identity
Safeguard articles tagged "identity" — guides, analysis, and best practices for software supply chain and application security.
20 articles
Your Access Review Checks One Node in a Graph
A user's permission listing shows no administrative access. By every direct check, they are ordinary. They can still become an administrator through a permission that looks unrelated, was granted for an unrelated reason, and lets them modify something that leads there.
Just-in-Time Provisioning Moves Trust From a Person to a Claim in a Token
A new employee signs in with SSO for the first time, and your application creates an account and assigns a role based on group claims from the identity provider, with no human in the loop to notice if the claim maps to more access than intended.
Account Linking by Email Match Trusts a Claim, Not a Verification
Continue with Google links to the matching existing account by email address. That is correct when the identity provider genuinely verified the email. Some providers make verification optional, and not every system checks which claim it is reading.
Which of Your Second Factors Can Be Relayed by Someone in the Middle
A code read off a screen and typed into a page can be typed into the wrong page. A key bound to an origin cannot produce anything usable for a site that is not yours. That is the whole distinction.
Domain Verification Is the Root of Trust for Your Enterprise Tier
Claiming a domain routes new signups, enforces sign-on and can absorb existing accounts. Every control that follows inherits whatever confidence that one check produced.
Every Production System Has Accounts Nobody Created on Purpose
The demo tenant from the launch, the test user from a 2023 bug, the seed administrator that shipped with the first deployment. None appear on an access review, because reviews enumerate employees and these live in the product's own user table.
The Contractor Offboarding Nobody Ever Did
Every offboarding process is triggered by a termination event in a directory. A contractor's engagement ending produces an invoice, not a directory change, so nothing downstream fires and the account stays live.
Disabling the SSO Account Did Not Remove Their Access
SSO centralises authentication. It does not end existing sessions, revoke tokens issued through other paths, or touch the tools that were never federated. Deprovisioning is a credential problem, and credentials outlive identities by design.
Your Quarterly Access Review Revoked Nothing
Managers approve everything because the task as presented cannot be done well: uninterpretable entitlement names, no usage data, and a default that costs nothing while the alternative breaks a colleague's Friday.
One Mailbox, Six Spellings: The Signup Bug in Almost Every Product
name+tag@, dotted Gmail, googlemail.com, a zero-width space. All reach one inbox, all pass a uniqueness check, and one common fix locks real users out of accounts they are entitled to.
Authentication vs Authorization: What's the Difference?
Authentication proves who you are. Authorization decides what you're allowed to do. One is the ID check at the door; the other is the list of rooms you can enter.
MGM Ransomware One Year Later: A Retrospective
A 2025 retrospective on the September 2023 MGM Resorts ransomware incident, what changed, what stalled, and how supply chain defenders should adjust.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.