Learn to secure
agent actions

In-depth, evergreen writing for the people wiring agents into real systems - and the people accountable when they act. For timelier notes, see the Blog.

Coming next

Guide· Coming soon

A threat model for tool-using agents

What actually goes wrong when an agent has credentials - from prompt injection to tool abuse to data exfiltration.

Guide· Coming soon

Designing human approval that people don't hate

Approval flows that catch what matters without turning your on-call into a click farm.

Guide· Coming soon

Short-lived credentials for autonomous systems

Why standing service keys and agents don't mix - and what scoped access looks like in practice.