Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Governing non-human identities with Identity Manager 10.0

Most organizations today have more non-human identities than human identities. These NHIs often hold privileged access, operate continuously and are difficult to track. Get a handle on every identity in your environment with Identity Manager by One Identity.

DPDP Act Penalties: Fines for Non-Compliance Explained

The Digital Personal Data Protection (DPDP) Act, 2023, has shifted data privacy from a regulatory obligation into a critical business risk. With the DPDP Rules, 2025 providing operational clarity, businesses are expected to implement reasonable security safeguards, manage consent, protect children's data, and respond promptly to personal data breaches.

Identity-Centric PAM: The Future of Privileged Access Management

Privileged Access Management (PAM) has become a cornerstone of enterprise security, but the environments it protects have changed dramatically. Organizations now manage cloud infrastructure, SaaS applications, remote workforces, third-party vendors, machine identities, and AI-driven workloads that constantly request privileged access. Security teams need to verify every identity, understand the context of each request, and grant only the minimum level of access required.

Agent verification might just be KYC/KYB

Every time a card gets issued or a payment moves, something has to decide, in milliseconds, whether it's legitimate. That's the problem Robin Gandhi, chief product officer at Lithic, solves every day. Lithic builds the programmable infrastructure behind modern card issuing and money movement for developers, digital banks, and financial institutions.

AI Agent Identity: Securing Desktop, SaaS, and Enterprise AI Agents

Your enterprise probably has a few thousand employees with managed identities. HR provisioned them, IT governs them, and your IAM platform watches them. Now count the AI agents running across your org. The Claude Code and codex instance that sit inside every dev's IDE. The Salesforce Einstein bot with access to every open deal. The Zapier AI that reads your CRM, writes to your Slack, and forwards summaries to email. You can't count, secure, or govern them with traditional IAM, can you?

SCIM & REST API Provisioning for Jira and Confluence

Wouldn't it be great if managing user accounts didn't take hours of manual effort? For many IT teams, unfortunately, that's exactly the reality. Every new employee needs access for all the apps they intend to use. When someone switches roles, permissions need updating. And when someone leaves, all their access needs to be revoked immediately. These tasks might sound simple, but they become exponentially more challenging as your company grows.

DPDP Compliance Checklist: Assess Your DPDPA Readiness

The Digital Personal Data Protection (DPDP) Act, 2023, has established a new privacy framework for organizations handling digital personal data, while the DPDP Rules, 2025, provide greater clarity on how businesses should implement these obligations in practice. For many organizations, however, translating legal requirements into day-to-day operational processes remains a significant challenge.

Access Governance vs. Access Management: What's the Difference?

Most organizations deploy access management tools and believe they have identity security covered. They do not. What they have is a way to let users in, but no systematic way to ask whether those users should still have that access at all. Access governance and access management are related but distinct disciplines.