top of page
Insights
Practitioner thinking, from the people doing the work.
We publish what we learn, the same instinct that leads us to ship our source code. No gated downloads, no thought leadership theatre. Writing on agentic AI governance, the EU AI Act and identity as the control plane.
Search for Midships Knowledge Base
! No Results found


What do you have to lose?
For one bank, the answer starts with more than USD 15 million in five year software licensing savings. That is before the cost of running a simpler stack, before reduced operational overhead, and before the strategic value of growing a digital business without being penalised for every new customer, transaction, environment, or channel. For years, enterprises treated CIAM as a premium software category. That made sense when the market was less mature, open source was harder t

Ajit Gupta
Jul 14 min read


Designing Secure Authentication Journeys with Keycloak: Tokens, Sessions, Revocation, and Step-Up Flows
Abstract Production identity failures do not always begin with infrastructure outages. Many begin with early token and session design decisions that become difficult to reverse later. Long-lived access tokens, introspection-heavy service designs, weak revocation paths, and inconsistent session binding can create security and availability risks that only become visible after applications have already integrated with the identity platform. Keycloak can support secure authentica

Ajit Gupta
Jun 267 min read


Why Autonomous Agents Are Driving A New Generation Of Enterprise Governance
For decades, enterprise automation has followed a simple principle. If a business process could be mapped in advance, it could be automated. Workflow engines, business rules, approval systems, and orchestration platforms transformed how organisations operate by taking predictable work and executing it consistently at scale. That model remains incredibly effective. But it has limits. Many of the most valuable activities inside an enterprise cannot be fully mapped in advance. F

Yuxiang Lin
Jun 235 min read


What I Stopped Chasing
Earlier this month I spent several days away from the business. No meetings, no notifications, no family obligations. For the third year running I blocked out time to do nothing but think, about what I want from the years ahead, the kind of company I want to build, and the kind of person I want to become, and answer the big question "what do I want to be when I grow up". The exercise is uncomfortable by design. This year it surfaced a question I had been avoiding. For years I

Ajit Gupta
Jun 205 min read


From Console to GitOps: Operating Keycloak as a Governed Cloud-Native Identity Platform
Abstract Keycloak is an open-source identity and access management platform that provides authentication, authorization, single sign-on (SSO), identity federation, user management, and token-based security services for applications and APIs. It enables organisations to centralise identity functions while supporting standards such as OpenID Connect, OAuth 2.0, and SAML. Keycloak gives engineering teams deep control over identity infrastructure. That control is one of its great

Ajit Gupta
Jun 167 min read


Keycloak at Production Scale: High Availability Patterns for Regulated Cloud-Native Platforms
Abstract Keycloak deployments often begin well. They pass user acceptance testing, perform acceptably in staging, and go live without visible issues. The problems usually appear later: session state becomes inconsistent under load, Kubernetes maintenance disrupts authentication, cache replication behaves unpredictably, or a regional failover exposes assumptions that were never tested. For production environments where authentication is critical infrastructure, Keycloak must b

Ajit Gupta
Jun 105 min read


Scope Integrity, Proof-of-Possession, and Enforceable Token Exchange for Agentic AI Systems
Abstract An agent identity model is the design that defines how a system proves which agent is acting, which user the agent is acting for, what authority the agent has, and how that authority is preserved across downstream calls. In agentic AI systems, delegation solves one major identity problem: it preserves the original human user context across agent-to-agent chains. Delegation means that an agent acts on behalf of a user while the token still preserves both identities: t

Ajit Gupta
Jun 26 min read


A year on from embracing AI. What I actually think now.
It has been just over a year since AI tools became part of my day, here is where I have actually landed. My musings for June... When I first started using these tools seriously, I had two reactions inside the same week. Excitement, and a quiet panic about whether the business I had built was about to be eaten. Twelve months later that panic has not disappeared, but it has changed shape. For Midships, less changes than you might think. We have always run lean, expert le

Ajit Gupta
Jun 14 min read


Delegated Human Context Across Agent-to-Agent Chains
Abstract Agentic AI systems introduce an identity problem that becomes visible when agents begin calling other agents. In a simple single-agent model, OAuth2.1 authorisation can capture user consent and issue a scoped access token to one agent. That model works when the user is present, the same agent requests and uses the token, and the scope of the action is known at consent time. Multi-agent systems break these assumptions. A user may interact with one orchestrating agent,

Ajit Gupta
May 267 min read
Common Questions
Insights – FAQs
What does Midships publish?
Practitioner writing on agentic AI governance, the EU AI Act and identity as the control plane, from the people doing the work.
Are the insights gated?
No. There are no gated downloads and no thought leadership theatre.
bottom of page



















