verifiedagents.ai
Blog

Notes on governing AI agents.

What we're learning from assessments and from teams putting agents into production.

What is an OAuth consent grant hero image
September 28, 20267 min readTechnical Guidesmassivescale.ai

What Is an OAuth Consent Grant, and Why Is It Your Fastest AI Inventory?

Every AI tool connected to your email or files left an OAuth consent grant in your identity provider. Here's how to pull that list this week, for free.

By Josh Woodruff

Why Your Copilot Pilot Outruns Your Data Classification
September 16, 20269 min readAI Agentsmassivescale.ai

Why Your Copilot Pilot Outruns Your Data Classification

Copilot doesn't create a data leak. It reveals the permissions you already had. Nine client calls in 2026 hit the same wall. Classification sets the tier.

By Josh Woodruff

Contain First, Count Second: AI Agent Blast Radius
September 9, 20268 min readSecuritymassivescale.ai

Contain First, Count Second: AI Agent Blast Radius

Contain the damage before you finish the inventory. Blast-radius controls work against the AI agents you haven't found yet, and discovery never finishes.

By Josh Woodruff

Hero: How Do You Respond When an AI Agent Goes Rogue?
July 3, 20266 min readAI Agentsmassivescale.ai

How Do You Respond When an AI Agent Goes Rogue?

When an AI agent goes wrong you have minutes, not months. Traditional breach response averages 258 days, but agent decisions compound every second.

By Josh Woodruff

Hero: What Is the Agentic Trust Framework for Securing AI Agents?
July 3, 20266 min readAI Agentsmassivescale.ai

What Is the Agentic Trust Framework for Securing AI Agents?

The Agentic Trust Framework turns Zero Trust into five working controls for AI agents: identity, behavior, data, segmentation, and incident response.

By Josh Woodruff

Hero: What is the AI agent identity problem?
May 17, 20268 min readCybersecuritymassivescale.ai

What is the AI agent identity problem?

Only 18% of security leaders trust their identity systems for AI agents (Strata, May 2026). The five-element blueprint that fixes pilot purgatory.

By Josh Woodruff

Hero: Why Zero Trust Needs More for AI Agents (and How to Fix It)
March 23, 20267 min readCybersecuritymassivescale.ai

Why Zero Trust Needs More for AI Agents (and How to Fix It)

Zero Trust was designed for humans logging into systems. AI agents don't log in...they act, chain decisions, and call systems continuously. Here's what to do.

By Josh Woodruff

Hero: What Is Trusted Agents? AI Agent Security for Business Leaders
March 8, 20265 min readZero Trustmassivescale.ai

What Is Trusted Agents? AI Agent Security for Business Leaders

Trusted Agents is a free weekly newsletter on AI agent security for business leaders. Real incidents, action plans, and Zero Trust gap analysis every Tuesday.

By Josh Woodruff

Hero: Why Microsoft 365 Copilot's Hacking Shows the Need for Zero Trust
August 19, 20257 min readAgentic AImassivescale.ai

Why Microsoft 365 Copilot's Hacking Shows the Need for Zero Trust

In our rush to adopt AI, we forgot everything we every learned about security. Learn how all AI agents are vulnerable and need Zero Trust security.

By Josh Woodruff

Hero: Why are 60% of corporate logins now non-human?
August 6, 20256 min readSecuritymassivescale.ai

Why are 60% of corporate logins now non-human?

At RSAC 2025, a presenter showed a live dashboard of users logged into a normal company's systems. 60% were AI agents making decisions.

By Josh Woodruff