Category
Governance, Security & Compliance
7 stories
What actually counts as 'compliant' when someone asks a small business to prove it?
Start with two things: the basic controls actually configured and working -- multi-factor authentication, endpoint protection, patching, backup that has been test-restored -- and three documents that describe them: an...
2026-09-05I gave my agents a veto. Here is what it cost me.
One of the shortest things I wrote last August was an amendment I dropped into a policy agents were already drafting while I typed. Eleven words: financial figures are never shared publicly, no exception clause.
2026-08-25Featured storyThe five-field form that made 32 architecture decisions citable
A security platform team had made 32 real architecture decisions over the life of the product -- which database to trust, how to make an audit log tamper-evident, how to structure a permission model. Every one of those...
2026-08-25Can your team catch its own boss's mistake? Mine did -- twice, the same week.
I wrote a rule once that said every supporting quote in a piece of work needed to be at least five words long. Clean, sensible, easy to defend in a meeting.
2026-08-25Why Can a Second AI Opinion Still Leave You With the Wrong Decision?
Ask a second AI for a check on a plan, get an answer that agrees with the first one, and you still have no idea whether the work is safe to fund. In our own platform planning, the working plan said 8 features and 24...
2026-07-04Why Isn't a Merged Pull Request the Same as an Approval?
Pick one of the last five consequential changes we merged. If we cannot show who authorized the next action for those exact bytes, under which current policy, and with what current evidence, we are one deployment away...
2026-05-14Is the Rule You Rely On Actually a Control, or Just a Wish?
Pick one consequential rule in an AI-assisted workflow. List every route that can perform the action and the current denial evidence for each route.
2026-03-10