Watchlight AI
Back to Home
Blog

Watchlight Insights

Writing on AI agent security, agent identity, delegated authorization, MCP, and Agent Runtime Governance for the enterprise.

Validated content only. Every post is backed by working code we build and run across the full stack, from the agents to the interface to the backend. If it is here, we have implemented it.

Filter by topic

Tap a star to filter. Brighter stars cover more posts. Connections show topics that appear together in the same post.

Agent Runtime GovernanceAgentic AIAI Agent SecurityAI GovernanceAI SecurityAWS BedrockCISOClaude Agent SDKEnterprise AIGoogle ADKIAMIdentityLangGraphMCPMicrosoft Agent FrameworkOpenClawPolicy Enforcementwl-proxy

Subscribe to Watchlight Insights

Get new writing on Agent Runtime Governance, AI agent security, agent identity, and delegated authorization, delivered when we publish. No noise, just the new posts.

Unsubscribe anytime. We never share your email.

August 26, 20267 min readAldo Pietropaolo

A Tool-Call Check Is a Feature. Governing Delegated Authority Is an Architecture.

Runtime authorization went mainstream this year. Identity, PAM, cloud, MCP, and agent-security vendors all now check the action. That convergence validates the category we defined, and it moves the real question. Identity establishes who the agent is and what it can access. The harder problem is whether, how, and under whose delegated authority the agent may act, enforced where actions execute, with the lineage of what follows preserved. A single check is a feature. That is an architecture.

Read more
August 25, 20266 min readAldo Pietropaolo

Govern the Moment an AI Agent Turns Intent Into Action

An AI agent run is a long stream of decisions, but in each one there is exactly one point where governance can change what happens: the moment the agent turns intent into action. Before it, the agent has only formed a plan. After it, the action has already reached your systems. Identity, guardrails, and detection all sit on the wrong side of that moment. Governing it is the job of Agent Runtime Governance.

Read more
August 25, 20266 min readAldo Pietropaolo

Introducing Agentic IAM Architecture: Identity and Access, Designed for AI Agents

Every IAM team is now getting the same question from the business: how do we handle identity and access for our AI agents? The honest answer is that the identity architecture you spent years building was designed for humans and applications, and agents are neither. Agentic IAM Architecture is our flagship engagement to design enterprise identity and access for AI agents, autonomous workflows, machine identities, and human-to-agent delegation.

Read more
August 24, 20266 min readAldo Pietropaolo

AI Agent Delegation Is Getting Standardized. Enforcement Is the Part That Isn't.

The identity industry is quietly standardizing how AI agents carry authority delegated from a human. It is real progress, and if you run agents it is coming to your stack. But every one of these standards describes the authority an agent may hold. None of them, on their own, enforce that the agent stayed inside it when it acted, or prove that it did. That is Agent Runtime Governance, and it is the part they leave to you.

Read more
August 24, 20266 min readAldo Pietropaolo

Authenticating an Agent Is Not Authorizing It

Give an AI agent an identity and a role and it is easy to feel like you have governed it. You have authenticated it. You have not decided what it may actually do. Identity establishes who the agent is. Something else has to determine what authority that agent may exercise for the task in front of it, and for agents that authority is not fixed.

Read more
August 21, 20267 min readAldo Pietropaolo

An Agent Deleted It. Can You Prove Why It Was Allowed?

An autonomous agent deletes something it should not have. Within the hour you are asked two questions: why was it allowed to do that, and can you prove it. Application logs answer neither. They show that the delete happened. They do not show the authority that permitted it, and they can be edited. US regulators, from the SEC's incident-disclosure rules to the NIST AI RMF, are already moving toward requiring the answer, and you cannot reconstruct it after the fact. You either recorded it at runtime or you did not.

Read more
August 21, 20268 min readAldo Pietropaolo

Identity Says Who. Agent Runtime Governance Says Whether.

Enterprise identity has started treating AI agents as first-class identities with delegated authority. Okta and Ping both shipped for it in the last year. That is the right move, and it is only half of the problem. Issuing a scoped token decides what an agent may do. Something still has to decide, at the moment of every action and across the whole delegation chain, whether it actually did, and then prove it. That layer is Agent Runtime Governance.

