- September 9, 2026
- Posted by: Mukul Bisht
- Category: Newsletter
This month in IAM 
Two of the biggest names in the IAM space made the same bet this month.
- Okta acquired Permiso Security, adding real-time threat detection for human, machine, and agentic identities.
- Anthropic put frontier AI to work finding and fixing vulnerabilities inside enterprise codebases.
The industry is no longer asking whether non-human identity needs defending in real time. It has moved on to who does it best.
We spent August on that same problem. Here is what came out of it.
Eliminate manual access review preparation with automated account correlation, configurable service account detection, and self-service data validation for application owners with enhanced NeuroID.
A mid-size US healthcare organization is running fully automated access reviews across 28 disconnected applications. Extraction, correlation, evidence capture, remediation verification, all automated. Zero manual effort after initial setup, using NeuroID & IdentityXpress
WHAT WE BUILT THIS MONTH
Securing AI agents-NeuroShield

We built two AI agents. Then we attacked them.
A framework nobody has tested is just a diagram.
So this month we built two working AI agents and tried to break them.
The first, CuraGuide, is a healthcare assistant that recommends treatment paths from clinical guidelines. We poisoned the data it learns from. The second, NexPay, is a banking assistant that can move a customer’s money. We tricked it into making transfers it should never have made.
Both attacks failed.
Because NeuroShield stopped them at runtime, at the exact moment each agent tried to act.

Here is what sits underneath: Every agent gets a verifiable identity the moment it is created, tracked all the way to retirement. Every action it takes, every tool it calls, every piece of data it touches, passes through one secured checkpoint. A compromised agent gets caught there, before it reaches anything in operations.
Four more agents are already in build, carrying the same test into retail, real estate, and agents impersonating other agents. We protect against failures we have actually seen, not ones we assumed.
You already have AI agents running somewhere in your organization. Could anyone tell you where, right now?
More on NeuroShield: cybersolve.com/neuroshield
WHAT WE BUILT
Application onboarding · IdentityXpress
The app nobody had a week to onboard
Onboarding an app into your governance program has always felt like filing taxes the old way. Print the forms. Fill every field by hand. Mail it in. Wait.
And if the app had no API, it often never got onboarded at all. It just sat there, ungoverned, because nobody had a free week to deal with it.
This month we rebuilt IdentityXpress to work the way TurboTax changed tax filing.

Instead of a blank form, it asks you questions. It detects what it can on its own. Point it at a web service and it reads the API, finds the attributes, and maps the entitlements itself. A built-in assistant walks the admin through the rest in plain language.
For the disconnected apps with no API, you can now teach the system by recording how the job is done, the same way you would train a new hire.

That app you have been putting off for a year? Pointing IdentityXpress at it is the whole job now.
More on IdentityXpress: cybersolve.com/identityxpress
WHAT WE BUILT
Access reviews · NeuroID

One screen for a review that used to take twenty
Running an access review across twenty-five apps used to mean tracking twenty-five things. Log in, check one campaign, chase one set of reviewers, export one set of results. Then do it again. And again.
The person running the cycle ends up spending more time tracking progress than reviewing access.
This month, NeuroID’s InFlightCampaign fixed that. It pulls certification data from whichever IGA platform you run and builds a single dashboard. Who has finished. Who has not started. Who still owes a decision. Across every app, in one view, emailed to your team automatically.

Your review cycle spanning twenty apps and three campaigns? One dashboard. One email. One answer to “where are we?”
More on NeuroID: cybersolve.com/neuroid
CUSTOMER IMPACT
A review program customers can own
A leading surgical services provider used to wait on us to run each review cycle. Uploading flat files by hand. Assigning reviewers one at a time. Exporting decisions to CSV and fixing them separately.
Not anymore. The program runs on NeuroID now, and it is theirs.
The numbers tell the story. Last year, on a previous vendor’s tool, they reviewed 21,005 accounts with a 38 percent correlation rate, meaning fewer than four in ten accounts were confidently matched to the right person.
This year, NeuroID cleaned and enriched the data first. Despite a far larger and harder population, more than double the accounts, the correlation rate climbed to 67 percent.
Last year → This year |
|
21,005 → 50,275 |
Accounts in scope |
8,100 → 33,896 |
Accounts correctly matched |
38% → 67% |
Correlation rate |
300,000+ |
Accounts cleaned by NeuroID |
Year-over-year comparison, FY2025 vs FY2026 review cycle.
The higher rate is the headline, but the real point is that it held up on a bigger, messier dataset. That is the hard version of the problem.
OUT IN THE FIELD
Millennium Alliance, Austin
Sonal Srivastava took a room of security leaders through a live access review, start to finish, on a real application. Nine steps, from pulling identities together to the discrepancy report at the end, closing on the exact evidence package an auditor receives.
No slides of promises. The actual thing, running.

