Resources
Product Blog
Technical deep dives, architecture notes, and engineering write-ups from the SecureAuth product team.
Product Radar: July 2026
Everything we shipped in July, in one place. Lower OTP costs and automatic rate limits, passkeys that survive a domain change, more access control on the config APIs, plus passwordless low-risk sign-ins, flexible Dashboard access and native OpenLDAP.
Agent Authority: the runtime control plane for AI agents
AI agents are moving out of demos and into real work. But, once an agent can act on your tools, who makes sure it only does what it should? Agent Authority is the runtime control plane and governance layer that lets you deploy agents securely across your organization.
Your IdP authorized the connection, not the action
First in a three-part series. EMA and ID-JAG are a genuinely good open standard for governing the door, and they were never built to decide whether a specific action should run. Here is exactly where connection governance stops.
The Agent Authority pattern
Part 3 of 3. If SCIM cannot be the kill switch, something on your side of every vendor boundary must be. Agent Authority: token custody, per-call ticket exchange, and revocation measured in milliseconds.
Your agent does not log in. SCIM does not know that.
Part 2 of 3. SCIM is a wire protocol, not a guarantee, and your blast radius is the worst vendor in your stack. Why SCIM-based revocation cannot be the kill switch you need for agent tokens.
The new JML gap: agents outlive their humans
Part 1 of 3. Deprovisioning revokes the human in Okta, but the agent runtime on a personal laptop keeps refreshing cached tokens long after Monday. The new shape of the Joiner-Mover-Leaver problem.
Ready to secure your identity stack?
Talk to our team about how SecureAuth delivers continuous identity security across workforce, customer, and AI agent identities.