AI Agent Observability Is a Security Control
Security telemetry must connect agent identity, tool requests, authorization decisions, resource effects, and recovery—not just model latency.
Security telemetry must connect agent identity, tool requests, authorization decisions, resource effects, and recovery—not just model latency.
An agent's effective authority spans identity, delegation, tools, credentials, policies, resources, and downstream effects—not its prompt alone.
Prompt injection manipulates model behavior; authorization, mediation, and resource reach determine whether manipulation becomes a harmful action.
GitHub OIDC eliminates stored AWS access keys, but workflow claims, role trust, session permissions, and resource reach still define risk.
A zero-finding scan is uninterpretable unless the scanner records what it analyzed, skipped, could not build, and does not support.
Repository findings become more actionable when connected to identities, credentials, policies, resources, data, and reachable effects.
Use CVSS as severity evidence—not a remediation order—by adding exploitation, exposure, business context, and control evidence.
A source URL is not provenance. Useful intelligence preserves record identity, version, retrieval, claim scope, transformations, and uncertainty.
A useful cryptographic inventory connects algorithms to libraries, protocols, keys, certificates, data, owners, and replacement constraints.
Effective AWS authority depends on principal, action, resource, context, and every applicable policy—not the visible wildcard count alone.