categories
Agentic Access Management
Browse Pomerium articles in the Agentic Access Management category.
Topic archive
Resources Categorized: Agentic Access Management

Data-Layer Proxy vs Context-Aware Proxy: Which Do You Need?
Two proxy architectures secure AI agent access, and they solve different problems. How data-layer and context-aware proxies differ, and when you need each.

MCP Governance: What the OWASP Framework Requires, and Where Enforcement Has to Live
The OWASP MCP Governance & Risk Framework v1.0 sets tiers, hard gates, and audit rules for AI agents. Here's what it requires and how to enforce it at runtime.

Agents Have Boundary Issues. Your Infrastructure Shouldn't.
Why the five isolation boundaries in agent security research all point to the same conclusion: enforcement has to live outside the model.

Google Built an Agent Runtime on Kubernetes. Here's How to Build a Cloud-Agnostic One with Identity Included
Google spent the last year quietly admitting what we already knew: Kubernetes was never designed to run AI agents. As Janakiram MSV writes in The New Stack , Google's GKE Agent Sandbox and the new Agent Substrate project amount to an indirect admission "that the platform that won the container decade is not the right control plane for AI agents."
.png.CaqDtkk2.webp)
IAM for Agentic AI: 6 Platforms Compared | Pomerium
Compare Pomerium, Aembit, Astrix, Token Security, Oasis, and Britive for securing AI agents and workload identities. See which platform fits your stack.
.png.D1dxPUm2.webp)
Top 5 Agentic Gateways for Securing MCP Tool Calls in 2026
The explosive growth of agentic AI has created a new security frontier. As large language models (LLMs) gain the ability to call external tools—through the Model Context Protocol (MCP)—organizations face an urgent question: How do you control what tools an agent can access, what parameters it can pass, and how do you audit its actions?
.png.DqqhEqND.webp)
Why Identity-Aware Access is the Missing Layer in Agentic Security
A new VentureBeat analysis from this week lands on a truth that every enterprise security team already feels in their gut: most AI agents are a credential exfiltration waiting to happen. The monolithic agent pattern — where reasoning, execution, credential storage, and tool access all share the same process — creates a threat surface that conventional security tooling wasn't designed to close.

The AIUC-1 Compliance Checklist: 5 Layers Every Enterprise Needs Before Deploying AI Agents
A quick-reference checklist for AIUC-1 compliance. Five layers, 28 controls, one page. Print it, pin it, pass the audit.

What Is an Agentic Gateway? Definition, Architecture, and Why It's Different from an API Gateway
Discover what agentic gateways are, how they secure autonomous AI agents with tool-level authorization and session-aware policy enforcement, and why API gateways fall short.
.png.CAHbD12i.webp)
The AIUC-1 Compliance Stack: The Architecture Auditors Are Actually Looking For
Most enterprises will fail AIUC-1 before the audit starts. Here’s the five-layer compliance architecture — built around a central control plane — that covers every domain.

What Made McKinsey's AI Platform Easy to Hack? And How to Fix it.
Enterprise AI assistants are quickly becoming the front door to internal systems .

AI Is Your Biggest Security Risk
IBM’s Cost of a Data Breach Report 2025 delivers a surprising headline: for the first time in five years, the global average cost of a data breach has declined, dropping to $4.44M . The reason? Faster detection and containment, driven largely by security automation and AI.

