
The paper is authored by CISOs from some of the world's most widely used SaaS platforms and lays out four security practices that SaaS providers should treat as pillars in SaaS foundation. It also outlines what those controls need to look like as autonomous AI agents reshape the threat landscape. They include:
- Strong Authentication: Making SSO a standard feature, not an upsell. Isolated credential accounts outside centralized identity management create blind spots that attackers routinely exploit.
- Agentic AI: Security must shift from human-centric SSO to infrastructure-based identity.
- Identity Governance: Close the manual gap.
- Agentic AI: Move toward an identity-link model where agents are governed as distinct entities.
The full report can be accessed here.






















