Voices of the Identity Underground | Blog
Share your voice. Shape the conversation.
Insights, perspectives, and real-world lessons from members of The Identity Underground, rising out from the underground to move the discipline of identity security forward.
Featured post
Industry & Innovation
Why "Who" Is No Longer Enough: Building a Governance Framework for AI Agents
Industry & Innovation
The Missing Feedback Loop in AI Agent Authorization
Discover how the OpenID Shared Signals Framework turns runtime anomalies into risk scores that can lock an agent out in real time.
Industry & Innovation
AI Agents and the Authorization Gap: Why Static Permissions Don't Work
Static service accounts give AI agents fixed permissions that don't match how they actually behave in production. That's why authorization needs to move to the tool-call level using AuthZEN.
Executive Summary
Detection Now Arrives After the Attack is Over
The latest meetings with The Identity Underground members unpack Mythos and frontier AI models.
Executive Summary
The Agent You Authorized is Not the Agent Running Today
The latest meetings with The Identity Underground members unpack not what an agent is, but whether anyone can see what it has become.
Industry & Innovation
Real-Time Identity Governance: Moving Beyond Periodic Access Reviews
Identity risk changes every day. Most governance still runs on a calendar.
Industry & Innovation
Where Did All the Entitlements Go?
When authorization moves out of applications, governance must follow.
Industry & Innovation
Passkeys in Practice: Synced Convenience vs Hardware-Backed Assurance?
Industry & Innovation
The Agentic Paradox: Why Your 10-Year-Old Security Stack Is an Open Door
Identity in Depth
You Already Have the Pieces. Now Build It.
Stitching existing standards into end-to-end assurance for agentic identity
Executive Summary








