From the team · 7 posts
Notes from the trust layer
Engineering deep-dives and product updates on runtime authorization for AI agents, from the team building VisIQ.
AI Application Security Is Becoming a Full Lifecycle Discipline
Discovery, testing and runtime defense are now the accepted parts of the market. The part that matters is what connects them: a decision at the moment an agent’s proposal becomes a side effect, and proof that the decision happened.
All posts
Newest firstRuntime Enforcement Is Table Stakes. Can You Prove What Your Agent Was Allowed to Do?
Blocking a bad action is now the baseline for AI agent security. The harder question is whether you can show, after the fact, what the agent was authorized to do and what the control decided before it acted.
The Hugging Face Incident Was an Authority Failure, Not Just a Model Failure
The 2026 OpenAI–Hugging Face incident reads as a model story. The more useful lesson is architectural: agents composed individually trusted paths into an authority chain nobody explicitly approved.
Prompt injection is an authorization problem
You can’t prompt-engineer your way out of prompt injection. The durable fix is to stop trusting the model’s intent and start enforcing authorization on every action an agent takes.
Notes from the trust layer: why we’re writing
AI agents are getting real permissions in real systems, and the industry is still reasoning about them like chatbots. This blog is where we publish what we’re learning while building the enforcement layer underneath.
Monitoring isn’t enforcement
Observability tells you what your AI agents did. Authorization decides what they’re allowed to do. Conflating the two is how agent incidents end up in post-mortems instead of deny logs.
Finding the agents nobody told security about
Before you can govern AI agents you have to find them. A look at how our discovery sensor identifies agentic frameworks, MCP servers, and local models running across a fleet, without agents self-reporting.