Blog
Field notes on risk you can see without surveillance.
Practical writing on insider and access risk, behavioral signals, and building security that respects the people it protects.
Perspective
Signals over surveillance: a privacy-first approach to insider risk
Why the dominant model for insider risk — watch everyone, read everything — quietly makes organizations less safe, and what to do instead.
Read article → Deep diveMetadata, not content: what behavioral baselines actually reveal
A practical look at how much risk signal lives in access metadata alone — and the honest limits of what it can and can't tell you.
Read article → PlaybookJoiner, mover, leaver: the access lifecycle where risk actually lives
Most access risk is created at three moments. Here's how to instrument each one without standing up a surveillance program.
Read article →More articles as we publish. Want a topic covered? Mention it when you request access.