Writing on AI agent security, agent identity, delegated authorization, MCP, and Agent Runtime Governance for the enterprise.
Validated content only. Every post is backed by working code we build and run across the full stack, from the agents to the interface to the backend. If it is here, we have implemented it.
Filter by topic
Tap a star to filter. Brighter stars cover more posts. Connections show topics that appear together in the same post.
Subscribe to Watchlight Insights
Get new writing on Agent Runtime Governance, AI agent security, agent identity, and delegated authorization, delivered when we publish. No noise, just the new posts.
Runtime authorization went mainstream this year. Identity, PAM, cloud, MCP, and agent-security vendors all now check the action. That convergence validates the category we defined, and it moves the real question. Identity establishes who the agent is and what it can access. The harder problem is whether, how, and under whose delegated authority the agent may act, enforced where actions execute, with the lineage of what follows preserved. A single check is a feature. That is an architecture.
An AI agent run is a long stream of decisions, but in each one there is exactly one point where governance can change what happens: the moment the agent turns intent into action. Before it, the agent has only formed a plan. After it, the action has already reached your systems. Identity, guardrails, and detection all sit on the wrong side of that moment. Governing it is the job of Agent Runtime Governance.
Every IAM team is now getting the same question from the business: how do we handle identity and access for our AI agents? The honest answer is that the identity architecture you spent years building was designed for humans and applications, and agents are neither. Agentic IAM Architecture is our flagship engagement to design enterprise identity and access for AI agents, autonomous workflows, machine identities, and human-to-agent delegation.
The identity industry is quietly standardizing how AI agents carry authority delegated from a human. It is real progress, and if you run agents it is coming to your stack. But every one of these standards describes the authority an agent may hold. None of them, on their own, enforce that the agent stayed inside it when it acted, or prove that it did. That is Agent Runtime Governance, and it is the part they leave to you.
Give an AI agent an identity and a role and it is easy to feel like you have governed it. You have authenticated it. You have not decided what it may actually do. Identity establishes who the agent is. Something else has to determine what authority that agent may exercise for the task in front of it, and for agents that authority is not fixed.
An autonomous agent deletes something it should not have. Within the hour you are asked two questions: why was it allowed to do that, and can you prove it. Application logs answer neither. They show that the delete happened. They do not show the authority that permitted it, and they can be edited. US regulators, from the SEC's incident-disclosure rules to the NIST AI RMF, are already moving toward requiring the answer, and you cannot reconstruct it after the fact. You either recorded it at runtime or you did not.
Enterprise identity has started treating AI agents as first-class identities with delegated authority. Okta and Ping both shipped for it in the last year. That is the right move, and it is only half of the problem. Issuing a scoped token decides what an agent may do. Something still has to decide, at the moment of every action and across the whole delegation chain, whether it actually did, and then prove it. That layer is Agent Runtime Governance.
A framework only matters if something implements it. We authored the 12 Non-Negotiable Principles for Agent Runtime Governance, and we build the control plane that delivers them. Here is the direct mapping from each principle to the Watchlight AI Beacon capability that implements it, including the one principle still on the roadmap, because a control matrix is only useful if it is honest.
Watchlight AI Beacon is easy to file under AI security or agent security, another tool that monitors AI agent behavior and flags anything that looks wrong. It belongs somewhere else entirely. Agent Runtime Governance is not a security product. It is a different category, closer to identity and PKI than to any scanner, and that difference is the reason it becomes critical infrastructure rather than another line in the security budget.
The 12 Principles tell you what to build. The maturity model tells you where you are and what to do next. Five levels, from agents deployed with no governance at all to fully governed multi-agent operations. Find the row that matches your reality today, see exactly which principles move you up, and get a clear path to mature.
The enterprise is being rebuilt on AI compute, and that compute does not just answer questions. It acts. When autonomous action becomes the substrate of how work gets done, the layer that governs those actions at runtime stops being a feature and becomes infrastructure, the way identity and PKI did before it. Here is the case that Agent Runtime Governance is on that trajectory, and what it means for enterprises standing up agents now.
When an AI agent does something it should not have, the first question is what exactly happened and who authorized it. Application logs cannot answer that. Agent Runtime Attestation gives every governed agent action a chain of custody: a signed, tamper-evident record of the authority behind it and what it did, so you can prove what your agents have done to a security team, a compliance officer, and an auditor.
Watchlight AI Beacon now governs LangChain deep agents. Every tool call, filesystem operation, and sub-agent action is authorized against policy before it executes, before it ever places a request on the wire, each sub-agent under its own explicit, narrowed authority so delegation never becomes privilege escalation. A drop-in integration, no changes to your tool code. Request early access through the Founding Design Partner program.
