CyberSolve

This month in IAM CyberSolve August month in IAM - cybersecurity-concept-illustration

Two of the biggest names in the IAM space made the same bet this month.

  • Okta acquired Permiso Security, adding real-time threat detection for human, machine, and agentic identities.
  • Anthropic put frontier AI to work finding and fixing vulnerabilities inside enterprise codebases.

    The industry is no longer asking whether non-human identity needs defending in real time. It has moved on to who does it best.

We spent August on that same problem. Here is what came out of it.

Eliminate manual access review preparation with automated account correlation, configurable service account detection, and self-service data validation for application owners with enhanced NeuroID.

mid-size US healthcare organization is running fully automated access reviews across 28 disconnected applications. Extraction, correlation, evidence capture, remediation verification, all automated. Zero manual effort after initial setup, using NeuroID & IdentityXpress

WHAT WE BUILT THIS MONTH

Securing AI agents-NeuroShield

CyberSolve NeuroShield curaguide access graph

We built two AI agents. Then we attacked them.

A framework nobody has tested is just a diagram.

So this month we built two working AI agents and tried to break them.

The first, CuraGuide, is a healthcare assistant that recommends treatment paths from clinical guidelines. We poisoned the data it learns from. The second, NexPay, is a banking assistant that can move a customer’s money. We tricked it into making transfers it should never have made.

Both attacks failed.

Because NeuroShield stopped them at runtime, at the exact moment each agent tried to act.

CyberSolve NeuroShield curaguide policy edit

Here is what sits underneath: Every agent gets a verifiable identity the moment it is created, tracked all the way to retirement. Every action it takes, every tool it calls, every piece of data it touches, passes through one secured checkpoint. A compromised agent gets caught there, before it reaches anything in operations.

Four more agents are already in build, carrying the same test into retail, real estate, and agents impersonating other agents. We protect against failures we have actually seen, not ones we assumed.

You already have AI agents running somewhere in your organization. Could anyone tell you where, right now?

More on NeuroShield: cybersolve.com/neuroshield

WHAT WE BUILT

Application onboarding · IdentityXpress

The app nobody had a week to onboard

Onboarding an app into your governance program has always felt like filing taxes the old way. Print the forms. Fill every field by hand. Mail it in. Wait.

And if the app had no API, it often never got onboarded at all. It just sat there, ungoverned, because nobody had a free week to deal with it.

This month we rebuilt IdentityXpress to work the way TurboTax changed tax filing.

CyberSolve IDXP app onboarding main screen

Instead of a blank form, it asks you questions. It detects what it can on its own. Point it at a web service and it reads the API, finds the attributes, and maps the entitlements itself. A built-in assistant walks the admin through the rest in plain language.

For the disconnected apps with no API, you can now teach the system by recording how the job is done, the same way you would train a new hire.

That app you have been putting off for a year? Pointing IdentityXpress at it is the whole job now.

More on IdentityXpress: cybersolve.com/identityxpress

WHAT WE BUILT

Access reviews · NeuroID

CyberSolve NeuroID In flight campaign

One screen for a review that used to take twenty

Running an access review across twenty-five apps used to mean tracking twenty-five things. Log in, check one campaign, chase one set of reviewers, export one set of results. Then do it again. And again.

The person running the cycle ends up spending more time tracking progress than reviewing access.

This month, NeuroID’s InFlightCampaign fixed that. It pulls certification data from whichever IGA platform you run and builds a single dashboard. Who has finished. Who has not started. Who still owes a decision. Across every app, in one view, emailed to your team automatically.

snapshot IFC report

Your review cycle spanning twenty apps and three campaigns? One dashboard. One email. One answer to “where are we?”

More on NeuroID: cybersolve.com/neuroid

CUSTOMER IMPACT

A review program customers can own

A leading surgical services provider used to wait on us to run each review cycle. Uploading flat files by hand. Assigning reviewers one at a time. Exporting decisions to CSV and fixing them separately.

Not anymore. The program runs on NeuroID now, and it is theirs.

The numbers tell the story. Last year, on a previous vendor’s tool, they reviewed 21,005 accounts with a 38 percent correlation rate, meaning fewer than four in ten accounts were confidently matched to the right person.

This year, NeuroID cleaned and enriched the data first. Despite a far larger and harder population, more than double the accounts, the correlation rate climbed to 67 percent.

Last year → This year

 

21,005 → 50,275

Accounts in scope

8,100 → 33,896

Accounts correctly matched

38% → 67%

Correlation rate

300,000+

Accounts cleaned by NeuroID

Year-over-year comparison, FY2025 vs FY2026 review cycle.

The higher rate is the headline, but the real point is that it held up on a bigger, messier dataset. That is the hard version of the problem.

OUT IN THE FIELD

Millennium Alliance, Austin

Sonal Srivastava took a room of security leaders through a live access review, start to finish, on a real application. Nine steps, from pulling identities together to the discrepancy report at the end, closing on the exact evidence package an auditor receives.

No slides of promises. The actual thing, running.Sonal at Millennium Alliance

Sonal at Millennium Alliance

WHAT’S NEXT

This is what is in progress now.

NeuroShield. Agent discovery and the access graph continue. Runtime authorization and a redesign of per-session consent come next. Four more test agents extend the attack coverage.

NeuroID desktop automation. Screen evidence and full execution logs, for the complete audit trail an auditor asks for.

NeuroID privileged access review. The privileged accounts that escape most review cycles, because pulling their data means custom scripts, join the same automated review as everything else.

SafeAccessCopilot. App owners answer plain questions about an entitlement, and the system drafts a business-readable description a reviewer can approve.

 

CyberSolve August 2026 Newsletter