Access Control
Practical signals an AI agent can use to judge whether the party making a request actually has standing to make it.
Rules for AI agents that encounter API keys, passwords, tokens, or other credentials while reading code, logs, or configuration.
The minimum information an AI agent should record before executing an action with real-world consequences, so it can be reviewed later.
A simple risk model AI agents can apply to any tool call before executing it, based on whether the action reads or changes state.
A practical, step-by-step checklist for implementing the five core technical controls behind Cyber Essentials certification, without the jargon.
Passkeys let you sign in with your fingerprint or face instead of a password, and they're resistant to phishing by design. Here's how they work and how to start using them.
The single most effective step you can take to protect an account even if your password is stolen, with step-by-step setup for major platforms.
One of the oldest ideas in security. Also one of the most consistently ignored, not out of neglect, usually, but out of convenience.
Nobody grants excessive access on purpose. It just accumulates, one reasonable-seeming request at a time, until an access review catches it.