AI Agent Observability Is a Security Control
Security telemetry must connect agent identity, tool requests, authorization decisions, resource effects, and recovery—not just model latency.
Published
Bryan Oubaita created Baitaphish and publishes practical cybersecurity education and source-linked research.
His work focuses on cloud and AWS security, identity, phishing defense, AI security, and agent governance. Baitaphish separates original analysis from source records and makes provenance, review dates, automation, and limitations visible.
Security telemetry must connect agent identity, tool requests, authorization decisions, resource effects, and recovery—not just model latency.
Published
An agent's effective authority spans identity, delegation, tools, credentials, policies, resources, and downstream effects—not its prompt alone.
Published
A useful cryptographic inventory connects algorithms to libraries, protocols, keys, certificates, data, owners, and replacement constraints.
Published
Use CVSS as severity evidence—not a remediation order—by adding exploitation, exposure, business context, and control evidence.
Published
GitHub OIDC eliminates stored AWS access keys, but workflow claims, role trust, session permissions, and resource reach still define risk.
Published
Effective AWS authority depends on principal, action, resource, context, and every applicable policy—not the visible wildcard count alone.
Published
Prompt injection manipulates model behavior; authorization, mediation, and resource reach determine whether manipulation becomes a harmful action.
Published
A zero-finding scan is uninterpretable unless the scanner records what it analyzed, skipped, could not build, and does not support.
Published
A source URL is not provenance. Useful intelligence preserves record identity, version, retrieval, claim scope, transformations, and uncertainty.
Published
Repository findings become more actionable when connected to identities, credentials, policies, resources, data, and reachable effects.
Published
A provider-neutral systems-security framework for constraining autonomous AI agents through capability assessment, effective authority, bounded reach, exposure-path analysis, and runtime trajectory assurance.
Published
A decision model for multi-account AWS security: trust boundaries, identity, preventive and detective controls, evidence, containment, and recovery.
Published
A vendor-neutral threat model for AI agents that separates model behavior from authorization and maps threats to controls, evidence, tests, and residual risk.
Published
A practical method for turning system boundaries and abuse paths into owned controls, observable evidence, and repeatable tests.
Published
Provenance turns a security claim into a traceable record of source, transformation, review, and intended use—without pretending lineage alone guarantees truth.
Published
NIST's current incident-response guidance integrates preparation, response, recovery, and continuous improvement across the six CSF 2.0 Functions.
Published
OPA lets you centralize policy decisions (Rego) for authz and compliance across microservices, Kubernetes, CI, and more.
Published
Sigma is a detection-rule format that lets you write once and translate to multiple SIEM backends (Splunk, Sentinel, etc.).
Published
SLSA is a maturity model for build provenance and tamper resistance. The real value is disciplined build pipelines and signed attestations.
Published
Baitaphish writing names its sources, records review dates, labels AI assistance, and states what the available evidence cannot establish. Corrections should preserve the history of a claim rather than silently replacing it.