Why We're Building a Daily Identity Blog (And What You'll Get From It)
The identity industry moves faster than any single team can track. This blog is our attempt to keep practitioners current with quality, vendor-neutral writing, published daily.
The identity industry generates more noise than almost any corner of security. Every vendor has a blog, every blog has a thesis, and every thesis happens to recommend that vendor's product. Practitioners are left to triangulate the truth from a dozen sponsored posts.
That is the gap this blog exists to fill.
What this blog is
A daily, practitioner-written look at what is actually happening in identity, across workforce IAM, CIAM, PAM, IGA, Zero Trust, machine identity, and the emerging world of agentic and AI identity. No sponsorships. No "thought leadership" that is really a sales pitch. Every post is dated, and every claim that matters links to a primary source.
We write for the people who have to make this work: the architects choosing a CIAM platform, the engineers rotating secrets at 2am, the CISOs justifying an IGA budget.
What you'll get
- Daily posts. Short analysis on the day's developments, plus longer pieces when a topic deserves it.
- Vendor-neutral framing. When we name a top tool, the methodology is published and the scores are open.
- Primary sources. Standards drafts, breach disclosures, vendor release notes, linked, not paraphrased.
How to follow
Subscribe to the RSS feed and plug it into your reader of choice. We also publish a site-wide feed if you want everything, blog, news, and analysis, in one stream.
If you would rather get the highlights in your inbox, the newsletter goes out when something material ships.
This is day one. See you tomorrow.
Related on Start with Identity
- BlogA CVE ID is a name. The value is knowing who the attacker becomes.
We opened a practitioner catalog of identity CVEs: what broke, why IAM teams should care, and what to do this week. Not an NVD mirror. A place to triage SAML wr
- Blog1Password buys Apono, moving from credential vault to access control plane
Reported at 250 to 300 million dollars, the deal gives 1Password just-in-time privileged access across AWS, Azure, GCP, Kubernetes, Snowflake, and Databricks, a
- ArticleAccess Review and Certification Best Practices: Preventing Rubber-Stamping and Building Effective Governance
How to design access review and certification programs that actually work, moving beyond compliance theater to meaningful governance through micro-certification
- BlogBlack Hat USA 2026 recap: passkeys get broken (twice), and AI agents get an identity perimeter
Our identity takeaways from Black Hat USA 2026: two independent passkey implementation attacks, a wave of AI agent identity and governance launches, an open sou
- ArticleBuilding a 5-Year IAM Roadmap: Long-Term Strategy for Identity Programs
Create a complete 5-year IAM roadmap with capability maturity planning, phased implementation, stakeholder alignment, and budget strategies for sustainable iden
- CVECitrix Bleed, session-token leak from NetScaler ADC
A buffer over-read on NetScaler ADC/Gateway leaked session tokens in the clear. Attackers replayed them and skipped the login, including MFA. CISA KEV. October