
Claire McKenna
Director of Corporate Marketing, C1
Claire McKenna is Director of Corporate Marketing at C1 and writes much of the practical guidance published here, from third-party access management and the joiner-mover-leaver lifecycle to running an IAM risk assessment.
75 articles by Claire McKenna
GuideAgentic AI Security Risks: The OWASP Top 10 and How to Fix Them
Agentic AI security risks run through identity. See the OWASP Top 10 for Agentic Applications, what each risk looks like, and the controls that fix it.
GuideAI Agent Runtime Security: Governing What Agents Do
AI agent runtime security governs what an agent does while it runs. Learn tool call authorization, risk scoring, approval holds, and how to revoke access.
GuideSecuring AI Agent Credentials: A Guide to Stopping Secrets Sprawl
AI agents hold credentials nobody owns or rotates. Learn where agent secrets sprawl, why vaults built for humans fall short, and how to lock them down.
GuideShadow AI: How to Discover and Govern Unsanctioned AI
Shadow AI is any AI tool, agent, or MCP server running without approval or an owner. Learn where it hides, why DLP and EDR miss it, and how to govern it.
Guide13 IGA Best Practices for Modern Identity Security
Identity governance failures are behind some of the most costly breaches of the last decade. C1 outlines 13 proven IGA best practices that help security teams enforce least privilege, automate access lifecycles, and stay continuously audit-ready in 2026.
GuideHow to Conduct an IAM Risk Assessment
Step-by-step IAM risk assessment methodology covering identity inventory, access control gap analysis, orphaned accounts, SoD violations, privilege escalation risks, and automated remediation. Built for security and IT teams in regulated industries.
GuideThird-Party Access Management
Third-party breaches cost organizations $4.91M on average. Learn how to secure vendor and contractor access with Zero Trust, JIT access, and automated lifecycle controls from C1.
GuideVendor Access Management
Unmanaged vendor access is one of the top causes of enterprise data breaches. Learn how to govern the full vendor identity lifecycle — from onboarding to automated offboarding — with C1.
BlogAudit Proofing Your AI Implementation
Brad Thies (BARR Advisory) and Will Bengtson (C1 CISO) on how to govern AI adoption without slowing it down: access, risk, documentation, and the frameworks that actually matter.
BlogGoverning AI at Enterprise Speed: Announcing C1 integrations for Claude, OpenAI, and Cursor
C1 now governs the three most widely adopted AI platforms in the enterprise — Claude, OpenAI, and Cursor — with the same unified visibility, dynamic policy enforcement, and automated lifecycle workflows that cover your entire stack.
BlogAI Access Management: Your Questions, Answered
Security, IT, and GRC teams have questions about governing AI agent access. Here are the answers — from authentication and credentials to approvals, compliance, and license savings.
BlogFrom Risk Signal to Governance Action: Introducing C1 + CrowdStrike Falcon Next-Gen Identity Security
Announcing C1's strategic integration with CrowdStrike Falcon® Next-Gen Identity Security. Falcon risk scores now ingest directly into C1 — attached to identities, actionable as conditions in governance policies, and capable of triggering automated access decisions the moment risk changes.
BlogThree Properties Identity Must Have in the Agentic Era
Identity governance was failing before AI agents arrived. With multiple agents per employee spawning their own, here's what infrastructure must look like to survive.
BlogYour AI Strategy Has a Blind Spot
AI governance isn't a new silo. It's an identity problem. See how identity-first governance makes every team AI-native without sacrificing control.
BlogIntroducing Functions: Extend Identity Governance With Custom Code, Built Directly Into C1
Extend identity governance with C1 Functions. Write and run custom TypeScript code securely to automate workflows, provisioning, and policy logic.
BlogHow RRCU Uses C1 Automations to Streamline Identity Operations
Automate identity governance with C1 Automations. See how Red River Credit Union streamlined onboarding, offboarding, access reviews, and platform migrations using no-code workflows, AI optimization, and real-time identity data to reduce manual effort and improve security.
GuideAccess Request Management: The Complete Guide for Security Teams
A complete guide to access request management for security teams. Learn how to balance employee productivity with least privilege, automate approvals, and eliminate rubber-stamping.
