Blog
AI security and the identities behind it: coding agents, AI accounts, MCP servers, AI agents and the non-human majority.
What security teams miss about coding agents
Your vendor review covered the model. It didn't cover what Claude Code can run, read and install on a developer's laptop.
Read the article- AI Security · Sai Vashisht · October 2026
What an AI inventory can't tell you
The register says Claude Code is approved. It doesn't say which credential the agent runs on, what it can reach, or who pulls access when it does something it shouldn't.
- Research · Sai Vashisht · July 2026
Keys That Never Die
A documentation audit of 20 credential configurations across 19 developer, cloud, SaaS and data platforms finds that only 7 expire by default.
- Guide · Sai Vashisht · July 2026
Securing AI Agent Identities: A Practical Guide
How to give every AI agent a real identity, watch it at runtime, keep delegation narrow, and govern the fleet, grounded in MCP, OAuth token exchange, and the OWASP NHI Top 10.
- Point of View · Sai Vashisht · June 2026
The Non-Human Majority
Most enterprise identities are no longer human, and the gap between what they can do and what we can govern is the defining security problem of the agentic era.