Strip away the branding and every long running autonomous AI agent is the same thing: a loop that reasons, acts, sees the result, and decides again, on its own and at machine speed. That loop is what makes agents valuable and what makes them risky, and it is the one thing traditional security was never built to govern. Here is why the agentic loop is the real unit of risk, and what it takes to govern it at runtime.
Enterprises already believe in zero standing privileges for people and service accounts. For AI agents, most have quietly abandoned it: agents run with broad, always-on credentials that make every compromise catastrophic. Here is why standing access is more dangerous for agents than for any prior identity, why the tools that deliver zero standing privileges for humans do not translate, and how Agent Runtime Governance delivers the outcome at the layer where agents actually act.
The instinct to verify agent intent with a supervisor LLM that reads the agent's chain-of-thought is a trap. A model that judges another model inherits its non-determinism, its susceptibility to prompt injection, and its persuasiveness. The durable approach authorizes the action against deterministic policy, treats declared intent as governed evidence with provenance, and measures alignment with statistical drift rather than a second model.
Watchlight AI adds a fifth advisory workshop: AI Agent Identity and Access. A hands-on engagement to design and stand up verifiable agent identity, scoped and time-bound access, and governed delegation, all enforced at runtime under Agent Runtime Governance. Your team leaves with a working reference implementation and a rollout plan.
Watchlight AI Beacon now governs agents built on Anthropic's Claude Agent SDK. A one-line integration authorizes every tool call against policy, including the calls made by subagents, each under its own scoped authority so delegation never becomes privilege escalation. High-risk actions can be held for human approval, outbound traffic routes through a network proxy with no change to agent code, and the full delegation tree lands in a forensic, tamper-evident record. Two enforcement boundaries, one governance plane.
Watchlight AI Beacon now governs agents running on OpenClaw. A drop-in plugin authorizes every tool call against current policy, gates high-risk actions for human approval, and surfaces agents that probe the gate, while a network-layer proxy enforces the same policy at the wire. Two independent enforcement boundaries, one governance plane, no agent code changes.
Three new Watchlight AI services for Agent Runtime Governance: an Executive Briefing for boards and senior leadership, an Implementation engagement that brings a governance architecture into production, and an Advisory Retainer that puts an ARG architect on call. Plus a new free 30-minute consultation that opens the conversation for any enterprise team.
Every CISO running AI agents in production eventually asks the same question: how worried should I be about this agent? Authority Blast Radius is the answer Watchlight AI Beacon gives, in a form a security team, a compliance officer, and an operator can all use.
Watchlight AI Beacon ships runtime governance plugins for the agent frameworks enterprises are actually deploying: LangGraph, Google ADK, AWS Bedrock Agents, and MCP servers, plus a contract for custom in-house agents. One governance plane, the same policy and audit trail across every framework.
The existing AI security ecosystem inspects, classifies, and detects. It is necessary and valuable. It does not answer the question autonomous AI now demands: what is this system actually permitted to do, right now, given its intent, authority, and delegation chain? That answer requires a new control plane.
Every action an AI agent takes proceeds through three stages: Plan, Act, Observe. Governance attached only at the network gateway is governance after the decision. Authorization belongs at the plan stage, where it costs nothing to deny.
Most organizations cannot answer basic questions about how their AI agents are governed. We built a free assessment tool that gives you a clear picture in 5 minutes: your maturity level, your specific gaps, and what to do next.
Semantic governance interprets what an agent means to do. Agent Runtime Governance controls what an agent is allowed to do. Interpretation is not enforcement. Enterprises need both.
Verifiable Credentials help establish who an agent is. Agent Runtime Governance determines whether that agent should take a specific action in a specific moment. Identity is not control. The enterprise needs both.
How does a peer agent, a downstream system, or an auditor verify that an AI agent is who it claims to be, has the authority it claims to have, and meets the governance requirements it claims to meet? Verifiable Credentials offer a cryptographic answer that works across trust boundaries.
Traditional IAM answers who an agent is and what it can generally access. AI agents introduce a different class of question: should this agent perform this specific action, right now, in this context, for this goal, under this delegation chain? That is not an identity question. It is a runtime governance question.
The recent attention on MCP-related risks is being framed as a bug or a developer mistake. The deeper lesson is architectural. AI agents are being given connectivity and capability without a runtime layer that decides whether a specific action should proceed.
A growing wave of solutions can detect when an AI agent does something wrong. But detection happens after execution has begun. The question enterprises should be asking is not 'what went wrong?' but 'was this action ever authorized in the first place?'
The final principle. When agents work together, governance complexity does not just increase — it changes shape. Single-agent governance is necessary. It is not sufficient. Principle 12 completes the framework.
AI agents act at machine speed across systems, but security teams have no real-time picture of what is actually happening. The Agent Execution Graph changes that. It is a live, queryable graph of every agent action, every policy decision, and every delegation hop, materialized as events flow.
Endpoint Detection and Response answers what happened on a system. Agent Runtime Governance answers what should be allowed to happen. Both are necessary. Neither can substitute for the other.
