SOC 2 Type II·HIPAA·ISO 27001
Field notes

Notes from the layer above the agent.

AI Workforce Infrastructure, in practice. Identity, supervision, evaluation, records, and termination — written for the people hiring, supervising, and retiring the digital employees your enterprise is bringing on. Security agents are where the urgency is. The pillars apply to every agent your team builds.

Market · Newest

Palo Alto Bought the Gateway. The Action Layer Is Where AI Governance Actually Lives.

Palo Alto Networks just acquired Portkey. Here is what it tells us about where AI agent governance is heading — and where Zenity, Noma, Geordie, Lakera, and the rest of the field actually sit on the stack.

May 1, 2026  ·  10 min read
Read the post
// AI GOVERNANCE STACK PROMPT LAYER Lakera · Lasso · Calypso AI · AIM · Prompt Security inspects tokens GATEWAY LAYER Portkey → PANW · Witness AI · Aporia ACQ · Apr 30 '26 POSTURE LAYER Noma · Zenity · (scores, doesn't block) ACTION LAYER · blast radius lives here ARX · Geordie PERMIT · ESCALATE · DENY → tool API AUDIT   layer= action   verdict= DENY   op=okta:user.deactivate
All field notes 26 posts
Market

Palo Alto Bought the Gateway. The Action Layer Is Where AI Governance Actually Lives.

What the Portkey acquisition tells us about where AI agent governance is heading — and where Zenity, Noma, Geordie, Lakera, and the rest of the field actually sit on the stack.

May 1, 202610 min
Governance

Interactive Audit Trails: Making AI Agent Governance Visible

How complete flow tracing transforms passive audit logs into an interactive, auditor-ready governance dashboard. See every policy decision, approval, and execution in context.

Apr 29, 20267 min
Integrations

ARXsec + Paperclip: Secure Document Management for AI Security Agents

Security agents don’t just query endpoints — they produce evidence. Here is how ARXsec and Paperclip close the document governance gap nobody noticed was open.

Apr 27, 20267 min
INTEGRATION

Building the LLM Red-Team Pipeline: Scanning, Validation, Orchestration

How garak, promptfoo, and pyrit work together to scan for vulnerabilities, validate exploits, and orchestrate campaigns across frontier models.

Apr 27, 20267 min
INTEGRATION

Securing Autonomous Agents: Detection, Runtime Gating, Normalization

agentic-radar, agentfence, and ai-scanner form a three-tier security stack for discovering, constraining, and normalizing autonomous agent vulnerabilities.

Apr 27, 20268 min
INTEGRATION

Pentesting Across the Stack: Infrastructure, LLM Guidance, Autonomous Loops

Why reaper, pentestgpt, and pentagi together deliver complete attack-surface coverage across traditional infrastructure and frontier model layers.

Apr 27, 20268 min
OSS Spotlight

Tachi: An Autonomous Pentest Agent We're Watching

Recon, exploit, and post-exploit reconnaissance in a single autonomous loop. Why davidmatousek/tachi is on our radar — and how ARX wraps it with policy, audit, and sandbox controls.

Apr 27, 20265 min
Open Source

Free ARX for Open Source: Our Stake in the OSS Security Community

Open source security tools are the foundation we build on. Here's what we're doing to make sure governance isn't why they lose in enterprise.

Apr 27, 20266 min
Engineering

The Three Layers of Production AI: Why Redis, Arcade, and LangChain Are Not Optional

An agent in production is not one thing. It is an orchestration layer, a tool-use layer, and a state layer — and skipping any one of them is how demos never become deployments.

Apr 23, 20267 min
AI Governance

Why AI Agents Need Data & Identity Governance

Understand why governance is critical for enterprise AI agents and how it prevents risk at scale.

Apr 20, 20268 min
Integrations

Snowflake + Sayvient Integration: Enterprise-Grade AI Governance

How to combine data governance and identity governance for complete control over AI agents.

Apr 20, 20268 min
AI Governance

Identity Governance vs. Traditional Access Control

Why traditional access control fails for AI agents and what identity governance does differently.

Apr 20, 20268 min
Frameworks

Mapping ARXsec to OWASP Agentic AI, OWASP LLM Top 10, and NIST AI RMF

Procurement is about to ask you about AI security frameworks. Here is how ARXsec's runtime controls map — including the honest gaps.

Apr 18, 20268 min
AI Governance

Frontier Models Need Frontier Governance: ARX's Maturity Model

How enterprises can govern frontier models responsibly and scale AI deployment safely.

Apr 17, 20268 min
Governance

How to Use AI Agents Safely at Your Company

The board wants AI in production. Your security team wants nothing in production. Here is how to give both of them what they want.

Apr 16, 202612 min
Launch

Introducing ARX: The Platform That Lets Your Security Team's Best Work Ship

Why we built ARX, what it does, and how to be part of the launch.

Apr 15, 20264 min
Integrations

ARXsec + Microsoft Agent Governance Toolkit: Complete Governance for Enterprise Security Agents

Microsoft governs the agent runtime. ARXsec governs what the agent touches. Here is how the two platforms combine into one governance story.

Apr 12, 20266 min
Field Notes

Your Security Team's Best Work Is Trapped on a Laptop Somewhere

Why the most effective security automation in your organization never made it to production — and what that costs you.

Apr 11, 20265 min
CISO Perspective

The CISO's AI Agent Problem Nobody Is Talking About

Shadow automation is the new shadow IT — and it's running on your security stack right now.

Apr 11, 20265 min
Compliance

How to Get a SOC 2 Report for Your Internal Security Tool

The practical guide to getting internally-built security automation through enterprise procurement.

Apr 11, 20266 min
AI Governance

Why "Human in the Loop" Means Nothing Without Infrastructure to Enforce It

The gap between AI governance policy and AI governance reality — and how to close it.

Apr 11, 20265 min
Engineering

Hardcoded API Keys Are the Single Biggest Security Risk in Your Security Program

The credential exposure problem hiding inside your team's internal security automation tools.

Apr 11, 20266 min
Audit & Compliance

What an Immutable Audit Trail Actually Means — and Why Your SIEM Is Not One

The difference between logging and compliance-grade audit trails for AI agent activity.

Apr 11, 20266 min
Industry

The Agentic Transition in Cybersecurity: What It Means for Security Teams Right Now

How the shift from AI copilots to AI agents changes everything about how security programs operate.

Apr 11, 20266 min
Engineering

How We Built ARX: The Technical Architecture of a Compliance-Native Security Agent Platform

A look under the hood at the technology decisions behind ARX — and why we made them.

Apr 11, 20268 min
Procurement

What Security Procurement Teams Are Actually Asking When They Request a VSQ

Understanding the vendor security questionnaire so you can answer it — and eventually generate it automatically.

Apr 11, 20267 min

See the platform against your own agents.

30-minute demo. We'll spin up a sandbox workspace, ingest one of your Python agents, and walk your review board through what they'd see.