four-step workflow on onboarding records to extract structured data from KYC documents, evaluate that data against a firm's KYC rules, screen named parties, and escalate exceptions to a compliance file for human review. The Anthropic template is purpose-built for meeting basic KYC compliance requirements during onboarding, and it lowers the cost of getting it right.