Organizations are deploying AI agents that call APIs, access SaaS systems, and execute workflows autonomously. Traditional IAM governs access to systems. It does not govern the decisions agents make. Agent Runtime Governance is the missing control plane.
NIST NCCoE invited industry input on AI agent identity and authorization. We submitted a technical companion with 20 architectural diagrams showing how existing standards can compose into a governance architecture for AI agents.
AI agents are moving from experimentation to enterprise production. Before that transition happens, security leaders need answers to seven fundamental questions that traditional IAM cannot address.
Your AI agents are making thousands of decisions per hour. When your CISO asks 'how did that agent get access to our CRM?', can you answer in under 60 seconds? Most platforms tell you what happened. Execution Lineage tells you how.
Today we are opening the Founding Design Partner Program: a small cohort of organizations collaborating with us to define how autonomous AI agents should be governed at runtime. This is a milestone we have been building toward for a long time.
An agent with ungoverned tool access is an employee with the master key to every system in the building and no record of which doors they opened. Tools are how agents act on the world. If you do not govern tool access, you do not govern agent behavior.
Agents will fail. The question is not whether, but how. Traditional software fails in predictable ways. Agents fail mid-plan, mid-delegation, mid-action, with partial state scattered across systems and other agents still operating on assumptions that are no longer valid. If your failure model does not account for this, you do not have one.
You can govern every agent action with identity, authority, and formal policy — and still have no idea what is actually happening at scale. Observability is not logging. Auditability is not log retention. Without both, governance is a claim you cannot prove.
Agents accumulate context -- conversation history, tool results, user data, business logic. Ungoverned memory is a data governance nightmare. If you can't classify it, scope it, expire it, and delete it on demand, you don't have governance. You have a liability.
Policy that lives in the prompt is a suggestion. Policy in the control plane -- formal, versioned, evaluated on every action -- is governance. Agent Runtime Policy Enforcement is the difference.
Human oversight is not error handling. It is a designed operational mode -- and agents that cannot request, wait for, and incorporate human judgment are not governed.
An AI agent doesn't just execute a single action. It plans, acts, observes, and adapts — often across dozens of steps. If your runtime governance can only evaluate individual actions in isolation, you can't detect plan deviation, goal drift, or an agent that's quietly doing something it never said it would do.
You can define perfect identity, purpose, and authority for your agents — but if the agent itself decides whether to follow the rules, you don't have governance. You have suggestions. Governance for AI agents requires a deterministic control plane that sits outside the agent and cannot be bypassed.
An identified agent with a declared purpose still needs one more thing before it acts: authority. And authority for AI agents can't work the way it works for humans. It must be explicitly granted, scoped to the task at hand, and expire the moment the task is done.
IAM was built for humans. AI agents break every assumption in that model. This post introduces our new position paper defining the gap, the category, and the minimum requirements for Agent Runtime Governance.
Knowing who an agent is isn't enough. You need to know why it exists, what it's trying to achieve right now, and what specific action it's taking at this moment. Purpose, goal, and intent are three different things — and your governance depends on getting all three.
Every AI agent operating in your enterprise needs a stable, unique, cryptographically verifiable identity. No identity means no execution. Here's why service accounts and API keys aren't enough — and what agent identity actually requires.
Traditional governance was designed for a world where humans initiate every action. AI agents break that model. Watchlight AI's whitepaper defines 12 non-negotiable principles for Agent Runtime Governance — a new discipline for organizations deploying autonomous agents in production.
Traditional enforcement-only security models force AI agents to discover their boundaries through failures. A guidance layer that communicates constraints upfront transforms how agents operate—and how effectively we can govern them.
Identity Governance and Administration platforms were built for a world of human employees with predictable lifecycles. AI agents break every assumption they were designed around.
AI agents are transforming enterprise operations—but they introduce security challenges that traditional controls weren't designed to handle. Here's what security leaders need to understand about securing autonomous AI systems.
AI is only as good as its data. For organizations handling sensitive personal, infrastructure, and operational datasets, building secure data foundations isn't optional—it's the prerequisite for every AI initiative that follows.
Traditional authorization asks 'What can this identity access?' For AI agents, we need a different question: 'Why is this agent taking this action, and does it align with approved business objectives?' This paradigm shift is essential for securing autonomous AI.
The BodySnatcher vulnerability (CVE-2025-12420) exposed critical gaps in how we secure AI agents. Authentication and authorization aren't enough. Learn the security layers needed for agentic AI: delegation, context propagation, privileged access management, and semantic audit trails.
Your employees are already using ChatGPT, Copilot, and dozens of other AI tools, with or without your approval. Here's how to regain visibility and control in 90 days.
We use cookies to enhance your browsing experience, analyze site traffic, and personalize content. You can choose to accept all cookies or customize your preferences. Learn more