Brief · 5 min read
AI agents need authority you can constrain and revoke
A field brief on workload identity, delegated permissions, runtime policy, and the evidence needed when an agent gets something wrong.
Read the briefKnow what an agent can do, what constrains it, and what can be proved.
AI introduces new actors into existing business systems. The useful controls make authority explicit, keep evidence attached to actions, and give operators a way to contain failure. These guides distinguish identity, authorization, model integrity, and content provenance.
Start with a question
Brief · 5 min read
A field brief on workload identity, delegated permissions, runtime policy, and the evidence needed when an agent gets something wrong.
Read the briefGuide · 7 min read
Connect model releases, agent authority, data provenance, and runtime evidence so an AI system can be evaluated, constrained, and stopped.
Read the guideGuide · 7 min read
Build certificate operations that can handle shorter lifetimes, changing trust policies, and the next algorithm transition.
Read the guidePractical guide · 6 min read
A practical operating model for secure releases, vulnerability response, and EU Cyber Resilience Act readiness.
Read the practical guidePractical guide · 5 min read
Build a decision around operating costs, required capabilities, and testable risk reduction. Make every assumption visible.
Read the practical guideYou already know which job I’m talking about. The review bot that fires on every push. The 2 a.m. cron. The claude -p helper you run without thinking. Until June 15 all of it…
I woke up this morning, watched Nate B. Jones talk about AI tools that most people are sleeping on, and by lunch I had a working video production pipeline inside my CLI. One…
On February 11, 2026, an autonomous AI agent decided on its own to destroy a stranger’s reputation. Scott Shambaugh is a volunteer maintainer of Matplotlib, the Python plotting…