Atul Tulshibagwale
- Invented the Continuous Access Evaluation Protocol (CAEP) while at Google
- Co-chair of the OpenID Foundation Shared Signals working group
- CTO of SGNL, acquired by CrowdStrike
Bio
Atul Tulshibagwale invented the Continuous Access Evaluation Protocol at Google and co-chairs the OpenID Foundation's Shared Signals working group, which published the final Shared Signals Framework and CAEP specifications in 2025. He was CTO of SGNL, since acquired by CrowdStrike, and co-chairs the AuthZen and AI identity management groups.
Profile built from public OpenID Foundation and company records.
Where their work shows up
Federation has a structural flaw: a token is issued for an hour, and nothing in the protocol revokes it if the user is fired, the device is compromised, or the session is hijacked in minute two. CAEP and the Shared Signals Framework let an identity provider and a relying party exchange those events in near real time, which is what makes Zero Trust continuous rather than a check at the door. See the ITDR guides and the best ITDR tools ranking for the detection side of the same problem.
Related on Start with Identity
- BlogAgent identity just got a protocol, which is the easy half
Okta shipped Agent SSO and got Cross App Access adopted into MCP the same month a GitHub issue was shown to reach CI secrets in Claude Code and Gemini CLI. The
- BlogAgentic AI Identity Is the Next Frontier (And Your IAM Stack Isn't Ready)
AI agents now act on behalf of users, call APIs, and chain tools together. They need identities, scopes, and audit trails, and almost no existing IAM stack was
- BlogCrowdStrike agrees to buy SGNL for 740 million dollars
The deal that opened 2026's consolidation wave. SGNL brings CAEP-based continuous access evaluation and just-in-time authorization to a Falcon identity business
- CVEKeycloak authorization bypass
Keycloak failed an authorization check, so a caller could reach a resource their role should have blocked. Part of the April 2024 RHSA-2024:1868 set with CVE-20
- CVEKeycloak UMA policy privilege escalation
Keycloak's UMA policy engine checked only the first resource in a request (CWE-266). Additional resources skipped the check. A privilege escalation in user-mana
- CVESailPoint IdentityIQ role-editing authorization flaw
IdentityIQ failed to authorize role edits on all versions at disclosure (April 2026). Anyone who could reach the role-editing surface could change roles they sh