<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>IGA Field Notes</title><description>Practical notes on identity governance, access architecture, non-human identities, and AI agents.</description><link>https://www.igafieldnotes.com/</link><item><title>Agent Governance Should Move to the Application Boundary</title><link>https://www.igafieldnotes.com/blog/agent-governance-should-move-to-the-application-boundary/</link><guid isPermaLink="true">https://www.igafieldnotes.com/blog/agent-governance-should-move-to-the-application-boundary/</guid><description>Instead of only governing which applications an agent can access, each application should decide which agents it trusts, what they may do, and how far their authority can travel.</description><pubDate>Sun, 19 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Why I Built gh-iga: Open-Source Identity Governance for GitHub</title><link>https://www.igafieldnotes.com/blog/open-source-git-hib-govenance-tool/</link><guid isPermaLink="true">https://www.igafieldnotes.com/blog/open-source-git-hib-govenance-tool/</guid><description>GitHub access grows quietly across people, apps, keys, secrets, and automation. I built gh-iga to make that access visible—and to be honest when a scan is incomplete.</description><pubDate>Fri, 17 Jul 2026 00:00:00 GMT</pubDate></item><item><title>The Certification That Never Was</title><link>https://www.igafieldnotes.com/blog/the-certification-that-never-was/</link><guid isPermaLink="true">https://www.igafieldnotes.com/blog/the-certification-that-never-was/</guid><description>A fictional story about a real IGA failure pattern: access reviews that create evidence of governance without governance actually happening.</description><pubDate>Sun, 12 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Cloud Breaches Don&apos;t Start in the Cloud — They End There</title><link>https://www.igafieldnotes.com/blog/cloud-breaches-dont-start-in-the-cloud/</link><guid isPermaLink="true">https://www.igafieldnotes.com/blog/cloud-breaches-dont-start-in-the-cloud/</guid><description>Most compromises begin outside the cloud, then ripple inward through identity, federation, and trust chains.</description><pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate></item><item><title>Your Verified Identity Is Now a Liability</title><link>https://www.igafieldnotes.com/blog/your-verified-identity-is-now-a-liability/</link><guid isPermaLink="true">https://www.igafieldnotes.com/blog/your-verified-identity-is-now-a-liability/</guid><description>AI agents, deepfakes, and synthetic profiles are dissolving the old boundary between verified identity and actual human trust.</description><pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate></item><item><title>Your Situation Isn&apos;t as Unique as You Think</title><link>https://www.igafieldnotes.com/blog/your-situation-isnt-as-unique-as-you-think/</link><guid isPermaLink="true">https://www.igafieldnotes.com/blog/your-situation-isnt-as-unique-as-you-think/</guid><description>The hidden cost of believing the rules don&apos;t apply to you.</description><pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate></item><item><title>The Guest User Blind Spot: Lessons from the Salesloft Breach</title><link>https://www.igafieldnotes.com/blog/salesloft-breach-guest-user-identity-gap/</link><guid isPermaLink="true">https://www.igafieldnotes.com/blog/salesloft-breach-guest-user-identity-gap/</guid><description>When an attacker can add a guest account without approvals or alerts, it&apos;s not a breach problem — it&apos;s an identity governance problem.</description><pubDate>Tue, 09 Sep 2025 00:00:00 GMT</pubDate></item><item><title>Two Types of Communicators in Corporate IT — Which One Are You?</title><link>https://www.igafieldnotes.com/blog/two-types-of-communicators-in-corporate-it/</link><guid isPermaLink="true">https://www.igafieldnotes.com/blog/two-types-of-communicators-in-corporate-it/</guid><description>Real-time responders and batch processors both have a place in IT. The best professionals know when to be each.</description><pubDate>Tue, 09 Sep 2025 00:00:00 GMT</pubDate></item><item><title>The Missing Middle: Where Humans and AI Meet</title><link>https://www.igafieldnotes.com/blog/the-missing-middle-where-humans-and-ai-meet/</link><guid isPermaLink="true">https://www.igafieldnotes.com/blog/the-missing-middle-where-humans-and-ai-meet/</guid><description>The real opportunity in the age of generative AI isn&apos;t on either extreme — it&apos;s in the space where humans and machines work together.</description><pubDate>Sun, 07 Sep 2025 00:00:00 GMT</pubDate></item><item><title>Weekend Read: What IGA Do You Use?</title><link>https://www.igafieldnotes.com/blog/weekend-read-what-iga-do-you-use/</link><guid isPermaLink="true">https://www.igafieldnotes.com/blog/weekend-read-what-iga-do-you-use/</guid><description>A roundup of practitioner takes on Okta, SailPoint, One Identity, Saviynt, Omada, midPoint, and Wren:IDM from a Reddit thread worth bookmarking.