Safeguard
Tag

identity

Safeguard articles tagged "identity" — guides, analysis, and best practices for software supply chain and application security.

20 articles

Application Security

Your Access Review Checks One Node in a Graph

A user's permission listing shows no administrative access. By every direct check, they are ordinary. They can still become an administrator through a permission that looks unrelated, was granted for an unrelated reason, and lets them modify something that leads there.

Sep 18, 20267 min read
Application Security

Just-in-Time Provisioning Moves Trust From a Person to a Claim in a Token

A new employee signs in with SSO for the first time, and your application creates an account and assigns a role based on group claims from the identity provider, with no human in the loop to notice if the claim maps to more access than intended.

Sep 18, 20267 min read
Application Security

Account Linking by Email Match Trusts a Claim, Not a Verification

Continue with Google links to the matching existing account by email address. That is correct when the identity provider genuinely verified the email. Some providers make verification optional, and not every system checks which claim it is reading.

Sep 18, 20266 min read
Application Security

Which of Your Second Factors Can Be Relayed by Someone in the Middle

A code read off a screen and typed into a page can be typed into the wrong page. A key bound to an origin cannot produce anything usable for a site that is not yours. That is the whole distinction.

Sep 18, 20265 min read
Application Security

Domain Verification Is the Root of Trust for Your Enterprise Tier

Claiming a domain routes new signups, enforces sign-on and can absorb existing accounts. Every control that follows inherits whatever confidence that one check produced.

Sep 18, 20265 min read
Compliance

Every Production System Has Accounts Nobody Created on Purpose

The demo tenant from the launch, the test user from a 2023 bug, the seed administrator that shipped with the first deployment. None appear on an access review, because reviews enumerate employees and these live in the product's own user table.

Sep 18, 20265 min read
Compliance

The Contractor Offboarding Nobody Ever Did

Every offboarding process is triggered by a termination event in a directory. A contractor's engagement ending produces an invoice, not a directory change, so nothing downstream fires and the account stays live.

Sep 18, 20266 min read
Compliance

Disabling the SSO Account Did Not Remove Their Access

SSO centralises authentication. It does not end existing sessions, revoke tokens issued through other paths, or touch the tools that were never federated. Deprovisioning is a credential problem, and credentials outlive identities by design.

Sep 17, 20266 min read
Compliance

Your Quarterly Access Review Revoked Nothing

Managers approve everything because the task as presented cannot be done well: uninterpretable entitlement names, no usage data, and a default that costs nothing while the alternative breaks a colleague's Friday.

Sep 17, 20266 min read
Security

One Mailbox, Six Spellings: The Signup Bug in Almost Every Product

name+tag@, dotted Gmail, googlemail.com, a zero-width space. All reach one inbox, all pass a uniqueness check, and one common fix locks real users out of accounts they are entitled to.

Aug 18, 20265 min read
Concepts

Authentication vs Authorization: What's the Difference?

Authentication proves who you are. Authorization decides what you're allowed to do. One is the ID check at the door; the other is the list of rooms you can enter.

Jul 2, 20265 min read
Incident Analysis

MGM Ransomware One Year Later: A Retrospective

A 2025 retrospective on the September 2023 MGM Resorts ransomware incident, what changed, what stalled, and how supply chain defenders should adjust.

May 21, 20264 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.