top of page



Your Browser Extensions Are Becoming Shadow AI Agents
AI browser extensions can read, rewrite, summarize, and interact with sensitive SaaS data. Learn why they need Shadow AI governance.
Sep 75 min read


Shadow AI in Insurance: Claims Data, Underwriting Support, and Vendor Drift
Shadow AI in Insurance: Claims Data, Underwriting Support, and Vendor Drift
Sep 45 min read


How to Create an AI Approved Apps Program Employees Will Actually Use
Learn how to create an AI approved apps program that gives employees safe, fast options while supporting security, compliance, and vendor governance.
Sep 25 min read


Stop Asking Employees to Self-Report AI Usage
Employee AI self-reporting is useful but incomplete.
Aug 315 min read


Shadow AI for Government Contractors: CUI, Export Control, and the Tools Nobody Approved
Shadow AI for Government Contractors: CUI, Export Control, and the Tools Nobody Approved
Aug 285 min read


How to Audit AI Meeting Bots Before They Capture Sensitive Conversations
How to Audit AI Meeting Bots Before They Capture Sensitive Conversations
Aug 265 min read


Shadow AI in Retail: Loyalty Data, Marketing Tools, and Customer Privacy
Shadow AI in Retail: Loyalty Data, Marketing Tools, and Customer Privacy
Aug 215 min read


How to Build an AI Usage Register for SaaS Applications
A practical guide to building an AI usage register for SaaS applications, including owners, users, data types, training exposure, and controls.
Aug 195 min read


The AI Agent in Your SaaS Stack Is the New Service Account Nobody Owns
AI agents are becoming unmanaged service accounts inside SaaS. Learn why agent discovery, ownership, and access review now matter for AI governance.
Aug 176 min read


The Compliance Industry Has a Discovery Problem And Nobody Wants to Talk About It
The compliance industry built beautiful dashboards on top of a foundation everyone politely pretends is solid. It isn't. Discovery is the hole in the middle.
May 133 min read


How to Prepare Defensible SaaS Compliance Evidence for Your Next SOC 2 Audit
Auditors have grown more sophisticated about SaaS and identity controls. This guide describes how to assemble a defensible evidence package that survives the new questions.
May 133 min read


How to Build a SaaS Offboarding Checklist That Actually Closes Every Access Path
Most offboarding processes terminate at the IdP. The access that remains active afterward is the access that produces post-employment incidents. This guide closes the loop.
May 133 min read


Your CASB Has Been Lying to You for Five Years
Your CASB dashboard is impressively green. That's not because everything is fine. It's because the things going wrong moved off the network three years ago.
May 133 min read


Stop Buying Security Tools. Start Discovering What You Actually Have.
The security team's tool budget keeps climbing. The breach rate doesn't move. Maybe the problem isn't the tools — it's the inventory underneath them.
May 133 min read


How to Build the Business Case for a SaaS Discovery Initiative
Funding for SaaS discovery is often blocked because the value is preventive rather than visible. This guide describes how to articulate the value persuasively.
May 133 min read


A Brief History of OAuth: From Twitter Frustration to Enterprise Authorization Standard
OAuth is now the dominant authorization protocol for cloud applications. Its history explains both its strengths and the security properties that make it difficult to govern.
May 133 min read


How to Audit OAuth Permissions in Google Workspace and Microsoft 365 Without Installing an Agent
OAuth grants are the silent privilege expansion of modern SaaS. This guide describes how to audit them in both major workspaces using only built-in administrator tooling.
May 133 min read


Every Free-Tier SaaS Sign-Up Is a Future Breach Disclosure
Every free-tier sign-up is, statistically, on its way to becoming someone's breach disclosure post. The only question is whether you're the customer or not.
May 133 min read


Defense in Depth Means Something Different in 2026 Than It Did in 2006
Defense in depth was a network concept. It still applies in 2026 — but the layers are no longer about the network. Here is how the model translates to the identity perimeter.
May 133 min read


"Identity Is the New Perimeter": Where the Phrase Came From and Why It Finally Matters
"Identity is the new perimeter" became security cliché around 2015. It became operational reality only recently. The gap between the two is the subject of this piece.
May 133 min read
bottom of page