</description><pubDate>Sat, 30 Aug 2025 00:00:00 GMT</pubDate></item><item><title>Jagged Intelligence: Why AI Is Brilliant and Clumsy at the Same Time</title><link>https://www.igafieldnotes.com/blog/jagged-intelligence-ai/</link><guid isPermaLink="true">https://www.igafieldnotes.com/blog/jagged-intelligence-ai/</guid><description>AI can pass medical exams and solve advanced math, then fumble on something a child would handle. That unevenness has a name — and it might be permanent.</description><pubDate>Tue, 01 Jul 2025 00:00:00 GMT</pubDate></item><item><title>Deployment Pain: Where Dev Truly Meets Ops</title><link>https://www.igafieldnotes.com/blog/deployment-pain-where-dev-meets-ops/</link><guid isPermaLink="true">https://www.igafieldnotes.com/blog/deployment-pain-where-dev-meets-ops/</guid><description>It worked on my machine. Then it didn&apos;t. Every engineer has lived this gap — and it&apos;s where the real work of bridging dev and ops begins.</description><pubDate>Mon, 31 Mar 2025 00:00:00 GMT</pubDate></item><item><title>Hacked Data, Real Projects, Fake Invoices: The Perfect Scam Recipe</title><link>https://www.igafieldnotes.com/blog/hacked-data-real-projects-fake-invoices/</link><guid isPermaLink="true">https://www.igafieldnotes.com/blog/hacked-data-real-projects-fake-invoices/</guid><description>A Plymouth fraud case shows how data theft plus social engineering can bypass every control you&apos;ve built — by impersonating a vendor you already trust.</description><pubDate>Sat, 31 Aug 2024 00:00:00 GMT</pubDate></item><item><title>Unmasking a USPS Phishing Scam: A Sandbox Walkthrough</title><link>https://www.igafieldnotes.com/blog/unmasking-usps-phishing-scam/</link><guid isPermaLink="true">https://www.igafieldnotes.com/blog/unmasking-usps-phishing-scam/</guid><description>A &apos;delayed package&apos; text from USPS landed in my inbox. Three checks in a sandbox were enough to confirm it was a phishing scam.</description><pubDate>Mon, 19 Aug 2024 00:00:00 GMT</pubDate></item><item><title>When the Phishing Email Is Real: Booking.com&apos;s Magic Link Problem</title><link>https://www.igafieldnotes.com/blog/booking-com-magic-link-scam/</link><guid isPermaLink="true">https://www.igafieldnotes.com/blog/booking-com-magic-link-scam/</guid><description>Scammers don&apos;t need to spoof Booking.com — they trigger it to send you a real login link. MFA doesn&apos;t help. Here&apos;s why.</description><pubDate>Sat, 27 Jul 2024 00:00:00 GMT</pubDate></item><item><title>Humans Are Still the Weakest Link — So Build for That</title><link>https://www.igafieldnotes.com/blog/lockbit-bank-ransomware-humans-still-the-weak-link/</link><guid isPermaLink="true">https://www.igafieldnotes.com/blog/lockbit-bank-ransomware-humans-still-the-weak-link/</guid><description>A LockBit ransomware attack on a bank started with one employee clicking a link. The lesson isn&apos;t &apos;train harder&apos; — it&apos;s &apos;design assuming the click happens.&apos;</description><pubDate>Tue, 09 Jul 2024 00:00:00 GMT</pubDate></item><item><title>RockYou2024: 10 Billion Passwords and Why Credential Stuffing Is the Real Threat</title><link>https://www.igafieldnotes.com/blog/rockyou2024-largest-password-leak/</link><guid isPermaLink="true">https://www.igafieldnotes.com/blog/rockyou2024-largest-password-leak/</guid><description>The leak itself isn&apos;t the danger — it&apos;s what attackers do with it next. A practical take on why MFA stopped being optional.</description><pubDate>Fri, 05 Jul 2024 00:00:00 GMT</pubDate></item><item><title>The Patelco Ransomware Attack: Anatomy of a Modern Breach</title><link>https://www.igafieldnotes.com/blog/patelco-ransomware-attack-anatomy/</link><guid isPermaLink="true">https://www.igafieldnotes.com/blog/patelco-ransomware-attack-anatomy/</guid><description>A credit union with $9B in assets and 400,000 members gets hit. Walking through how ransomware actually unfolds — and what the real impact looks like.</description><pubDate>Wed, 03 Jul 2024 00:00:00 GMT</pubDate></item><item><title>TeamViewer and Midnight Blizzard: When Password Sprays Find an Open Door</title><link>https://www.igafieldnotes.com/blog/teamviewer-midnight-blizzard-password-spray/</link><guid isPermaLink="true">https://www.igafieldnotes.com/blog/teamviewer-midnight-blizzard-password-spray/</guid><description>The TeamViewer breach is a textbook case of why MFA strength — not just MFA presence — is the line between an attempted attack and a successful one.</description><pubDate>Mon, 01 Jul 2024 00:00:00 GMT</pubDate></item><item><title>Detecting Phishing: How I Caught a Suspicious Email</title><link>https://www.igafieldnotes.com/blog/detecting-phishing-real-world-example/</link><guid isPermaLink="true">https://www.igafieldnotes.com/blog/detecting-phishing-real-world-example/</guid><description>Gmail&apos;s built-in filters didn&apos;t flag this one. Six small signals — none of them obvious individually — told the real story.</description><pubDate>Tue, 30 Apr 2024 00:00:00 GMT</pubDate></item></channel></rss>