Blog
Insights on identity security, access governance, and modern IGA.

Agent Authorization: Gateway or Token? The Answer Is Both
·Jess Starr
Gateway proxy or standards-based token exchange? The two credible models for authorizing AI agents at runtime have complementary strengths, and no enterprise environment is uniform enough for one to cover everything. Why the right question is whether your platform supports both.

Seven Ways Enterprise AI Programs Die
·Kevin Paige
C1's Field CISO on the seven failure patterns that kill enterprise AI programs — shadow tool sprawl, SSO mistaken for authorization, shared service accounts, policy nobody reads, and the review board reborn as an AI Council — and how to convert a gating function into an enabling one.



Introducing agent runtime governance: intent-based access control for AI agents
·Maarten Buis
C1's agent runtime governance routes every AI agent tool call through one governed gateway, scopes each agent to the tools its job needs, and scores every call for risk before it runs so you can block, hold, or redact it.

Introducing Agentic Vault: govern every secret like an identity
·Melody Scheidler
C1's Agentic Vault secures the credentials your people, agents, and service accounts depend on, governing every secret through the same request, approval, and audit path as any other access, with post-quantum protection from day one.


