<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Axec Blog</title><description>Research, engineering, and practical guidance for securing AI agents in the enterprise.</description><link>https://axec.dev/</link><language>en-us</language><item><title>AI Agent Authorization: A Practical Architecture</title><link>https://axec.dev/blog/ai-agent-authorization/</link><guid isPermaLink="true">https://axec.dev/blog/ai-agent-authorization/</guid><description>How to authorize AI agents with explicit application identity, user consent, bounded credentials, and runtime enforcement.</description><pubDate>Thu, 20 Aug 2026 00:00:00 GMT</pubDate><category>Agent Security</category><category>AI agents</category><category>authorization</category><category>OAuth 2.0</category><category>MCP</category><category>credential governance</category><author>Axec Team</author></item><item><title>How to Secure MCP Servers for Enterprise Use</title><link>https://axec.dev/blog/secure-mcp-servers-enterprise/</link><guid isPermaLink="true">https://axec.dev/blog/secure-mcp-servers-enterprise/</guid><description>A deployment-focused guide to MCP authentication, resource-bound authorization, credential isolation, and runtime controls.</description><pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate><category>MCP</category><category>MCP</category><category>enterprise security</category><category>OAuth 2.0</category><category>tool authorization</category><category>credentials</category><author>Axec Team</author></item><item><title>Agent Identity vs. Workload Identity</title><link>https://axec.dev/blog/agent-identity-vs-workload-identity/</link><guid isPermaLink="true">https://axec.dev/blog/agent-identity-vs-workload-identity/</guid><description>How agent identity relates to workload identity, user delegation, credentials, and authorization boundaries.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate><category>Identity &amp; Authorization</category><category>agent identity</category><category>workload identity</category><category>OAuth 2.0</category><category>service accounts</category><category>delegation</category><author>Axec Team</author></item><item><title>OAuth Token Exchange for AI Agents</title><link>https://axec.dev/blog/oauth-token-exchange-ai-agents/</link><guid isPermaLink="true">https://axec.dev/blog/oauth-token-exchange-ai-agents/</guid><description>When OAuth token exchange fits agent architectures, when it does not, and how to preserve resource and delegation boundaries.</description><pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate><category>Architecture</category><category>OAuth 2.0</category><category>token exchange</category><category>AI agents</category><category>delegation</category><category>MCP</category><author>Axec Team</author></item><item><title>Human-in-the-Loop Authorization for AI Agents</title><link>https://axec.dev/blog/human-in-the-loop-authorization/</link><guid isPermaLink="true">https://axec.dev/blog/human-in-the-loop-authorization/</guid><description>Design meaningful human approval for agent authority changes and high-impact actions without creating approval fatigue.</description><pubDate>Sun, 16 Aug 2026 00:00:00 GMT</pubDate><category>AI Governance</category><category>human in the loop</category><category>AI governance</category><category>consent</category><category>agent authorization</category><category>risk controls</category><author>Axec Team</author></item><item><title>Cedar vs. OPA for Agent Authorization</title><link>https://axec.dev/blog/cedar-vs-opa-agent-authorization/</link><guid isPermaLink="true">https://axec.dev/blog/cedar-vs-opa-agent-authorization/</guid><description>A practical comparison of Cedar and Open Policy Agent for capability, resource, and context decisions in AI agent systems.</description><pubDate>Sat, 15 Aug 2026 00:00:00 GMT</pubDate><category>Research</category><category>Cedar</category><category>OPA</category><category>policy as code</category><category>agent authorization</category><category>Rego</category><author>Axec Team</author></item><item><title>Why AI Agents Need Identity</title><link>https://axec.dev/blog/why-ai-agents-need-identity/</link><guid isPermaLink="true">https://axec.dev/blog/why-ai-agents-need-identity/</guid><description>Identity gives agent actions attribution, credential boundaries, revocation, and a foundation for meaningful authorization.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Identity &amp; Authorization</category><category>AI agents</category><category>identity</category><category>authentication</category><category>authorization</category><category>auditability</category><author>Axec Team</author></item><item><title>How to Prevent Over-Permissioned AI Agents</title><link>https://axec.dev/blog/prevent-over-permissioned-ai-agents/</link><guid isPermaLink="true">https://axec.dev/blog/prevent-over-permissioned-ai-agents/</guid><description>Reduce agent authority with capability ceilings, specific consent, credential isolation, live checks, and measurable revocation.</description><pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate><category>Agent Security</category><category>least privilege</category><category>AI agents</category><category>credential governance</category><category>MCP</category><category>authorization</category><author>Axec Team</author></item></channel></rss>