C1 Transform registration is now open.

Paul Querna

Co-Founder and CTO, C1

Paul Querna is co-founder and CTO of C1. He previously co-founded ScaleFT, the Zero Trust networking company acquired by Okta, which is where he and Alex Bovee first met. He writes about identity architecture, open source, and the security implications of agentic AI.

LinkedIn

17 articles by Paul Querna

  • Engineering

    Terminal Apps need a DOM

    agent-tui runs terminal programs on a PTY and exposes the rendered screen as text or an outline with stable refs. Agents can drive live TUIs, including other AI agents, by snapshotting, pressing keys, and waiting for screen state.

  • Blog

    What MCP doesn't include: governance

    MCP is the protocol everyone is racing to govern. But the protocol itself doesn't include governance. Identity, policy, audit, lifecycle — those still have to come from somewhere. Here's where they come from.

  • Engineering

    Splitting AI Agents to Contain Prompt Injection

    Go behind the scenes of how we built guardrails into Thomas, C1's AI agent—and the industry's first multi-agent identity security platform. This blog breaks down our architecture, trust models, and sandboxing techniques that ensure agents can automate identity governance safely, securely, and transparently.

  • Blog

    The AI Identity Problem

    AI agents are changing the identity landscape, but legacy IAM systems weren’t built for them. These fast-moving, ephemeral identities require dynamic access, machine-speed decisions, and a new model of governance. In this post, we break down the AI identity problem—and what it takes to solve it.

  • Blog

    The Divergent AI Landscape: Making Sense of Agentic AI

    Explore the evolving world of agentic AI. Learn the three core types of AI agents—company, employee, and agent-to-agent—and the identity, security, and governance challenges they introduce.

  • Blog

    The Inevitable AI Wave: Modeling the AI Agent Explosion

    AI agents are set to outnumber humans 25 to 1—and this blog breaks down what that means for identity and access management. Drawing from the evolution of servers to serverless, learn how companies must rethink their approach now or risk being overwhelmed by an imminent surge of short-lived, high-density AI identities.

  • Blog

    Identity Is the New Perimeter — Here’s How to Lock It Down

    Thanks to the success of zero trust, attackers are finding it harder to execute traditional breach tactics—so they've shifted their focus to identity. Here are practical steps you can take to shore up your defenses against identity-based attacks.

  • Blog

    HARBleed: When History Doesn't Repeat, But It Does Rhyme

    The cybersecurity landscape is marked by breaches that serve as learning pivots. The Okta's recent incident shares a thematic lineage with one of the most notorious security lapses in history: Heartbleed. Delve into the C1 coined concept termer "HARBleed," which highlights its procedural kinship with Heartbleed and emphasizing the lurking danger represented by bearer tokens.

  • Blog

    Baton: The Open Source Fabric Powering Identity Security

    Baton, our open-source C1 connector project, provides the connective tissue to communicate and orchestrate identity security workflows to any technology. Learn more about what we've been working on with Baton, and how it furthers our goal of securing workforce identity.

  • Blog

    Redefining Identity Security: C1's Inclusion in the InfraRed 100

    We are thrilled to share that C1 has been recognized as one of Redpoint Venture Capital's InfraRed 100 list.

  • Blog

    Embracing the SaaS Mindset: "There's an App for That"

    "There's an app for that" has become the new norm to navigate the growing software ecosystem. Automation is key to finding this balance.

  • Blog

    Rethinking Access Management: Centralization vs. Decentralization

    Rethinking access management and finding a balance between centralization and decentralization is vital to ensure your organization remains responsive to these changes.

  • Blog

    The Great Convergence of IT and Security

    The lines between IT and Security are becoming increasingly indistinct. This convergence is fostering a new era of collaboration, adaptability, and shared responsibility. Hear our CTO Paul Querna's thoughts on this complex topic and his outlook on the future of the current security climate.

  • Blog

    Secrets, Key Rotation, and the Role of Automation

    GitHub's accidental leak of their SSH RSA server private key sheds light on security best practices. What can we do to prevent other such breaches and increase our security posture. Our CTO Paul Querna gives his take.

  • Blog

    When Threat Models Collide

    Insider and outsider threats are starting to look the same - hackers are stealing identities or logged in sessions. Our approach to a solution? A pragmatic least privilege maturity curve.

  • Blog

    Announcing Baton, an Open Source Toolkit for Auditing Infrastructure User Access

    Announcing Baton, the first open source toolkit to extract, normalize, and interact with identity data from any app, with a standardized but extensible data model.

  • Blog

    Why Identity Needs to Shift Left

    “Shifting left” has become a critical mindset to fix problems in modern security practice that have remained unsolved, despite increased governance and visibility.