blog/
45 pages · Updated September 7, 2026
Pages
- OAuth on MCP: The Comprehensive Implementation Guide
- Agent Identity Security: Authentication, Authorization, and Trust in AI Systems
- Best Practices for AI Identity Governance
- A poisoned Linear ticket told our AI agent to leak the team. It tried three ways. None worked.
- Agent Identity Is Becoming a Protocol Layer, but Tool Calls Still Need Runtime Authorization
- Securing Coding Agents: What You Need to Know
- Zero Standing Privileges: What It Is, How to Implement It, and Why AI Agents Need It
- Least Privilege in AI Agents and Agentic Identity
- Agent Identity Is Not Agent Authorization: What Entra Agent ID Still Leaves to Runtime Policy
- Agent Identity vs. Service Accounts: Why Scoped Tokens Still Need Runtime Authorization
- Tool-Call Safety Is Not Text Safety: Why Coding Agents Need Action-Time Authorization
- OPA for Protecting AI Agents and Agentic Stacks
- Read-Only Is a Trust Level, Not a Feeling: How to Govern AI Ops Agents Before They Remediate Production
- Authentication vs. Authorization in MCP: What Atlassian Rovo Shows About OAuth, API Tokens, and Tool Calls
- When AI Subagents Call MCP Tools, Who Owns the Permission Decision?
- RBAC vs ReBAC for AI Agents: Best Authorization Model for Secure Agentic Systems
- Coding Agent Sandboxes Don't Solve Credential Authorization
- Agent-Generated APIs Need Governance Before They Become Agent-Callable Tools
- Trust Levels for Coding Agents: How to Decide Which Commands and MCP Tools Can Run Automatically
- Best Practices for Multi-Tenant Authorization
- MCP Auth vs Tool-Call Authorization After the 2026-07-28 Spec
- Zero Standing Permissions for AI Agents: Lessons from Hermes Blank Slate and Toolset Pinning
- Implementing Fine-Grained Postgres Permissions for Multi-Tenant Applications
- Can AI Generate Authorization Policy Safely?
- Permit.io Blog - Authorization Guides, Tutorials and News
- MCP in ERP: Why Agentic Business Workflows Need Runtime Authorization
- Payment Is Not Permission: How to Authorize Paid MCP Tool Calls
- What the NSA Agentic AI Advisory Actually Requires
- MCP Server Supply Chain Is Runtime Supply Chain: Tool Manifests Need Policy and Evidence
- Shared Agent Memory Is a Permissions Problem
- How Security Teams Review an MCP Gateway for SOC 2 + HIPAA
- When the AI Gateway Becomes the Blast Radius: Lessons from the LiteLLM MCP RCE Chain
- Claude Code MCP Token Theft Shows Why OAuth Tokens Need Runtime Tool-Call Authorization
- Agent Identity Is Not Enough: From DIDs and AI Control Towers to Runtime Permissions
- MCP Auth vs Agent Authorization: Why OAuth Alone Doesn’t Solve Agent Security
- Prompt Injection Is an Authority-Promotion Failure, Not Just a Bad Prompt
- OpenAPI-to-MCP Turns Every API Into an Agent Tool. The Missing Piece Is Endpoint-Level Policy
- Zero Standing Permissions for Coding and Automation Agents
- OPAL + OPA VS XACML
- Agent Audit Logs Need a Causal Commit Log, Not Just Tool Traces
- CVE-2026-49257: Why MCP Database Servers Need Fail-Closed Authorization
- MCP Auth Bypasses Show Why Tool Calls Need Runtime Authorization
- OPAL - an Authorization Service for Fine-Grained Permissions
- MCP Gateway vs MCP Proxy: What’s the Difference, and Why It Matters in Production
- How to Govern AI Agents Operating Cloud and API Control Planes Through MCP