#access-control
8 stories taggedaccess-control.

Varonis pitches 'intent-based' guardrails for AI agents that stray off task
Agent IBAC watches what an AI agent is trying to do, not just what it is allowed to touch, and pulls the brakes when the two drift apart.

UK Government Investments Agency Exposed Data on 51 Officials for 40 Hours
A security failure at the public body that manages taxpayer stakes in companies like Channel 4 and the Post Office left sensitive management records and personal details of more than 50 civil servants sitting openly accessible online for nearly two days.

AI Agents Need More Than a Watchful Eye. They Need a Leash.
Watching what AI agents do inside your systems is useful. Stopping them doing the wrong thing is the harder job, and the one security teams keep tripping over.

Your AI Is Moving Faster Than Your Security Team Can Follow
Boards want CISOs to greenlight AI projects at speed. The problem is that the tools to track what those AI systems actually touch, and whether they are behaving safely, have not kept up.

European Workers Trust Their Collaboration Tools. The Numbers Tell a Different Story.
A new survey finds that most IT leaders in the UK, France, and Germany feel confident about how securely their teams share information at work. But the same survey shows files staying open too long, consumer apps slipping in through the back door, and fewer than a third of organisations using a secure channel for outside partners.

AI Agents Need Passports, Not Passwords
As companies hand more decisions to autonomous AI agents, the old rules about who gets access to what are breaking down. Here is what needs to change, and why it matters to everyone.

Robinhood Rebuilt Its Access-Approval Pipeline — Here's What Actually Changed
The fintech firm's engineering-security team overhauled how developers request and receive system access. The goal: speed without sacrificing control.

Zero Trust Turns 15 and Still Can't Get Out of Its Own Way
The 'never trust, always verify' model isn't failing because the idea is wrong. It's failing because organizations keep treating a security philosophy like a SKU.