
Paul Querna
Co-Founder and CTO, C1
Paul Querna is co-founder and CTO of C1. He previously co-founded ScaleFT, the Zero Trust networking company acquired by Okta, which is where he and Alex Bovee first met. He writes about identity architecture, open source, and the security implications of agentic AI.
LinkedIn17 articles by Paul Querna
EngineeringTerminal Apps need a DOM
agent-tui runs terminal programs on a PTY and exposes the rendered screen as text or an outline with stable refs. Agents can drive live TUIs, including other AI agents, by snapshotting, pressing keys, and waiting for screen state.
BlogWhat MCP doesn't include: governance
MCP is the protocol everyone is racing to govern. But the protocol itself doesn't include governance. Identity, policy, audit, lifecycle — those still have to come from somewhere. Here's where they come from.
EngineeringSplitting AI Agents to Contain Prompt Injection
Go behind the scenes of how we built guardrails into Thomas, C1's AI agent—and the industry's first multi-agent identity security platform. This blog breaks down our architecture, trust models, and sandboxing techniques that ensure agents can automate identity governance safely, securely, and transparently.
BlogThe AI Identity Problem
AI agents are changing the identity landscape, but legacy IAM systems weren’t built for them. These fast-moving, ephemeral identities require dynamic access, machine-speed decisions, and a new model of governance. In this post, we break down the AI identity problem—and what it takes to solve it.
BlogThe Divergent AI Landscape: Making Sense of Agentic AI
Explore the evolving world of agentic AI. Learn the three core types of AI agents—company, employee, and agent-to-agent—and the identity, security, and governance challenges they introduce.
BlogThe Inevitable AI Wave: Modeling the AI Agent Explosion
AI agents are set to outnumber humans 25 to 1—and this blog breaks down what that means for identity and access management. Drawing from the evolution of servers to serverless, learn how companies must rethink their approach now or risk being overwhelmed by an imminent surge of short-lived, high-density AI identities.
BlogIdentity Is the New Perimeter — Here’s How to Lock It Down
Thanks to the success of zero trust, attackers are finding it harder to execute traditional breach tactics—so they've shifted their focus to identity. Here are practical steps you can take to shore up your defenses against identity-based attacks.
BlogHARBleed: When History Doesn't Repeat, But It Does Rhyme
The cybersecurity landscape is marked by breaches that serve as learning pivots. The Okta's recent incident shares a thematic lineage with one of the most notorious security lapses in history: Heartbleed. Delve into the C1 coined concept termer "HARBleed," which highlights its procedural kinship with Heartbleed and emphasizing the lurking danger represented by bearer tokens.
BlogBaton: The Open Source Fabric Powering Identity Security
Baton, our open-source C1 connector project, provides the connective tissue to communicate and orchestrate identity security workflows to any technology. Learn more about what we've been working on with Baton, and how it furthers our goal of securing workforce identity.
BlogRedefining Identity Security: C1's Inclusion in the InfraRed 100
We are thrilled to share that C1 has been recognized as one of Redpoint Venture Capital's InfraRed 100 list.
BlogEmbracing the SaaS Mindset: "There's an App for That"
"There's an app for that" has become the new norm to navigate the growing software ecosystem. Automation is key to finding this balance.
BlogRethinking Access Management: Centralization vs. Decentralization
Rethinking access management and finding a balance between centralization and decentralization is vital to ensure your organization remains responsive to these changes.
BlogThe Great Convergence of IT and Security
The lines between IT and Security are becoming increasingly indistinct. This convergence is fostering a new era of collaboration, adaptability, and shared responsibility. Hear our CTO Paul Querna's thoughts on this complex topic and his outlook on the future of the current security climate.
BlogSecrets, Key Rotation, and the Role of Automation
GitHub's accidental leak of their SSH RSA server private key sheds light on security best practices. What can we do to prevent other such breaches and increase our security posture. Our CTO Paul Querna gives his take.
BlogWhen Threat Models Collide
Insider and outsider threats are starting to look the same - hackers are stealing identities or logged in sessions. Our approach to a solution? A pragmatic least privilege maturity curve.
BlogAnnouncing Baton, an Open Source Toolkit for Auditing Infrastructure User Access
Announcing Baton, the first open source toolkit to extract, normalize, and interact with identity data from any app, with a standardized but extensible data model.
BlogWhy Identity Needs to Shift Left
“Shifting left” has become a critical mindset to fix problems in modern security practice that have remained unsolved, despite increased governance and visibility.