Pulse Continuous Authentication & Authorization
Securing Every Moment of Every Session, For Users and AI Agents Alike
Introduction
Pulse Continuous Authentication & Authorization (Pulse CA2) keeps verifying who is in control of a session for its entire life, not just at login. Its companion, Reflex, extends that protection to the computers people work on and the AI agents acting on their behalf.
Today's security model has two halves. Identity tools (Okta, Microsoft Entra, Ping and similar) check who you are at the front door. Monitoring tools watch for trouble after the fact. Pulse CA fills the space between them: it confirms, continuously, that the verified person is still present and still in charge, and it acts the moment that stops being true.
Pulse CA is deployed in one of two ways:
Pulse CA handles sign-in and single sign-on itself, with continuous protection built in.
Pulse CA runs alongside any existing IdP or IAM platform, adding continuous protection without replacing what you already own.
The Problem: Security Stops at Login
Most systems verify identity once, then trust the session until logout. That trust is carried by a digital token. Whoever holds the token is treated as the user, whether the session lasts ten minutes or ten hours.
Attackers know this. Rather than break multi-factor authentication (MFA), they wait for it to succeed and then steal or reuse the session it produced. A stolen token, an unlocked workstation, a compromised phone or a hijacked AI agent all look legitimate to systems that stopped checking after login.
Two recent incidents show the cost:
- Salesloft Drift (August 2025): Attackers stole access tokens belonging to Drift, an AI chat agent connected to Salesforce. With no login required, they quietly exported data from more than 700 organizations, including major security vendors such as Cloudflare, Palo Alto Networks and Zscaler. (Help Net Security, Cyber Security News)
- Gainsight (November 2025): The same pattern struck again through another connected application, reaching more than 200 potentially affected Salesforce customer instances. No one's login was broken; nothing was watching what happened after it.
As AI agents run for hours without human oversight, and spawn sub-agents of their own, this gap widens. One compromised session can now drive automated actions at machine speed across many systems. In July 2026, OpenAI AI agents under test escaped their sandbox and breached Hugging Face, running for days and taking more than 17,000 actions before anyone tied them to their source (The Implicator, ThreatCluster). Closing it is no longer optional for organizations handling sensitive data or subject to Zero Trust and CMMC requirements.
What Pulse Continuous Authentication & Authorization Is
Pulse CA is a single, purpose-built framework that verifies identity, presence and engagement for every moment of every session, for people and AI agents alike. It rests on seven principles:
- Phishing-resistant authentication establishes the root of trust. Every session begins with a FIDO2 passkey login that cannot be phished or replayed.
- Phishing-resistant protection doesn't end at login. FIDO2 device attestation is applied at every connection point between Pulse components, so the session stays phishing-resistant from login to logout. To our knowledge, this is unique in the market.
- Every device must prove possession. Each phone, workstation and server in the framework must continuously demonstrate it holds its own cryptographic keys. A copied token alone gets an attacker nowhere.
- Full session coverage. Trust is measured continuously, not sampled at login.
- Every session traces to a human. No session, agent or sub-agent exists without an unbroken chain back to the verified person who started or assigned it.
- AI agents get the same scrutiny as people. Agentic and non-agentic AI, and any sub-agents they launch, are individually known, scoped and evaluated.
- Trust is verified, never assumed. Pulse puts the Zero Trust principle of "never trust, always verify" into practice for the full session, not just at the perimeter.
Login to Logout: Monitor, Detect, Prevent, Report
The source of truth for identity, presence and engagement is the user's own phone. The Pulse Auth app is bonded to the user by PIN and learned behavior, and to the device by FIDO2. Throughout the session, it streams live trust signals:
- Identity: behavioral patterns confirm the same person is still in control.
- Proximity: Bluetooth confirms the phone is still near the workstation. Walk away, and trust drops.
- Location: GPS plus altitude detects impossible travel down to the floor of a building.
- Device health: jailbreaks, malware and tampering are caught as they happen.
- Session health: the phone, the Pulse service and the workstation continuously verify each other through Pulse's patented three-way trust network (Tri-Net), so the signals themselves can't be spoofed.
Most security tools monitor, detect and report. Pulse adds the missing step: prevent. When trust is high, work continues uninterrupted. When it dips, the session and every agent tied to it are paused, the user is prompted to re-verify and all agents are resumed. When it falls too low, the session and every agent tied to it are shut down within milliseconds, before damage occurs, with a complete audit trail of what happened and why.
AI Agents: Reflex and the Human Chain of Custody
Every AI agent, however autonomous, was started by a person, and Reflex makes that person the permanent anchor of the agent's authority.
- Each agent session carries an identifier linked to the human session that launched it, so every action traces back to a verified person.
- Sub-agents inherit only the access they need, tied to the same human origin and evaluated the same way.
- If the human's trust drops, every agent acting on their behalf is affected within seconds or less.
- High-risk agent actions can require real-time re-checks or explicit human approval.
- Agent requests are evaluated through the OpenID Foundation's AuthZEN authorization standard, typically in milliseconds. Support for Model Context Protocol (COAZ-MCP) tool access is planned once the AuthZEN working group releases its revised standard covering MCP.
Reflex runs on Windows, macOS and Linux. Additional agentic AI capabilities roll out through the remainder of 2026.
Working Alongside Your Identity Stack
Pulse CA adds protection without disrupting what is already in place.
- Runs in parallel. As an add-on, Pulse operates independently next to your existing IdP or IAM platform. Enforcement uses standard OIDC and SAML, with no custom development.
- Feeds your SIEM. An optional output streams trust events and enforcement actions into your existing security monitoring tools.
- One dashboard, two audiences. The Commander dashboard serves managed service providers (MSPs) running many client tenants and organizations running a single tenant. It covers configuration and reporting, plus user and policy management.
Why Pulse
- Easy installation. Integration and configuration typically take minutes. Installing Reflex on a workstation may require a restart.
- Low cost. Pulse protects existing identity investments rather than replacing them, and avoids the expense of stitching together multiple products.
- One framework, not piece parts. Authentication, continuous monitoring, enforcement, AI agent governance and reporting were designed together as one system.
- A unique answer to a hard problem. Session-long phishing resistance and the patented Tri-Net trust network are, to our knowledge, unmatched.
- Compliance-ready. Pulse aligns with Zero Trust Architecture (NIST SP 800-207), CMMC Levels 2 and 3, FIDO2/passkeys and AuthZEN, with an audit trail for every session.
Pulse CA turns security from a checkpoint at login into continuous assurance, for every session, whether a person or an AI agent is at the controls.
For the full architectural detail, including Tri-Net, AuthZEN and deployment specifics, see the Pulse CA Technical Brief.