Writing
Notes from building the evidence layer.
Why agents sit in security review, what a reviewer will actually accept, and how a decision becomes something a third party can check. No predictions, and nothing we have not built.
Latest
Your Agent Is Not Blocked Because It Is Unsafe
It is blocked because nobody can prove what it did. Six weeks in security review, and the question holding it up is not whether the agent can be attacked. Everyone accepts that it can.
Earlier
- June 5, 2026Your AI Agent Passed OAuth. Now What?One developer logged 4,519 tool calls from his AI agent. 63 of them were things he never authorized. The agent had valid credentials the whole time. Here's why that's not a security problem — it's an infrastructure problem nobody has solved yet.9 min read
- June 2, 2026Introducing the Agent Authorization Standard (AAS) v0.1OAuth and RBAC answer one question: is this identity allowed in? They were never designed to answer what actually matters for autonomous agents. AAS is a vendor-neutral standard that does.10 min read
- May 29, 2026Why Microsoft's Agent Governance Toolkit Misses Kill ChainsMicrosoft's Agent Governance Toolkit validates each agent request independently. That's not enough. Here's the attack it can't see — and why stateful behavioral analysis is the only defense.8 min read