top of page
Insights
Practitioner thinking, from the people doing the work.
We publish what we learn, the same instinct that leads us to ship our source code. No gated downloads, no thought leadership theatre. Writing on agentic AI governance, the EU AI Act and identity as the control plane.
Search for Midships Knowledge Base
! No Results found


From Console to Compliance: Operating Keycloak as a Regulated, API-Driven Identity Platform
Abstract In regulated environments, identity systems must meet strict audit, compliance, and governance requirements. Default operational models are often insufficient, particularly when configuration changes are not traceable or reproducible. In Keycloak deployments, achieving compliance requires shifting from manual administration to an API-driven, pipeline-controlled model. This article explores how configuration management, audit pipelines, and access controls can be desi
Mayank Soni
May 124 min read


The governance gap Anthropic just exposed.
Anthropic just released ten finance agent templates. They cover the most expensive and most regulated parts of bank operations: KYC screening, month-end close, general ledger reconciliation, statement audit, valuation review, earnings review, and model building. The published benchmark score is 64.37 percent on Vals AI's Finance Agent benchmark. Anthropic is clear that this is industry-leading. It is also the best on offer. Roughly one in three finance tasks still fails. Read

Ajit Gupta
May 82 min read


Scaling Identity to Millions: Session, Token, and Cache Design in Keycloak
Primary Audience: Platform Engineers building identity infrastructure, Security architects designing authentication systems, Teams operating large-scale SaaS or financial systems. CNCF Alignment: Kubernetes, HA, Multi-RegionAbstract At scale, identity systems are defined by how sessions are managed, tokens are designed, and validation is performed. In large Keycloak deployments, these decisions directly impact performance, availability, and security. This article explores pra
Mayank Soni
May 54 min read


Intent-based governance is not what most vendors are selling
I have spent the last few months on the road with Icebreaker, our agentic AI governance product, in customer and partner conversations across this category. One challenge keeps coming back. "Doesn't your approach do the same thing as everyone else's." Every time we look closely, the answer is no, and for a reason worth naming. The products being compared fall into one of two camps. The first helps the organisation identify mistakes after the agent has already made them, hop

Ajit Gupta
May 55 min read


Designing Financial-Grade Identity: High-Availability Patterns for Keycloak on Kubernetes
Primary Audience: Platform Engineers CNCF Alignment: Kubernetes, HA, Multi-Region Abstract In regulated financial environments, identity systems must meet stringent availability and resilience requirements. While Keycloak offers flexibility and extensibility, it does not abstract the complexity of distributed system design. This article presents production-proven patterns for building highly available Keycloak deployments on Kubernetes, focusing on cache topology, multi-regio
Mayank Soni
Apr 284 min read
Mythos, Fear, and What Good Security Architecture Already Tells You
The reaction to Mythos is understandable. There however appears to be a lot of misunderstanding (at least from my conversations). Mythos is a frontier AI model that can identify software vulnerabilities at a level previously reserved for highly skilled human operators changes the economics of cyber risk (think about a seriously good hacker on steroids!). It fundamentally changes the economics of cyber risk. It compresses the time between vulnerability discovery and exploitati

Ajit Gupta
Apr 282 min read
Human in the Loop is Necessary. It Cannot Be the Destination.
Professor Paul Morrissey C.Eng, FIET, FBCS, FRSA published a piece this week on the Agentic Digital Workforce that deserves serious attention. His central warning is right: human oversight designed as theatre, nominal checkpoints with no real authority or context, is not governance. It is liability without accountability. I agree completely. Where I think the argument needs to go further is what happens at scale. Enterprises deploying AI agents across real-time, high-volume w

Ajit Gupta
Apr 272 min read


Why Red Hat Keycloak Is Not What You Think "Open Source" Means
There is a conversation I keep having with CISOs across Southeast Asia and beyond. It goes something like this: we recommend Keycloak for their identity platform, and the room gets uncomfortable. "We looked at it," someone says. "It's open source." The tone tells you everything. In that sentence, open source means unsupported, unvetted, and unsuitable for production workloads that carry regulatory weight. And if we were talking about community Keycloak downloaded from GitHub

Ajit Gupta
Apr 164 min read


Your Permissions Model Was Not Built for AI Agents
The EU AI Act is not the only regulation your enterprise needs to think about. But it is the clearest signal that the governance gap most organisations have quietly tolerated is about to become a measurable compliance liability. This is not a policy problem. It is an architectural one. The Governance Gap Nobody Talks About Most enterprises deploying AI agents rely on the same access control infrastructure they have used for a decade. RBAC. ABAC. API gateways. Firewall rules.

Ajit Gupta
Mar 314 min read
Common Questions
Insights – FAQs
What does Midships publish?
Practitioner writing on agentic AI governance, the EU AI Act and identity as the control plane, from the people doing the work.
Are the insights gated?
No. There are no gated downloads and no thought leadership theatre.
bottom of page



















