Security writing for teams
deploying AI agents

Incident analysis, architecture breakdowns, and governance frameworks — written by a security engineer, for security engineers.

Strategy April 11, 2026 · 8 min read

AI Agent Governance: Build vs. Buy

Should you build your own governance layer or buy a platform? A decision framework based on complexity, timeline, and compliance requirements.

Read post
Compliance April 11, 2026 · 9 min read

How to Set Up AI Agent Audit Trails for SOC2 Compliance

SOC2 Type II requires continuous monitoring of system activity. Here's how to build audit trails for AI agents that satisfy auditors.

Read post
Governance April 11, 2026 · 6 min read

Most Enterprises Have No Visibility Into AI Agent Actions

The deployment of AI agents is outpacing the deployment of controls. Most teams know agents are running but not what they're doing.

Read post
Compliance April 11, 2026 · 7 min read

Why Your Audit Trail Starts Too Late — Repudiation Risk in Agentic AI

OWASP T8 warns agents can operate without sufficient logging. If your audit trail starts at the SIEM, you're missing critical evidence.

Read post
Architecture April 11, 2026 · 10 min read

The Missing Layer — Why SIEM, SOAR, and Guardrails Don't Cover Agent Actions

SIEMs detect after. SOAR automates known playbooks. Guardrails filter text. None intercept agent tool calls before they execute.

Read post
SOC April 11, 2026 · 8 min read

The Agentic SOC Is Coming — But Who Governs the Agents?

CrowdStrike, Microsoft, and Palo Alto are building AI-powered SOCs. But the agents inside have the same governance gaps.

Read post
OWASP T2 April 11, 2026 · 7 min read

Tool Misuse Is the Biggest Agentic AI Threat You're Not Monitoring

OWASP T2 is the highest-risk threat for teams with AI agents that have API and infrastructure access.

Read post
OWASP April 11, 2026 · 12 min read

OWASP's 17 Agentic AI Threats — What They Mean for Your Security Team

The full T1–T17 taxonomy. Not a Top 10 — 17 distinct threat categories for AI agents with tool access.

Read post
Incident Analysis April 13, 2026 · 7 min read

How a Claude AI Agent Started Deleting Production Files — and Why No Tool Stopped It

A Claude agent with filesystem access began deleting production files. The SOC team caught it — but only after the damage was done. No existing tool intercepted it before it executed. This is the incident that led to Intercis.

Read post
Governance April 8, 2026 · 11 min read

What is AI Agent Governance?

AI agents with filesystem access, cloud credentials, and CI/CD pipelines can take real actions with real consequences. AI agent governance is the policy enforcement, monitoring, and audit layer that controls what they're allowed to do — and stops them before they execute.

Read post
Architecture April 10, 2026 · 10 min read

Proxy vs SDK: Two Architectures for AI Agent Enforcement

Compare in-process SDK enforcement and out-of-process proxy enforcement for AI agents. Learn the trade-offs in tamper resistance, deployment complexity, and multi-agent support.

Read post

More posts coming soon

OWASP Agentic AI Top 10 · AI agent audit trails for SOC2 compliance