What sounds better, persistent or purpose-bound access? Implicit trust or enforced boundaries? Risk accumulation or risk containment?
The latter? Then you might need zero standing privileges.
Explore why here: https://t.co/ST9S79YWNm
AI agents aren’t malicious by design, and that's not the main risk organizations should be dealing with.
The risk is what those agents can access. If permissions are too broad, will they leak sensitive data leaks? Can you risk it?
https://t.co/l3WliyMa2S
On June 11, PlainID's Gal Helemski and Marco Venuti, Director, IAM Business Acceleration at @thalesgroup, are running a live session on what CIAM has to become to catch up in the AI era.
Block your calendar now and sign up here: https://t.co/rUkQtk3MUk
Authentication tells you who is making the request, but in an MCP-driven system, that’s only a small part of the problem. Because in these systems, every request is should be a separate security decision, and those decisions need to be made in real time.
https://t.co/aQVu9aEN5n
We're honored to be named a Sample Vendor in the API Access Control category of the Gartner® Hype Cycle for APIs, 2026.
Full report: "Hype Cycle for APIs, 2026," Shameen Pillai and Mark O'Neill, May 22, 2026. (Gartner subscription required) 👉https://t.co/Mqm4xwoC6F
Authorization is the system of control for every human, non-human, and AI identity in your enterprise. It decides what gets through and what doesn't. The architects we work with chose an independent control plane on purpose.
https://t.co/H57NvnBAeI
Once access is granted, systems assume that everything that follows is authorized. And that's how, in agentic environments, every permission is valid, every action is allowed, and every result... violates policy.
https://t.co/zoQTKCnTRZ
Authentication = who showed up.
Authorization = what they can do.
Delegation = on whose behalf.
Most CIAM stacks collapse all three into a login.
PlainID's Gal Helemski + @thalesgroup's Marco Venuti on fixing that in the agentic AI era: https://t.co/DL5pmijAqe
Most environments still assume that once access is granted, it remains valid for the duration of the task or session. But in AI workflows, that assumption breaks very quickly.
https://t.co/XltoNZknFx
The agentic era is here, and PlainID is officially the control plane 🚀
PlainID now supports AWS AgentCore and Microsoft Foundry as additional enforcement targets, alongside our existing coverage for MCP, LangChain, applications, APIs, and data.
https://t.co/p0KJKQlTXG
Identity authorization needs to change. We moved from users to their agents. From logging in during business hours to continuous 24/7 activity. From accessing things to actually acting upon them across multiple systems.
https://t.co/nQPZX7HiA5
If authorization considers only the agent, it risks granting broad capabilities disconnected from the user’s context.
But if it considers only the user, it ignores how actions are carried out across multi-step workflows.
The correct model is here: https://t.co/lzjGc8q8B8
When authorizing access, who do you focus on:
A) the user
B) the AI agent
C) none of the above is correct
The reality is that it cannot be one or the other. It has to be both.
We're talking about it in more detail in our latest ebook: https://t.co/KKxC6d3XIy
If Gartner predicts that over 50% of successful cybersecurity attacks against AI agents will exploit access control issues by 2029... then that number should stop you.
If you’re deploying agents and want to do it responsibly, early access is open: https://t.co/kMf3xe6Brf
What we're seeing across board is AI agents being connected to enterprise systems before organizations fully understand:
• what data agents can access
• what tools they can use
• how their actions are governed
https://t.co/KV1lafqfuW
Catch up on Gal Helemski's conversation with @kuppingercole's John Tolbert to discuss how to set real security boundaries for AI agents that act, decide, and execute across your apps, APIs, and data: https://t.co/cZ7QR9ZeJF
Your biggest risk in AI is not building an inaccurate model. It’s what the model can access.
If you are deploying AI agents and want real governance built into the flow, not layered on after, request early access here: https://t.co/9XIZBGH9OB
Where does legacy IAM break in agentic architectures? What agentic identity does actually look like in practice? And how does MAESTRO threat modeling apply to AI workflows?
https://t.co/8FeptUfldM