Patterns, scenes, and what we learned shipping agents in regulated environments.

An AI agent can pass every access check and still act on something false. In Josh's Lab, a made-up source ended up in two documents. Check what agents believe.

Don't give an AI agent a long-lived key. Use short-lived tokens issued at runtime for one tool. Ten client calls in 2026 showed the four-rung path.
A practical guide to securing AI agents. What good governance looks like and how to start this quarter. Free.
One short note when we publish. No marketing list. No drip campaign.