Hosted Clusters in Pomerium Zero & MCP Hacking (endpoints from localhost via ssh)
If you’re building an MCP server and you want a public model (ChatGPT, Claude, or Gemini) to actually call it, you hit the same wall: All the frontier models need a public HTTPS URL.
September 2025 MCP Round‑Up: Growing Adoption Meets Rising Security Fears
September was a month of contrasts for the Model Context Protocol (MCP). On the one hand, the ecosystem matured rapidly. On the other hand, a wave of reports underscored how quickly attackers are targeting these interfaces. Researchers warned of prompt‑injection attacks, backdoored packages and a raft of newly ranked vulnerabilities, while practitioners called for stronger identity flows, fine‑grained authorization and tighter governance.
August 2025 Agentic Access and MCP Content Round‑Up: Security, Innovations & Growth
August was filled with vulnerabilities and developments in the agentic AI and Model Context Protocol (MCP) landscape. Multiple high‑severity remote‑code‑execution vulnerabilities demonstrated how easily malicious servers or modified configurations can hijack developer machines. Docker went so far as to label the MCP ecosystem a “security nightmare,” prompting calls for OAuth 2.1 authorization and zero‑trust practices. Meanwhile, vendors made notable releases and thought leaders explored the future of AI as adoption accelerates.
The OWASP Top 10 for LLMs and How to Defend Against Them
TL;DR — The OWASP Top 10 for Large Language Model (LLM) applications highlights prompt injection, insecure output handling, and data exposure as critical risks. This guide walks through the Top 10 and shows where Zero Trust access controls, starting free with Pomerium Zero , are most effective: LLM01 Prompt Injection and LLM02 Sensitive Information Disclosure.
Why Traditional Access Controls Fail in LLM Deployments
TL;DR: Prompt-driven apps quickly outgrow static API keys and coarse Identity Access Management (IAM) roles. OWASP’s LLM risk list shows why that model breaks. The answer is continuous, identity-aware policy applied before prompts ever reach the model. Pomerium provides that control so teams can ship GenAI features with confidence.
July 2025 Agentic Access and MCP Content Round‑Up: Vulnerabilities, Governance & Growth
A number of pivotal developments marked the agentic AI and Model Context Protocol (MCP) world this past July. Two critical remote‑code‑execution flaws, one in the widely used mcp‑remote tool and another in Anthropic’s MCP Inspector , highlighted the growing security risks of AI‑agent tooling. Meanwhile, vendors released new MCP servers and training programs, and the open‑source project announced a formal governance model to sustain its rapid growth. The compiled July headlines below capture both the promise and the perils of the evolving MCP ecosystem.
Why the Managed Context Protocol (MCP) Spec Still Leaves Gaping Security Holes
TL;DR — MCP gives AI agents a shared way to invoke tools and complete tasks. But the spec lacks core security features. There is no built-in authorization, no identity enforcement, and no way to apply context-aware policy. Teams relying on reference servers are exposing internal APIs without guardrails. Pomerium applies Zero Trust controls to every request, adding identity, context, and policy enforcement at Layer 7.
How Shadow AI Impacts SOC 2 and HIPAA, and What to Do About It
Shadow AI bypasses critical access and audit controls required by SOC 2 and HIPAA. Learn how per-route policy with Pomerium restores visibility, enforcement, and audit readiness.
Top 10 Articles in Agentic Access - MCP, Models, and Clients (June 2025)
June was a messy, revealing, and incredibly important month for anyone paying attention to how AI agents interact with real-world systems.
When AI Has Root: Lessons from the Supabase MCP Data Leak
In a post by Simon Willison , we saw a lethal trifecta in action: an LLM agent with broad database privileges was tricked by a user's support-ticket text into exfiltrating secrets. The scenario with Cursor (a Claude-based IDE) and Supabase's new Model Context Protocol (MCP) is eerily simple but deadly: the developer's LLM agent runs with the full service_role key, bypassing all Row-Level Security (RLS). It ingests customer support messages as input. An attacker files a ticket containing hidden instructions like:
Your Employees Are Already Dumping Company Data to LLMs (Here’s What To Do About It)
It's happening right now, in your organization. That senior developer just pasted your global auth tokens into ChatGPT to debug a tricky race condition. Your data analyst uploaded last quarter's customer churn data to Claude to help write their board presentation. Your product manager is feeding competitive analysis docs to Gemini to brainstorm feature ideas.
Asana's AI Connector Leak Exposed Sensitive Data Across Organizations: What It Means for MCP Security
When news broke that Asana's MCP server had exposed sensitive data across organizations, it wasn’t just a one-off flaw. It was a warning shot for anyone integrating AI agents into their systems without guardrails.
Secure Access for Model Context Protocol (MCP)
Learn why OAuth alone can't secure the Model Context Protocol (MCP). Discover how Pomerium enforces Zero Trust for agentic AI with per-request authorization, JWT identity, and full audit logging.
What We Heard From RedMonk Analysts—And Why Agentic Access Needs a New Security Model
Model Context Protocol (MCP) is here, and LLMs are already making requests to your internal systems. The existing security model wasn’t built for this new world of autonomous agents.
Agentic Access Management for Model Context Protocol (MCP) Workflows
We’re no longer designing systems where humans are the sole decision-makers. Agentic AI changes the rules. LLMs don’t just respond to prompts anymore, they make decisions autonomously within your systems.
