Autonomous Response1The Case for Autonomous Response: Machine-Speed Threats Need Machine-Speed ContainmentWatch2Investigation as a Pipeline: Signal Triage, Evidence Gathering, and Hypothesis TestingWatch3Containment Primitives for Agents: Quarantine, Capability Revocation, and Safe RollbackWatch4Guardrails on the Responder Itself: The Autonomy-Safety Trade-offWatch5Measuring Response: MTTD, MTTR, and the False-Containment CostWatch
Agent Behavior Security1From Signatures to Behavior: Why Static and Permission Controls Fail on Non-Deterministic AgentsWatch2Building a Behavioral Baseline: Action Distributions, Tool-Call Profiles, and Sequence ModelsWatch3Anomaly Detection on Agent Traces: Sequence Models, Embeddings, and the Cold-Start ProblemWatch4Behavior as Enforcement: Allow and Deny by Observed Behavior, Not Just Static PermissionWatch5Evasion and Robustness: Mimicry Attacks on Behavioral Detectors and Their Provable LimitsWatch
Agent Goal-Drift Detection1The Goal-Drift Problem: What Drift Is, Why Non-Determinism Makes It Inevitable, and the Detection ObjectiveWatch2Specifying Intended Behavior: Goal Representations, Invariants, and the Reference Policy to Drift FromWatch3Detecting Drift at Runtime: Trajectory Distance, Reward-Model Monitors, and Statistical Change DetectionWatch4The Base-Rate Problem: False-Positive Cost, Drift Budgets, and Calibrated Escalation ThresholdsWatch5Closing the Loop: Correction, Rollback, and Human Re-Grounding Without Halting the FleetWatch
Agent Identity & Lifecycle1Non-Human Identity for Agents: Why Agents Break Human IAM and What a Machine Identity NeedsWatch2Provisioning and Attestation: Issuing, Binding, and Proving an Agent's IdentityWatch3Credential Lifecycle: Short-Lived Tokens, Rotation, and Delegation Chains at RuntimeWatch4Decommissioning and Revocation: Killing an Agent's Authority Cleanly and ProvablyWatch5Governing the Fleet: Identity Inventory, Least-Privilege Drift, and Lifecycle AuditWatch
Intent-Based Governance1The Intent-Governance Model: Governing by Declared Intent Rather Than Enumerated PermissionsWatch2Capturing and Verifying Intent: Intent Specs, Provenance, and the Intent-Action GapWatch3Policy as Intent: Compiling Intent into Enforceable Runtime Guardrails and Where It Fails OpenWatch4Measuring Intent Conformance: Did the Agent Do What Was Asked, and Only That?Watch5Governance at Scale: Intent Ledgers, Audit Trails, and Mapping to NIST AI RMF and the EU AI ActWatch
Agent Observability1The Observability Gap: Why Traditional APM Fails on Non-Deterministic AI SystemsWatch2The Pillars for AI: Traces, Metrics, and Evals as First-Class TelemetryWatch3Semantic Telemetry: Capturing Reasoning, Tool Calls, and Decision Provenance with OpenTelemetry GenAIWatch4Detecting Regressions Without Ground Truth: Reference-Free Evals and Drift SignalsWatch5An Observability Reference Architecture: Sampling, Cost, Privacy, and the Feedback LoopWatch
AI Security Baseline1Why a Baseline: The 80/20 of AI Security and the Cost of Having No FloorWatch2The Baseline Control Set: The Minimum Controls Every AI System Must HaveWatch3Input, Retrieval, and Tool Boundaries: The Non-Negotiable Runtime GuardrailsWatch4Identity, Logging, and Human-in-the-Loop: The Governance FloorWatch5Adopting the Baseline: A Maturity Ladder, a Checklist, and a CI GateWatch
Autonomous SOC: Authority1The Irreversibility Spectrum: A Taxonomy of Autonomous SOC ActionsWatch2Principal Hierarchies in AI-Automated Response: Who Governs the Responder?Watch3Chain-of-Custody in AI-Mediated ForensicsWatch4Playbook Drift as an Attack Surface: When SOAR Updates ItselfWatch5Measuring Autonomous SOC Readiness: An Assessment FrameworkWatch
Autonomous SOC: Detection Limits1Statistical Limits of Autonomous Anomaly DetectionWatch2Concept Drift in Production Detection Models: The Defender's Red QueenWatch3Cross-Tenant Leakage in Shared Detection ModelsWatch4The Causal Gap: Why Correlation-Based Triage Fails Low-and-Slow AttacksWatch5Evaluating Detection Fidelity Without Ground TruthWatch
Multi-Agent Trust Models1The Multi-Agent Trust Problem: Why Agent Meshes Break Perimeter and Single-Identity AssumptionsWatch2Trust Models for Agents: Capability-Based, Reputation-Based, and Zero-Trust for MeshesWatch3Delegation and Transitive Trust: Trust Propagation, Confused-Deputy at Scale, and Chain-Length LimitsWatch4Verifiable Inter-Agent Claims: Attestation and Signed Provenance Between AgentsWatch5A Reference Architecture: Trust Brokers, Policy Meshes, and Failure ContainmentWatch