Skip to content

Writing

All writing

Long-form essays on identity, AI security, CIAM, Generative Engine Optimization, and the practice of building software. 674 pieces, newest first.

Latest essay

GTM

What a B2B Contact Database Actually Requires (Most Founders Get This Wrong)

Most founders build outbound infrastructure on top of a contact list that is already 25 to 30 percent stale. Discovery, verification, and enrichment are three different problems, and skipping verification is what wrecks deliverability.

Read the article
AI

Your Data Isn't Ready for AI (And Why That's Actually Good News)

Your data isn't ready for AI, and that's good news. It means you found the problem before you built on it. What LoginRadius, GrackerAI, and LogicBalls taught me about the gap between organized data and AI-ready data, plus the 2025 numbers on why it sinks most projects.

AEO

10 Lessons From Tracking 50,000 AI Citations Across 6 Engines

Over 90 days I tracked how six AI search engines cite sources across 50,000+ B2B software responses. The data broke several assumptions the GEO industry treats as settled, starting with the idea that AI visibility is one thing you can optimize for.

GEO

What Black Hat Week Reveals About Security Marketing

Black Hat and DEF CON pull millions in marketing spend to Las Vegas this week. AI engines that buyers ask afterward do not weigh booth size. They weigh whether your research is structured, specific, and citable.

AI Security

Your Phone Line Became the Front Door. Then Everyone Automated It.

Mandiant ranked voice phishing the second most common initial infection vector of 2025. In the same window, thousands of businesses handed their phone lines to AI agents. Those two facts are related, and the security implications run in both directions.

Authentication

Authentication and Authorization in Microservices: What Works

In a monolith you check who someone is once. In microservices, every hop has to ask again. Here is how I design authentication and authorization across services: edge auth, per-service verification, workload identity with SPIFFE, and centralized policy.

authentication

AI Authentication: Verifying People, Agents, and Content

AI made it cheap to fake a face, a voice, and a video. Here is my working map of the three problems authentication now has to solve, and the tools that actually hold up in 2026: verifying people, verifying agents, and verifying content.

AI Security

The Massive AI Security Hole Your CISO Doesn't Know About

Your AI security review passed and still missed the real attack surface. EchoLeak, over-permissioned agents, shadow AI: the AI-specific vectors most CISOs never test for, and the five moves that close them.

Machine Identity

When AI Hackers Meet Machine Identity: The Ignored Attack Surface

The Salesloft Drift breach hit 700+ companies with stolen OAuth tokens and never touched a password. Machine identities now outnumber humans 80 to 1, and AI-powered attackers are harvesting them at machine speed. Here is why human-shaped IAM cannot protect AI agents, and what to fix in 90 days.

Agentic AI

The Identity Mesh: Federated Trust for Multi-Agent AI

Agents can already prove who they are. What no standard has cleanly solved is passing scoped authority down a multi-hop chain across organizations. Here is the real state of agent identity in 2026, minus the blockchain hype.

Machine Identity

The Identity Orchestration Layer for Hybrid AI

Machine identities now outnumber humans by 45 to 1 or more, and every AI agent widens the gap. Here is what an identity orchestration layer is, in plain terms, and how to build one that governs humans, workloads, and agents from a single control plane.