25 Aug 2026
How to attack your own agent estate: the five objectives worth testing, twenty concrete tests across injection, entitlement, parameters, chains and data, how to score results, and how to run it safely in production.
Read the guide →
25 Aug 2026
An incident runbook for agent estates: the first ten minutes, why containment differs from conventional IR, six agent-specific incident types, blast-radius reconstruction, and what to preserve before you kill the agent.
Read the guide →
25 Aug 2026
What breaks when agents call agents: authority propagation, the amplification problem, four trust models, why a delegating agent must never widen scope, loop detection across agents, and the evidence a multi-agent chain needs.
Read the guide →
25 Aug 2026
Segregation of duties applied to autonomous agents: the five roles that must not collapse, why one agent completing a whole process is the control failure, compensating controls, and how to test for collusion paths.
Read the guide →
25 Aug 2026
Enterprises have an identity layer and a data layer but no authority layer. What it is, the four questions it answers, why authority cannot be delegated to the model, and how the layer assembles from parts you already have.
Read the guide →
25 Aug 2026
A practical guide to bounding agent actions: the five levers, how to write your first three rules, blocking dangerous calls before execution, what to do in week one, and how to tell a control from a preference.
Read the guide →
25 Aug 2026
Classic injection weaknesses when a language model supplies the parameters: five injection classes, why model-supplied input is worse than user input, schema-level defences, SSRF specifics for tool URLs, and a testing method.
Read the guide →
25 Aug 2026
Where sensitive data actually moves in an MCP estate: the six exposure surfaces, classification at call time, redaction versus tokenisation, the exfiltration pair problem, and why conventional DLP misses agents entirely.
Read the guide →
25 Aug 2026
Why the standard multi-tenant MCP pattern is a breach waiting to happen, four isolation models compared, why tenant must bind to identity rather than a parameter, the leakage paths, and how to test isolation in an afternoon.
Read the guide →
25 Aug 2026
How OAuth actually secures an MCP deployment: the seven token validation checks, audience binding, why bearer tokens leak through tool parameters, token exchange for delegation, and the eight-point hardening checklist.
Read the guide →