GuideThe Joiner-Mover-Leaver Process for IAM
Discover how to modernize your Joiner, Mover, and Leaver process for IAM with event-driven architecture, zero-touch provisioning, and real-time governance.
BlogWhat Identity Governance Looks Like When Automation Does the Work
What does identity governance look like when automation does the work? New data from C1 customers shows how organizations govern access at scale with policy and automation.
BlogThe Modern IGA RFP Guide: How to Choose the Right Identity Governance Platform in 2026
Finding the right IGA solution in 2026 can be a challenge. Learn how to build an effective RFP, evaluate vendors, and choose a platform that simplifies identity security, scales with your business, and accelerates time to value.
GuideTop 5 Challenges in IGA (and How to Solve Them)
Modern IGA challenges have evolved beyond manual spreadsheets. Learn how to tackle AI risks, non-human identities, and data quality issues to build a scalable governance program.
BlogMeet Automations Architect: Build Automated Workflows in Minutes
Meet Automations Architect, C1’s AI assistant for identity automation. Build, edit, and deploy secure workflows using natural language.
BlogThe IGA Maturity Curve: Shifting from Reviews to Assurance
A GRC leader’s take on why manual UARs are breaking down and what continuous identity assurance looks like in practice.
Guide13 Step Vendor Offboarding Checklist for Legal & IT Teams
This 13-step vendor offboarding checklist covers access revocation, contract review, data destruction, and compliance documentation for security & IT teams.
BlogTake Full Control of Identity Data with Advanced Attribute Mapping in Super Directory
Learn how Super Directory uses fallback mappings and CEL expressions to precisely map user attributes and match identities across apps in C1.
BlogWhy User Access Reviews Are Becoming a Relic of the Past
UARs aren’t enough for modern identity risk. Discover how continuous, policy-driven controls replace review-centric governance without breaking audits.
GuideContractor Access Management Process for Security Teams
Mismanaged contractor access is one of the most exploited attack vectors in enterprise security. This guide covers the frameworks and tools to lock it down.
Blog10 IGA Metrics Every Security Team Should Use to Measure Success
Still measuring IGA by checklists? Learn the identity governance metrics that show real risk reduction and efficiency in 2026.
BlogNIST’s New Cyber AI Profile Signals a Shift: AI Security Starts With Identity
NIST released a new Cyber AI Profile outlining how to secure AI at scale. See why identity is central to AI security and what teams must do next.
BlogHow Dynamic Access Enables Least Privilege
See how C1 enables dynamic access control using real-time context to grant and revoke access as work changes.
BlogAccess Profiles: A Smarter Way to Manage and Provision Access
Learn what access profiles are in C1, how they group entitlements, enable automation, and simplify access requests, reviews, and onboarding at scale.
BlogIncremental Sync: How C1 Keeps Identity Data Fresh in Real Time
Learn how C1’s incremental sync keeps identity and access data fresh using event-based updates for real-time identity governance.
GuideKey Differences Between JIT Access and Traditional PAM
Just-in-time (JIT) access and privileged access management (PAM) are methods of controlling and monitoring privileged access. Learn more about the important differences between the two and why JIT access may be the management method you need to stay secure.
GuideSCIM Provisioning Explained (+ Benefits and Limitations)
Learn what SCIM provisioning is, the benefits of using SCIM, common SCIM workflows, and the limitations of SCIM in this ultimate technical guide.
BlogRisks of Weak Identity Governance in 2026
Identity is the fastest-growing attack surface in 2026. See how weak identity governance, manual UARs, and AI agents increase risk.
BlogHuman vs. Non-Human Identities Explained
Discover how non-human identities like service accounts and AI agents work, why they create new security risks, and how to govern them effectively.
BlogIdentity Maturity in 2026: How the Best Teams Move Forward
Learn how leading teams build visibility, governance, and automation to reduce risk and scale securely.
BlogSoD in Modern Identity Security: How C1 Prevents Access Conflicts Before They Become Risk
Learn how C1 detects, prevents, and remediates access conflicts to enforce separation of duties and strengthen your identity security program.
