Notes on governing AI agents.
What we're learning from assessments and from teams putting agents into production.

How should an AI agent log in to the tools it calls?
Don't give an AI agent a long-lived key. Use short-lived tokens issued at runtime for one tool. Ten client calls in 2026 showed the four-rung path.
By Josh Woodruff

What Is an OAuth Consent Grant, and Why Is It Your Fastest AI Inventory?
Every AI tool connected to your email or files left an OAuth consent grant in your identity provider. Here's how to pull that list this week, for free.
By Josh Woodruff

What Is the Confused Deputy Problem in AI Agent Gateways?
A gateway that reuses its own login for every downstream call hides which AI agent actually made the call. Token exchange fixes it with a narrow token.
By Josh Woodruff

Why Your Security Tools Can't See What Your AI Agents Do
Your CASB, EDR, and DLP watch people and devices. AI agents call tools through MCP, which looks like normal web traffic, so their calls slip past unseen.
By Josh Woodruff

Where Should Deterministic Code End and the LLM Begin?
Two teams in unrelated industries drew the same line independently. The useful question isn't whether to use AI. It's which parts stay deterministic.
By Josh Woodruff

Where Do You Stop an AI-Suggested Software Install?
Put the control where the command runs, not in the AI tool. Tenant settings stop at the copy button. Enforce on the endpoint and at the network exit.
By Josh Woodruff

Who Approves the Code Your AI Agent Just Wrote?
Coding agents came up on eleven security calls in seven months. Only two of those calls were about coding agents on purpose. The rest were discoveries.
By Josh Woodruff

What Is a Kill Switch for AI Agents, and How Do You Build One?
When an agent goes wrong, seconds count. A kill switch stops the damage. One team found their backup switch had a 45-second delay, an eternity at machine speed.
By Josh Woodruff

What Should Your First 90 Days of Agentic AI Look Like?
Deploy your first AI agent in 90 days without a disaster: find your hidden AI, pick one contained use case, and build boundaries in from day one.
By Josh Woodruff

Why Did Klarna Reverse Its AI Layoffs, and Who's Next in 2026?
Klarna replaced 700 customer service jobs with AI in 2024, reversed in May 2025. Salesforce and Block followed in 2026. Why the pattern repeats.
By Josh Woodruff

Why Zero Trust Needs More for AI Agents (and How to Fix It)
Zero Trust was designed for humans logging into systems. AI agents don't log in...they act, chain decisions, and call systems continuously. Here's what to do.
By Josh Woodruff

What Is Shadow AI and How Do You Find It Before It Finds You?
The biggest AI security threat isn't a nation-state hacker. It's the employee who uploaded files to make their job easier. See how to find and govern shadow AI.
By Josh Woodruff

AI Agents Are Failing: Why Your Data is the Real ROI Killer
30% of GenAI projects will be abandoned by 2026. Discover why your data—not the AI—is the real reason for failure and how to fix it with our 5-step audit.
By Josh Woodruff

Why Microsoft 365 Copilot's Hacking Shows the Need for Zero Trust
In our rush to adopt AI, we forgot everything we every learned about security. Learn how all AI agents are vulnerable and need Zero Trust security.
By Josh Woodruff