Checklist · · 29 checks
Security review checklist for an AI feature
What to check before an assistant, RAG app or agent goes in front of real users. Grouped by area, ticked off locally; progress stays in your browser.
Topic
In the glossary: Least privilege, On-behalf-of (token exchange), what each means and how to say it in a review
Part of Identity & Access: all Identity & Access entries · the Identity & Access lens on the map
Checklist · · 29 checks
What to check before an assistant, RAG app or agent goes in front of real users. Grouped by area, ticked off locally; progress stays in your browser.
Explainer · · 2 min read
Bind every AI action to a user, a service and a run, then scope the verb rather than only the data.
Deep dive · · 5 min read
Notes from building an MCP gateway. The protocol standardised how agents call tools, then stayed silent about credentials, context budgets and who may call what. That silence gets expensive as the servers multiply.
Explainer · · 2 min read
A list of tools is documentation. A registry decides who may act, as whom, and leaves proof behind.
Explainer · · 1 min read
Why shared memory becomes an access-control problem in multi-agent systems.
Explainer · · 2 min read
Why giving AI tools means designing permissions, observability, rollback, and approval paths.
Explainer · · 2 min read
Why relevant evidence is still wrong evidence if the user was not allowed to see it.