Open a developer's laptop, and you will find a stash of working credentials: cloud access keys, API tokens, SSH keys, package-registry tokens, and the secrets AI coding agents cache as they run. Network controls never see them. The identity provider decides who can log in, but not which valid keys are already on the disk. EDR watches process behavior, not the plaintext credential sitting in a config file. The credentials are present, valid, and reusable, but no layer in the stack is responsible for inventorying them.

The next phase of perimeter security starts with visibility into the credentials already sitting on the developer endpoint, before they become someone else's access.

The perimeter keeps moving

For thirty years, "securing the perimeter" has meant defending the boundary around access. First, that boundary was the corporate network. Then it became identity. Now it is wherever valid credentials live.

Era 1: The network was the perimeter