BlogSo Long, Standing Access: Inside Instacart’s Just-In-Time Access Playbook
Learn how Instacart built a fully automated, policy-driven, engineering friendly just-in-time (JIT) access program with C1.
BlogIntroducing C1’s Advanced Microsoft Teams Integration: Identity Security Where Your Team Works
C1 now brings secure access workflows directly into Microsoft Teams, helping employees complete reviews and requests without switching tools. Reduce friction, speed up decisions, and improve adoption with identity security that fits naturally into the flow of work.
BlogHere's What Your Auditor Thinks About Agentic AI
Learn how agentic AI is changing the audit process, magnifying risk fundamentals, and raising the compliance floor.
BlogMeet Super Directory: Identity Orchestration Starts Here
Introducing Super Directory, C1’s single source of truth for identity data. Standardize attributes, manage profile types and groups, automate updates across your stack, and strengthen security with clean, consistent, centralized identity management.
BlogHow Tide Uses C1 to Operationalize Least Privilege at Scale
Modernizing identity at scale: See how Tide adopted C1 and Terraform to move from static, role-based access to needs-based least privilege, automate birthright and just-in-time access, and streamline approvals for 2,000 users across critical systems.
BlogHow Weaviate Automated Privileged Access And Turned Zero Trust Into A Customer Win
C1 helped Weaviate eliminate standing access and cut manual access management from two days to two hours per week with fully automated JIT workflows.
BlogBuilding Trust Through Connector Reliability
Reliable IGA connectors are critical to identity security. Learn how C1 ensures trust and accuracy with anomaly detection, monitoring, and safe controls.
BlogThe Power of Policies in C1
Discover how C1’s flexible, layered policies automate access reviews, approvals, and least privilege at enterprise scale.
BlogCustom Connectors: Simplifying Integrations Without Code
Learn how C1 makes custom connectors fast and flexible with 300+ out-of-the-box integrations, YAML no-code options, and the Baton SDK. Simplify app onboarding, streamline identity governance, and scale your access management program with ease.
BlogVirtual Entitlements: Simplifying Access and Bundling Permissions
Discover how C1’s virtual entitlements simplify identity management by translating technical group names into plain language and bundling permissions into intuitive apps. Learn real-world use cases that improve clarity, reduce IT overhead, and streamline access requests.
GuideComparing Traditional vs AI-Powered IAM Systems
Is your rule-based IAM system enough? This guide compares traditional vs AI-powered IAM to demonstrate how AI delivers a more dynamic and secure approach.
BlogManaging Identity as Code: How to Use Terraform with C1
Discover how Terraform and C1 turn identity management into code. Automate policies, rotate secrets, manage access profiles, and gain auditability for secure, efficient, and consistent identity governance.
BlogAccelerating Integrations with AI-Generated Connectors
Discover how C1 uses AI-generated connectors enable faster integrations, greater scalability, and complete visibility across your environment.
BlogSimplifying FedRAMP Compliance with C1
Learn what FedRAMP is, why it matters for cloud service providers, and how C1 simplifies compliance with automated user access reviews, data accuracy reporting, and modern identity governance to accelerate authorization and reduce risk.
BlogFrom Manual to Intelligent: Using AI to Mature Your IGA Program
See how AI can mature your identity governance and administration (IGA) program. C1’s AI agent Thomas automates approvals, access reviews, and policy enforcement, while Copilot, an interactive assistant, streamlines workflows, surfaces risk insights, and guides smarter decisions. Scale governance for human and non-human identities, reduce IT overhead, and enforce least privilege at enterprise scale.
BlogHow UAR Automation Improves Audit Readiness and Reduces Risk
Automate user access reviews to save time, cut risk, and boost audit readiness. See how C1 transforms UARs into continuous control.
BlogSecurity vs. Compliance: Bridging the Gap with C1
Learn why modern identity governance must shift from checkbox compliance to a security-first approach with proactive access reviews, least privilege, and automation that keeps you audit-ready.
BlogMeet IVIP: A New Era of Identity Visibility
Discover Gartner’s new IVIP category and how C1 delivers unified identity visibility and intelligence to secure every identity.
