What's still annoying about SOC 2 in 2026
We completed our first SOC 2 audit. We still suffered through manual access reviews, scattered evidence, and proving compliance with bygone requirements.
CEO
CEO
Maya is the co-founder and CEO of Oblique. She is a product leader with experience in enterprise infrastructure and security tools. She previously led product at Tailscale, software supply chain security products at GitHub, and worked on Kubernetes security and encryption at Google Cloud.
We completed our first SOC 2 audit. We still suffered through manual access reviews, scattered evidence, and proving compliance with bygone requirements.
CEO
CEO
Your users are probably looking at your application’s user list because they're completing an audit or dealing with an incident. Here’s what they need to know.
CEO
CEO
Separation of duties is framed as about blocking toxic role combinations, but what you really want is to stop someone from approving their own transactions.
CEO
CEO
The hardest part of a security policy isn't writing it, it's rolling it out. The controls have to work, and your users can't hate you when it's all done.
CEO
CEO
As part of our initial SOC2 audit, we wanted to put in place actually useful security tools. Luckily, in 2026, world-class security costs literally nothing.
CEO
CEO
Groups used for access controls can be based on department, reporting chain, or projects. The right answer is whatever maps best to how your org actually works.
CEO
CEO
IT teams are overwhelmed with never-ending access requests. Getting off the identity treadmill means getting to fewer tickets over time, not faster tickets.
CEO
CEO
The SSO tax shouldn't be about having SSO — it should be about enforcing it. The value of SSO is to centrally manage access and require strong authentication.
CEO
CEO
Recent breaches at Okta, Snowflake, and Twitter help us learn how to prevent authentication failures like credential theft, MFA bypass, and session hijacking.
CEO
CEO
Security teams underestimate the investment needed for internal tools, and so underinvest in UX. When security tools are painful to use, people bypass security.
CEO
CEO
We interviewed IT and security teams to ask them how they actually define, implement, and improve their access control policies. Get the report to learn more.
CEO
CEO
Business teams have context for access decisions but lack authority. Delegate to those closest to the resources by defining clear ownership for each app.
CEO
CEO
Internal tools built as code come with version control and audit logs for free, but git becomes a barrier for non-engineers to use these tools.
CEO
CEO
A role in RBAC should represent what someone actually does in your environment. Your job title makes a bad RBAC role: it's your position, not your function.
CEO
CEO
Comms groups map to how people actually work, but often access groups don't. Comms groups always become access groups. It's not a matter of if, but when.
CEO
CEO
Authentication has evolved from simple passwords to federated systems with passwordless logins, continuously balancing security and usability.
CEO
CEO
Organizations ask users to fill out justification fields when requesting access, but these are useless explanations. You should already have the context.
CEO
CEO
IT teams are scared to remove access they don't understand, leading to sprawling entitlements. Removing unused access isn't risky — never removing access is.
CEO
CEO
Identity management is surprisingly hard: access controls change constantly and require context. We founded Oblique to work on impactful security problems.
CEO
CEO
We’d love to help you get to more maintainable access controls