top of page



How to Build an AI Usage Register for SaaS Applications
A practical guide to building an AI usage register for SaaS applications, including owners, users, data types, training exposure, and controls.
a few seconds ago5 min read


The Compliance Industry Has a Discovery Problem And Nobody Wants to Talk About It
The compliance industry built beautiful dashboards on top of a foundation everyone politely pretends is solid. It isn't. Discovery is the hole in the middle.
May 133 min read


How to Prepare Defensible SaaS Compliance Evidence for Your Next SOC 2 Audit
Auditors have grown more sophisticated about SaaS and identity controls. This guide describes how to assemble a defensible evidence package that survives the new questions.
May 133 min read


How to Build a SaaS Offboarding Checklist That Actually Closes Every Access Path
Most offboarding processes terminate at the IdP. The access that remains active afterward is the access that produces post-employment incidents. This guide closes the loop.
May 133 min read


Your CASB Has Been Lying to You for Five Years
Your CASB dashboard is impressively green. That's not because everything is fine. It's because the things going wrong moved off the network three years ago.
May 133 min read


Stop Buying Security Tools. Start Discovering What You Actually Have.
The security team's tool budget keeps climbing. The breach rate doesn't move. Maybe the problem isn't the tools — it's the inventory underneath them.
May 133 min read


How to Build the Business Case for a SaaS Discovery Initiative
Funding for SaaS discovery is often blocked because the value is preventive rather than visible. This guide describes how to articulate the value persuasively.
May 133 min read


A Brief History of OAuth: From Twitter Frustration to Enterprise Authorization Standard
OAuth is now the dominant authorization protocol for cloud applications. Its history explains both its strengths and the security properties that make it difficult to govern.
May 133 min read


How to Audit OAuth Permissions in Google Workspace and Microsoft 365 Without Installing an Agent
OAuth grants are the silent privilege expansion of modern SaaS. This guide describes how to audit them in both major workspaces using only built-in administrator tooling.
May 133 min read


Every Free-Tier SaaS Sign-Up Is a Future Breach Disclosure
Every free-tier sign-up is, statistically, on its way to becoming someone's breach disclosure post. The only question is whether you're the customer or not.
May 133 min read


Defense in Depth Means Something Different in 2026 Than It Did in 2006
Defense in depth was a network concept. It still applies in 2026 — but the layers are no longer about the network. Here is how the model translates to the identity perimeter.
May 133 min read


"Identity Is the New Perimeter": Where the Phrase Came From and Why It Finally Matters
"Identity is the new perimeter" became security cliché around 2015. It became operational reality only recently. The gap between the two is the subject of this piece.
May 133 min read


Your CISO Doesn't Actually Know What Apps You Use (Sorry)
Your CISO has a list of the apps they think you use. They're confident in it. They will defend it in board meetings. It will also be wrong. Here's why.
May 133 min read


Procurement Hasn't Been the Source of Truth for SaaS Since 2018
Procurement was a great choke point. It also stopped being one years ago. If your SaaS inventory comes out of procurement, your inventory is a fan-fic of your environment.
May 133 min read


How to Detect AI Features Quietly Enabled Inside the SaaS Applications You Already Use
AI capabilities are being added to SaaS products at unprecedented pace, often by default. This guide describes how to detect them without depending on vendor notifications.
May 133 min read


Five Compliance Frameworks Every Security Team Will Hear About in 2026
Compliance frameworks proliferate, but a small number dominate practitioner conversations in any given year. Here is the 2026 short list and what each one actually requires.
May 133 min read


A Field Guide to the Cloud and SaaS Security Acronym Soup: CSPM, CWPP, CNAPP, CIEM, SSPM, DSPM, ASPM
The acronym population in cloud and SaaS security has grown faster than most teams can track. This guide explains what each category actually addresses, in plain terms.
May 133 min read


How to Conduct a 48-Hour Pre-Audit SaaS and AI Risk Assessment
Pre-audit assessments often run for weeks and surface issues too late to remediate. A focused 48-hour approach can recover the schedule and protect the audit outcome.
May 133 min read


How to Locate Unauthorized AWS, Azure, and GCP Accounts Across Your Organization
Cloud accounts created outside the corporate organization are common, persistent, and rarely visible to CSPM. This guide outlines a structured way to find them.
May 133 min read


The SolarWinds Breach: What Most Retrospectives Got Right, and What They Quietly Missed
The SolarWinds story is widely told as a supply-chain incident. The post-implant identity activity, less widely covered, contains the deeper lesson for 2026.
May 133 min read
bottom of page