Applied IAM
Blogs

Identity security, written by the people who deliver it

Field notes on privileged access, governance and the platforms we implement — what actually happens on a rollout, not what the datasheet says.

Archive

Everything else we have written

Blog

SailPoint vs Saviynt: What Actually Differs Once You Deploy Them

The two pages that rank highest for this question are written by SailPoint and by Saviynt. Here is the version from people who deploy identity governance for a living.

Aug 31, 2026
Blog

CyberArk Competitors: An Implementer's Honest Comparison

Most CyberArk PAM comparisons are written by vendors selling against it. Here is what actually differs, from a team that deploys these platforms.

Aug 25, 2026
Blog

Zero-Knowledge Encryption Explained — And Is Keeper Zero-Knowledge?

Zero-knowledge encryption keeps your data unreadable to the provider. Here's how the architecture works and how Keeper implements it.

Aug 21, 2026
Blog

What Is a Password Vault? How Vaulting Works and Why It Beats Spreadsheets

A password vault encrypts and centralizes credentials so only authorized users can access them — a major step up from spreadsheets or sticky notes.

Aug 14, 2026
Blog

What Is PAM (Privileged Access Management)? A Plain-English Guide

PAM secures the accounts with the most system power. Here's what privileged access management does and why attackers go after these credentials first.

Jul 28, 2026
Blog

Identity Security Posture Management: What ISPM Is and Whether You Need It

Owning PAM and IGA is not the same as knowing your identity risk. What identity security posture management actually measures.

Jul 27, 2026
Blog

Just-in-Time Access and Zero Standing Privileges: What It Takes to Get There

Standing privilege is what turns one compromised account into a bad week. Here is how just-in-time access actually works in practice.

Jul 27, 2026
Blog

Non-Human Identity Management: Service Accounts, Machine Identities and Secrets

Service accounts, API keys and workload identities outnumber your people — and almost nobody reviews them. Where to start.

Jul 27, 2026
Blog

RBAC vs ABAC vs PBAC: Which Access Control Model Should You Actually Use?

Three access control models, three different failure modes. How RBAC, ABAC and policy-based access control actually compare in practice.

Jul 27, 2026
Blog

User Access Reviews: Why Access Certification Fails and How to Fix It

Managers approve 400 entitlements in eleven minutes and the campaign passes. Here is what makes an access review genuinely work.

Jul 27, 2026
Blog

CyberArk vs Okta: Why You Probably Need Both, Not Either

"Is Okta or CyberArk the better choice?" is one of the most common questions we hear — and it's usually the wrong question. They aren't competing for the same job.

Jul 24, 2026
Blog

IAM vs IGA: The Difference That Shows Up at Audit Time

You deployed SSO. You turned on MFA. Then the auditor asked 'who has access to what, and should they?' — and that question lives in the gap between IAM and IGA.

Jul 24, 2026
Blog

How Hard Is It to Actually Roll Out CyberArk Across a Distributed Workforce?

The honest answer: not as hard as a stalled project makes it look, but only if you phase it by risk instead of trying to boil the ocean.

Jul 24, 2026
Blog

What to Look for in an IAM Implementation Partner

The platform you buy matters less than who deploys it. Here's what actually distinguishes an IAM partner that finishes the job from one that leaves it half-done.

Jul 24, 2026
Blog

WP-SHELLSTORM: What an Exposed Hacker Server Teaches Us About Credential Theft at Scale

An exposed hacker server revealed a mass WordPress backdoor campaign that also harvested cloud credentials from corporate systems. Here are the identity-security lessons.

Jul 10, 2026
Blog

The Rogue Agent Vulnerability: What AI Platform Flaws Mean for Identity and Data Security

A flaw in Google's Dialogflow CX reportedly allowed silent conversation hijacking — here's what it reveals about AI platform access controls.

Jul 8, 2026
Blog

81 Million Password Spray Attempts Against Azure CLI: What the MFA Gaps Tell Us

Over 81 million login attempts targeted Azure CLI in under two weeks — and MFA gaps let attackers through even where it was supposedly enabled.

Jul 1, 2026
Blog

Data Breach Prevention in 2026: How Stolen Credentials Fuel Breaches — and How Keeper Stops Them

The biggest breaches of 2026 didn't start with a zero-day — they started with a stolen password. Here's how credential-based attacks work, and how Keeper stops them.

Jun 25, 2026

See where your privileged access really stands

A free audit is 30 minutes with a certified engineer, findings in writing. No cost, no obligation.