WHAT’S NEXT
This is what is in progress now.
NeuroShield. Agent discovery and the access graph continue. Runtime authorization and a redesign of per-session consent come next. Four more test agents extend the attack coverage.
NeuroID desktop automation. Screen evidence and full execution logs, for the complete audit trail an auditor asks for.
NeuroID privileged access review. The privileged accounts that escape most review cycles, because pulling their data means custom scripts, join the same automated review as everything else.
SafeAccessCopilot. App owners answer plain questions about an entitlement, and the system drafts a business-readable description a reviewer can approve.

Mak is a Cyber Security Executive with over 20 years of experience in Security Controls Design, Implementation and Sustainment with proven management, analytical, technological and strategic skills. He is a globally experienced, process driven and result oriented leader with a proven track record of successfully leading high-performing technical and non-technical teams and delivering industry leading IT Security Capabilities. He has led large scale Cyber Strategy and Implementation projects for Fortune 500 organizations from Finance, Insurance, Banking, Healthcare, Media and Communications domains. He has successfully managed and coordinated global teams to deliver complex project in Identity and Access Management(IAM), Privileged Access, Data Analytics, Risk Management, Governance and Compliance.
Todd is a recognized IAM and Cloud industry expert who brings over 20 years of experience in managing, advising, architecting, and deploying IGA, Authentication and Authorization, and Cloud solutions and services across IDaaS, SaaS, IaaS, and PaaS. Todd is a frequent speaker on effective risk and security practices at leading industry events. He is responsible for the oversight of CyberSolve’s business segments and for the development of strategic plans to sustain the company’s rapid growth while providing trusted advice to clients across the security and risk spectrum.
Atul has over 20 years of experience in managing, designing and implementing Customer Relationship Management (CRM) and Salesforce integrations. He has acted as a cloud-focused solutions expert in both domestic and international markets. Prior to founding CyberSolve, Atul was a Technical Consulting Director at Salesforce where he demonstrated his strong experience architecting financial services industry solutions. Atul holds a Bachelor of Engineering from Madan Mohan Malaviya University of Technology.
Shub possesses over 15 years of experience in the Identity and Access Management (IAM) industry in pre-Sales and technology architecture roles. Shubham has held various positions with SailPoint, RSA, Saviynt, and Okta. He has extensive Identity and Access Management industry technology and sales experience in both domestic and international markets as well strong knowledge of how Identity and Access Management satisfies Audit and IT compliance issues. Shub holds a
Rajesh has served Multi-National Corporations and large organizations as a full time Vice President of Finance, Chief Financial Officer and in equivalent roles. In order to fulfill his duties as a CFO he is a Chartered Accountant, holds a Diploma in Information System Audit (DISA certified by the Institute of Chartered Accountants of India), is a Certified SAP Consultant, Certified QuickBooks Professional Advisor, and Zoho Partner with 30+ years of experience in managing Finance, Accounting and ERP Systems for Medium to Large organizations in diverse sectors.
John is an experienced IT executive with extensive business leadership, operations management, project management, technology delivery and consulting skills who spent over two decades with General Electric where he was responsible for all aspects of their Global PIM program, he was also a key member of the security assurance team for the organizations Capital business. John leads the delivery of client services across the business landscape, to include Privileged Access Management, Managed Services, Identity Governance & Administration, Cybersecurity and Cloud Services.
Luis has been facilitating IAM programs for 20+ years. He was the CRO at Clear Skye, which builds identity governance capabilities on the ServiceNow Platform. His prior experience with services companies that deliver real world identity solutions has made him a trusted resource for information security executives that he has the privilege of advising. Luis assists in the management of our global sales organization, driving revenue growth via direct sales, ensuring our customers have the best plan and solution to ensure their IAM investment achieves the lowest TCO while providing the highest ROI.
Amit brings over 15 years of Identity and Access Management (IAM) experience to the organization. He has a proven track record in providing customers with the best of breed Identity and Access Management solutions. He ensures success within all engagements by staying integrated with the customer throughout the engagement whether it is a program, project or managed services and support. Amit acts as a customer champion at all times to ensure the right solution and resources are in place to achieve the right requirements.
James leads the delivery of client services across the Identity, Access, and Authorization landscape. He has delivered projects across a wide range of products including Okta, Ping, ForgeRock, Oracle, Microsoft, Citrix, Imprivata, Radiant Logic, Axiomatics and many others. With the advent of modern cloud services, James has served as the internal cloud architect and administrator for almost 10 years and uses that experience to help users make the best use of it.
Clark is a Channels, Sales and Marketing executive with 40+ years of experience as a direct seller, Executive and Founder. His experience includes services, software and hardware sales to Commercial, Federal, and State/Local/Education entities across US Domestic and International markets. Within the IAM spectrum, Clark spent over 5 years as SailPoint’s Channel Manager, Federal & Healthcare markets. He has developed and managed Partner relationships and strategies globally, and is known for significantly growing the revenue of his partners by building trusted, profitable relationships and business strategies.