Blog
Insights on identity security, access governance, and modern IGA.

Your Engineers Are Building the Same Agent Twelve Times. Here's How to Stop It.
·Kevin Paige
Our Field CISO on the producer/consumer flywheel — the six asset classes that flow through an internal agent marketplace, why reuse is a good outcome but a bad goal, the deprecation ritual that keeps the marketplace credible, and what federation actually means.

Anatomy of a decoy: what happens when someone uses a stolen credential
·Melody Scheidler
A decoy credential looks exactly like a real one and belongs to no workload, so using it is unambiguous. Here is the path a request takes through C1.ai when someone tries a planted decoy: what the caller gets back, and the critical finding that lands on your side.


C1 Deploy: Onboarding that does the setup for you
·Melody Scheidler
Most identity deployments begin with a long setup project. Ours begins with a question: what are you trying to get done first? Pick a goal, connect a directory, and C1 AI builds the plan from your live environment and runs the setup work for you, with every action gated on your approval.

The Most Important AI Meeting You'll Have This Quarter Costs Nothing
·Kevin Paige
Our Field CISO on the ADAPT phase — the one honest executive meeting that starts an agentic AI program, the failure graveyard worth naming out loud, the permanent tension between control and reuse, and the four written outputs including kill criteria for the program itself.




