Ashur Kanoon

Director of Technical Product Marketing

Expertise

  • Cybersecurity
  • Identity and access management
  • Non-human identity
  • Workload identity and access management
  • AI agent security
  • Enterprise security
  • Cloud and infrastructure security
  • Enterprise networking
  • Authentication and authorization
  • Software engineering
  • Product management
  • Technical product marketing

About Author

Ashur Kanoon is the technical product marketing guy at Aembit. He started his career as a software engineer at Cisco working on Y2K. Yes, that Y2K. Today, he takes what excited and highly caffeinated engineers build and makes sure business and technical buyers understand why it matters. He has done this at a spinout that was lateracquired and at two other startups, both of which were also acquired.Outside of work, Ashur enjoys mechanical things, mostly cars and watches, and spending time with his wife and two teenagers.

Education

  • Center for Executive Education, University of California, Berkeley
  • Master of Business Administration, San José State University
  • Bachelor’s degree in computer information systems, DeVry Institute of Technology

Certifications

  • AWS Certified Cloud Practitioner
  • CCNA, Cisco
  • JNCIS-AC, Juniper Networks

Articles by Ashur Kanoon

The second in a five-part series on how MCP is moving beyond tool calling, and what that shift means for agent workflows, interoperability, and enterprise use.
OAuth is an authorization framework that defines how to grant access. JWT is a token format that defines how to package and transmit claims. They solve different problems, and most production systems use both.
OAuth 2.1 eliminates implicit flow, mandates PKCE, and requires exact redirect matching.
The first in a five-part series on how MCP is changing for real-world use, and what those changes mean for teams building and securing agent systems.
Aembit adds an OpenAI Workload Identity Federation Credential Provider, replacing static sk-proj-… keys with short-lived, identity-bound tokens.
Aembit’s new Credential Provider automates Claude API Workload Identity Federation, retiring static keys for short-lived tokens.
AI agents need more than working credentials. They need verifiable identity, task-scoped access, and clear attribution.
A working prototype can mask the harder problem: keeping every workload, agent, credential, policy, and audit trail consistent across production environments.
AI agents exchange sensitive contexts across MCP servers in seconds. Without context-aware auditing, you can’t trace who accessed what.
Most CISOs fear AI agent risks, but legacy IAM can’t govern autonomous systems. A new identity model built on attestation is emerging.