<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>InfoQ - Zero Trust</title>
    <link>https://www.infoq.com</link>
    <description>InfoQ Zero Trust feed</description>
    <item>
      <title>Article: Designing Continuous Authorization for Sensitive Cloud Systems</title>
      <link>https://www.infoq.com/articles/continuous-authorization-cloud/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Zero+Trust</link>
      <description>&lt;img src="https://res.infoq.com/articles/continuous-authorization-cloud/en/headerimage/continuous-authorization-cloud-header-1781599988842.jpg"/&gt;&lt;p&gt;Most cloud systems make one authorization decision at login. Everything after runs on trust established at authentication time. For systems handling regulated data, that gap is where breaches happen. This article presents a continuous authorization architecture covering risk-tiered evaluation, behavioral baselines, privacy-preserving audit trails, and a phased and incremental rollout.&lt;/p&gt; &lt;i&gt;By Venkata Nedunoori&lt;/i&gt;</description>
      <category>Authorization</category>
      <category>Zero Trust</category>
      <category>Data Privacy</category>
      <category>Cloud Security</category>
      <category>Identity Management</category>
      <category>GDPR</category>
      <category>Cloud</category>
      <category>Compliance</category>
      <category>Architecture &amp; Design</category>
      <category>DevOps</category>
      <category>article</category>
      <pubDate>Fri, 19 Jun 2026 09:00:00 GMT</pubDate>
      <guid>https://www.infoq.com/articles/continuous-authorization-cloud/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Zero+Trust</guid>
      <dc:creator>Venkata Nedunoori</dc:creator>
      <dc:date>2026-06-19T09:00:00Z</dc:date>
      <dc:identifier>/articles/continuous-authorization-cloud/en</dc:identifier>
    </item>
    <item>
      <title>AI Agent Identity and Permission Challenges: How Uber and Auth0 Are Rethinking Access Control</title>
      <link>https://www.infoq.com/news/2026/06/ai-agent-identity-uber-auth0/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Zero+Trust</link>
      <description>&lt;img src="https://res.infoq.com/news/2026/06/ai-agent-identity-uber-auth0/en/headerimage/Auth0-Header-1781600533444.jpeg"/&gt;&lt;p&gt;Uber recently described an internal architecture for propagating identity across multi-agent AI workflows. The design aims to perserve user context, agent provenance, and scoped access as agents delegate work and call internal tools. The case study aligns with Auth0’s view that AI agents need permissions based on delegated authority, scoped credentials, and explicit human approval boundaries.&lt;/p&gt; &lt;i&gt;By Eran Stiller&lt;/i&gt;</description>
      <category>Model Context Protocol (MCP)</category>
      <category>Agents</category>
      <category>Agent2Agent</category>
      <category>OAuth</category>
      <category>Zero Trust</category>
      <category>Identity Management</category>
      <category>Architecture</category>
      <category>AI Security</category>
      <category>Architecture &amp; Design</category>
      <category>Development</category>
      <category>news</category>
      <pubDate>Wed, 17 Jun 2026 12:15:00 GMT</pubDate>
      <guid>https://www.infoq.com/news/2026/06/ai-agent-identity-uber-auth0/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Zero+Trust</guid>
      <dc:creator>Eran Stiller</dc:creator>
      <dc:date>2026-06-17T12:15:00Z</dc:date>
      <dc:identifier>/news/2026/06/ai-agent-identity-uber-auth0/en</dc:identifier>
    </item>
  </channel>
</rss>
