Turn emails into revenue with Brew. No credit card, free credits to try.
goteleport.com · newsletter
Explore this email design and adapt it to your own brand. Review the copy, links, and offer before sending.
Teleport
New in Identity
Teleport — New in Identity - Issue #7
First, some news. KuppingerCole Analysts named Teleport an Overall Leader in its 2026 Leadership Compass for Zero Trust Platforms, with #2 rankings in Product and Innovation Leadership. The analysts pointed to our infrastructure identity architecture, short-lived certificate model, and depth of coverage. The timing fits. As Ev Kontsevoy, our CEO, put it: "Zero trust takes on even more importance as we move into the agentic era. Our unified identity architecture enables enterprises to responsibly deploy large numbers of agents that operate at machine speed with human-like unpredictability. Companies driving agent innovation must first solve the identity problem."
That is what the rest of this issue is about. AI agents now query databases, call cloud APIs, and act across infrastructure that was never built to recognize them as a distinct actor. Every layer defaults to the same answer: a shared role, a generic service account, a name like agentcore-bot. The person who triggered the action disappears from the record the moment it crosses a system boundary. This issue follows that gap from the protocol layer, through a major cloud service, down to the database, and what closing it actually takes.
The 2026 KuppingerCole Leadership Compass evaluates how vendors deliver zero trust across cloud, on-prem, SaaS, and edge. It names Teleport an Overall Leader for a certificate-backed, secretless approach to securing infrastructure, machines, workloads, and AI agents. Read the announcement and download the full analyst report below.
Announcement →
Full Report →
Your AI Agent Needs to Know Who You Are
By Jeffrey Ellin
MCP tools see the agent, not the person driving it, so they can't tell Alice, who should only see her own data, from Carol, who shouldn't have access at all. That blind spot forces a choice between overprovisioning every user or throttling every agent to the least common denominator, and it leaves an audit trail that only shows the agent did something, not who asked. The fix is a short-lived, cryptographically signed JWT issued at login: any tool holding the public key can verify who's behind a request without a round trip back to the issuer.
Read the full post →
When AI Agents Call AWS, Who Does AWS Think They Are?
By Jeffrey Ellin
Ask an AI agent to list your S3 buckets through Amazon Bedrock AgentCore, and CloudTrail logs the action under a generic name like agentcore-bot, never your identity. AgentCore checks that a request is structurally valid but doesn't propagate who sent it, which leaves every user sharing one over-provisioned IAM role, an audit trail no one can tie to a person, and access that outlives the employee who had it. Carrying identity through the whole chain, from login through the agent through AgentCore into the Lambda, is what makes that audit trail useful again.
Read the full post →
PostgreSQL: How to Control and Audit Agent Access with Identity
By Megan Moore
PostgreSQL has no concept of an agent as a distinct actor. In pg_stat_activity, it looks like any other role created with CREATE ROLE, with nothing to show who or what opened the connection. Agent query patterns are naturally broad and non-deterministic, so a role with wide SELECT or INSERT privileges becomes an exfiltration path that's hard to distinguish from normal use, and it runs for anyone who controls the agent's inputs. Short-lived, task-scoped access is the alternative to a static role no one can trace back to a person.
Read the full post →
Have questions or want to keep the conversation going? Join us in our Community Slack →
If you found this useful, pass it along to someone else who would, too.
Thanks for reading,
The Teleport Editorial Team
P.S. We'll be at these events over the next few weeks. Come find us.
Jul 23: CISOMeet -- Orange County, USA
Aug 3-6: Black Hat USA -- Las Vegas, USA
Sep 1: KCD SF -- Mountain View, USA
Sep 7: CPX GISEC -- Dubai
Find us near you →
Teleport, 2100 Franklin St, Suite 400, Oakland, CA 94612
If you no longer wish to receive these emails anymore, click on the following link:
UNSUBSCRIBE
TERMS OF SERVICE | PRIVACY POLICY | SECURITY POLICY