verifiedagents.ai
Blog

Notes on governing AI agents.

What we're learning from assessments and from teams putting agents into production.

How should an AI agent log in to the tools it calls? (hero)
October 3, 20269 min readAI Agentsmassivescale.ai

How should an AI agent log in to the tools it calls?

Don't give an AI agent a long-lived key. Use short-lived tokens issued at runtime for one tool. Ten client calls in 2026 showed the four-rung path.

By Josh Woodruff

Hero: Why Authorized AI Agent Actions Still Add Up to an Attack
September 5, 20267 min readCybersecuritymassivescale.ai

Why Authorized AI Agent Actions Still Add Up to an Attack

Agent risk is a chain of approved actions nobody scoped together. Every step passes its check. The sequence is the attack.

By Josh Woodruff

Hero: How Do You Govern AI Agents That Disappear in Minutes?
September 2, 20269 min readAI Agentsmassivescale.ai

How Do You Govern AI Agents That Disappear in Minutes?

You can't govern AI agent copies. They vanish in minutes. Govern the blueprint they're stamped from, and put its tool scope in Git.

By Josh Woodruff

Hero: How to Tell What Level Your AI Agents Are Actually Running At
June 10, 202610 min readPrivilege Changes for AI Agentsmassivescale.ai

How to Tell What Level Your AI Agents Are Actually Running At

AI agents run at four levels: intern, junior, senior, principal. Most get installed too high on day one. Here's how to find each one's real level.

By Josh Woodruff

Hero: How Should You Govern a New AI Agent? Start It as an Intern.
June 3, 20269 min readCybersecuritymassivescale.ai

How Should You Govern a New AI Agent? Start It as an Intern.

Govern a new AI agent like a new hire. Give it an identity it can't fake, log every move, and grant access in stages it has to earn. Start it as an intern.

By Josh Woodruff

Hero: What Privilege Escalation Paths Do AI Agents Create?
April 16, 20269 min readPrivilege Changes for AI Agentsmassivescale.ai

What Privilege Escalation Paths Do AI Agents Create?

48% of security pros rank agentic AI as the most dangerous attack vector. Five privilege escalation paths your traditional controls don't catch.

By Josh Woodruff

Hero: That 'Temporary' Permission You Gave Your AI Agent Is Still There
August 30, 20254 min readAI Agentsmassivescale.ai

That 'Temporary' Permission You Gave Your AI Agent Is Still There

That 'temporary' access you gave your AI 8 months ago? Time to audit those permissions!

By Josh Woodruff