67 Followers
71 Following
208 Posts

Identity systems answer 'who are you?' well. They struggle with 'and who are you acting for?'

New post on delegated access — why separating the actor from the account matters across healthcare, financial services, telco and more, and how Auth0 + Auth0 FGA address the two sides of the problem.

https://tobytes.com/articles/acting-on-behalf-of-separating-actor-from-account

#Auth0 #FGA #Identity

Acting on behalf of: separating the actor from the account in modern identity

Identity systems are very good at answering one question: who are you? What they are less good at is the follow-up: and who are you acting for? In this post I will look at why separating the authenticated user from the account or person they are acting within is important, what it enables across a range of industries, and how Auth0 and Auth0 FGA address the two complementary sides of the problem.

Home Realm Discovery usually lives at the network edge. I tried it inside Auth0's Advanced Custom Universal Login instead — email lookup and tenant routing handled entirely in the login-id screen, no edge proxy.

A walk-through with the ACUL config and the security considerations of putting a lookup before authentication.

https://www.tobytes.com/articles/multi-tenant-home-realm-discovery-acul

#auth0 #identity #iam

Multi-Tenant Home Realm Discovery with Auth0 Advanced Custom Universal Login

Home Realm Discovery is a well-understood pattern at the network layer, but moving that routing logic inside Auth0's login flow using Advanced Custom Universal Login opens up some interesting possibilities — and a few unexpected challenges.

Home Realm Discovery usually lives at the network edge. I tried it inside Auth0's Advanced Custom Universal Login instead — email lookup and tenant routing handled entirely in the login-id screen, no edge proxy.

A walk-through with the ACUL config and the security considerations of putting a lookup before authentication.

https://www.tobytes.com/articles/multi-tenant-home-realm-discovery-acul

#auth0 #identity #iam

Multi-Tenant Home Realm Discovery with Auth0 Advanced Custom Universal Login

Home Realm Discovery is a well-understood pattern at the network layer, but moving that routing logic inside Auth0's login flow using Advanced Custom Universal Login opens up some interesting possibilities — and a few unexpected challenges.

Tako AI v3.0: Harness the Vibe

Tako AI agent for Okta - In v3.0, Tako is better at choosing the right path to answer a question, carrying context across follow-up questions, and giving teams a cleaner experience for longer investigations across web, CLI, and Slack.

https://iamse.blog/2026/05/04/tako-ai-v3-0-harness-the-vibe/

Tako AI v3.0: Harness the Vibe - IAMSE

Tako AI agent for Okta - In v3.0, Tako is better at choosing the right path to answer a question, carrying context across follow-up questions, and giving teams a cleaner experience for longer investigations across web, CLI, and Slack.

IAMSE

Higher temperatures are forcing irrigation districts to begin irrigating two weeks earlier than normal, putting more pressure of California's #water supplies.
Another impacts of human-caused #climatechange

https://abc30.com/post/early-heat-prompts-fresno-irrigation-district-release-water-ahead-schedule/18743144/

Fresno Irrigation District releases water early amid record March heat

Unusual March heat has led the Fresno Irrigation District to begin water deliveries earlier than planned as farmers prepare for an uncertain season.

 Tako AI v2.2: Your Okta AI Agent, Now in Slack

Tako AI v2.2 brings your Okta AI agent directly into Slack. Ask questions about your tenant in any channel — active users, app assignments, MFA gaps — and get answers without leaving where your team already works. Type /tako list contractors who haven't logged in for 60 days and results post back to the thread in seconds.

https://iamse.blog/2026/02/21/tako-ai-v2-2-your-okta-ai-agent-now-in-slack/

 Tako AI v2.2: Your Okta AI Agent, Now in Slack - IAMSE

Tako AI v2.2 brings your Okta AI agent directly into Slack. Ask questions about your tenant in any channel — active users, app assignments, MFA gaps — and get answers without leaving where your team already works. Type /tako list contractors who haven't logged in for 60 days and results post back to the thread in seconds.

IAMSE

Tako AI v2.1: CLI Power, Saved Favorites

Tako AI v2.1 brings terminal power to Okta

https://iamse.blog/2026/02/12/tako-ai-v2-1-cli-power-saved-favorites/

Tako AI v2.1: CLI Power, Saved Favorites - IAMSE

New Tako v2.1: Terminal CLI for Okta queries, query favorites, and 3x performance boost. Generate CSV reports from the command line.

IAMSE

Tako AI v2.0: The Swarm Is Here

Meet Tako AI v2.0, the autonomous AI agent for Okta. Instead of one agent doing everything, v2.0 uses a specialized swarm—Router, SQL, API, and Synthesis agents working together. It's faster, cheaper, and more accurate than ever.

https://iamse.blog/2026/01/30/tako-ai-v2-0-the-swarm-is-here/

Tako AI v2.0: The Swarm Is Here - IAMSE

Meet Tako AI v2.0, the autonomous AI agent for Okta. Instead of one agent doing everything, v2.0 uses a specialized swarm—Router, SQL, API, and Synthesis agents working together. It's faster, cheaper, and more accurate than ever.

IAMSE

Tako AI v1.5: Your New Okta AI Sidekick

Meet Tako AI v1.5, the autonomous AI agent for Okta. It thinks, codes, and fixes its own mistakes to manage your identity infrastructure. Built on a secure ReAct architecture, Tako delivers self-healing

https://iamse.blog/2025/11/23/tako-ai-v1-5-your-new-okta-ai-sidekick/

Tako AI v1.5: Your New Okta AI Sidekick - IAMSE

Tako AI v1.5 (AI agent for Okta) uses ReAct loops and fast, cost-effective models to autonomously manage Okta.

IAMSE

Recent Updates to Okta Privileged Access – Oct 25

There have been a number of features released for Okta Privileged Access over the recent months, some major and some minor, but may have been lost in the excitement of Oktane 25. This article provides a summary of all the changes release. Introduction Active Directory Integration Changes RDP Support (aka Click-to-Connect) AD rotate password configuration AD Accounts as Okta Users and OPA Service Accounts…

https://iamse.blog/2025/10/15/recent-updates-to-okta-privileged-access-oct-25/

Recent Updates to Okta Privileged Access – Oct 25

There have been a number of features released for Okta Privileged Access over the recent months, some major and some minor, but may have been lost in the excitement of Oktane 25. This article provi…

IAMSE