BlogHow Treasure Data Transformed User Access Reviews with C1
Discover how Treasure Data transformed its user access review program from manual spreadsheets to intelligent, continuous reviews with C1—cutting 160+ hours annually, expanding scope, and achieving meaningful security outcomes beyond compliance.
BlogFive Ways to Streamline SOX Compliance with C1
C1 automates access reviews, centralizes reporting, and streamlines SOX compliance for faster, audit-ready results.
BlogBuild vs. Buy for IGA: Why C1 Wins Every Time
Compare the true costs of building vs. buying an identity governance solution and see why C1 delivers faster, more cost‑effective, and future‑ready results.
BlogFour Ways to Use C1 Automations to Strengthen Security
Automate identity security with speed and precision. Learn how C1 Automations help security teams reduce risk, enforce least privilege, and respond to high-risk access changes in real time without adding operational overhead.
Guide4 Modern IAM Challenges & How to Solve Them
Learn the top modern IAM challenges, from multi-cloud complexity to security threats, and get actionable solutions to solve them effectively.
BlogU.S. vs. U.K. Perspectives on AI and Security
A firsthand look at how AI adoption, regulation, and security culture differ between the U.S. and U.K. and what that means for identity governance in a global world.
BlogHow to Streamline IT Operations with C1 Automations
Learn how C1 Automations helps IT teams eliminate manual work, reduce license costs, and streamline access workflows at scale.
BlogRethinking Identity for an AI-native Future
SaaS is being redefined by agentic AI. This blog explores how the shift is transforming identity security, creating new challenges and opportunities for platforms built to govern at AI scale.
BlogHow to Automate ILM with C1
Learn how to automate identity lifecycle management (ILM) with C1 to streamline onboarding, reduce risk, and simplify access changes across your organization.
BlogThe Pressure Is Real: Inside the Stress and Resilience of Today’s Security Leaders
Explore how today’s security leaders are navigating rising identity threats, intense pressure, and limited resources—with resilience, urgency, and a mission-first mindset.
BlogManaging Non-Human Identity Risk in 2025
In 2025, non-human identities from service accounts to AI agents have become the fastest-growing and most urgent identity risk, forcing security teams to rethink access governance at scale. Learn more from our 2025 FIS report.
BlogThe Cure for IGAD: Identity Governance Anxiety Disorder
At C1, we talk to security and IT teams every day. And we’ve noticed a troubling trend. We’re not doctors, but the symptoms are hard to ignore. After years of watching identity pros suffer in silence, we’re finally giving the condition a name: Identity Governance Anxiety Disorder.
BlogKey Takeaways From the 2025 Future of Identity Security Report
The 2025 Future of Identity Security Report reveals how security leaders are accelerating into an AI-driven era: embracing risk, scaling up identity budgets, and rethinking access for both humans and machines. Read on for key trends shaping the next wave of identity security.
BlogThe State of Agentic AI in Identity Security
Security leaders aren’t just experimenting with AI—they’re rapidly integrating agentic AI into high-stakes workflows like identity provisioning and network defense. C1’s 2025 Identity Security Outlook Report reveals that urgency is driving adoption, but with thoughtful strategies and real concern for risk.
BlogAI in Identity and Access Management: Are You Ready?
While AI transforms identity and access management, it creates urgent security risks. Understand the IAM challenges posed by AI agents & the path forward.
GuideLearn the Key Phases of Identity Lifecycle Management
Learn the key phases of identity lifecycle management, from user provisioning and modification to secure deprovisioning. Simplify the ILM process with C1.
GuideThe Identity and Access Provisioning Lifecycle Explained
Understand the identity and access provisioning lifecycle to ensure users get the right access promptly and securely, from onboarding to offboarding.
BlogIntroducing Arbitrary Access Control by C1
Embrace the chaos. Introducing Arbitrary Access Control: the first AI-powered access control tool designed to ignore your policies and do its own thing.
BlogCrawl, Walk, Run: Solving Your Identity Crisis
Managing identity security is increasingly complex, with blind spots, over-permissioned users, and the rise of non-human identities. A crawl, walk, run approach helps organizations gain visibility and automate identity governance for stronger security.