Read more
August 17, 20266 min readAldo Pietropaolo

The 12 Principles of Agent Runtime Governance, Implemented

A framework only matters if something implements it. We authored the 12 Non-Negotiable Principles for Agent Runtime Governance, and we build the control plane that delivers them. Here is the direct mapping from each principle to the Watchlight AI Beacon capability that implements it, including the one principle still on the roadmap, because a control matrix is only useful if it is honest.

Read more
August 17, 20267 min readAldo Pietropaolo

Agent Runtime Governance Is Not Agent Security

Watchlight AI Beacon is easy to file under AI security or agent security, another tool that monitors AI agent behavior and flags anything that looks wrong. It belongs somewhere else entirely. Agent Runtime Governance is not a security product. It is a different category, closer to identity and PKI than to any scanner, and that difference is the reason it becomes critical infrastructure rather than another line in the security budget.

Read more
August 17, 20267 min readAldo Pietropaolo

The Agent Runtime Governance Maturity Model

The 12 Principles tell you what to build. The maturity model tells you where you are and what to do next. Five levels, from agents deployed with no governance at all to fully governed multi-agent operations. Find the row that matches your reality today, see exactly which principles move you up, and get a clear path to mature.

Read more
August 14, 20269 min readAldo Pietropaolo

Agent Runtime Governance Is Becoming Critical Infrastructure

The enterprise is being rebuilt on AI compute, and that compute does not just answer questions. It acts. When autonomous action becomes the substrate of how work gets done, the layer that governs those actions at runtime stops being a feature and becomes infrastructure, the way identity and PKI did before it. Here is the case that Agent Runtime Governance is on that trajectory, and what it means for enterprises standing up agents now.

Read more
August 12, 20267 min readAldo Pietropaolo

You Can't Govern What You Can't Prove: Agent Runtime Attestation

When an AI agent does something it should not have, the first question is what exactly happened and who authorized it. Application logs cannot answer that. Agent Runtime Attestation gives every governed agent action a chain of custody: a signed, tamper-evident record of the authority behind it and what it did, so you can prove what your agents have done to a security team, a compliance officer, and an auditor.

Read more
August 4, 20266 min readAldo Pietropaolo

Announcing the Watchlight AI Beacon Plugin for LangChain Deep Agents: Governing the Long-Horizon Loop

Watchlight AI Beacon now governs LangChain deep agents. Every tool call, filesystem operation, and sub-agent action is authorized against policy before it executes, before it ever places a request on the wire, each sub-agent under its own explicit, narrowed authority so delegation never becomes privilege escalation. A drop-in integration, no changes to your tool code. Request early access through the Founding Design Partner program.

Read more
August 3, 20269 min readAldo Pietropaolo

Securing the Agentic Loop: Governing Autonomous AI at Runtime

Strip away the branding and every long running autonomous AI agent is the same thing: a loop that reasons, acts, sees the result, and decides again, on its own and at machine speed. That loop is what makes agents valuable and what makes them risky, and it is the one thing traditional security was never built to govern. Here is why the agentic loop is the real unit of risk, and what it takes to govern it at runtime.

Read more
July 30, 20269 min readAldo Pietropaolo

Zero Standing Privileges for AI Agents

Enterprises already believe in zero standing privileges for people and service accounts. For AI agents, most have quietly abandoned it: agents run with broad, always-on credentials that make every compromise catastrophic. Here is why standing access is more dangerous for agents than for any prior identity, why the tools that deliver zero standing privileges for humans do not translate, and how Agent Runtime Governance delivers the outcome at the layer where agents actually act.

Read more
June 30, 20268 min readAldo Pietropaolo

The Supervisor LLM Trap: Verifying AI Agent Intent at Runtime

The instinct to verify agent intent with a supervisor LLM that reads the agent's chain-of-thought is a trap. A model that judges another model inherits its non-determinism, its susceptibility to prompt injection, and its persuasiveness. The durable approach authorizes the action against deterministic policy, treats declared intent as governed evidence with provenance, and measures alignment with statistical drift rather than a second model.

Read more
June 24, 20265 min readAldo Pietropaolo

Announcing the AI Agent Identity and Access Workshop

Watchlight AI adds a fifth advisory workshop: AI Agent Identity and Access. A hands-on engagement to design and stand up verifiable agent identity, scoped and time-bound access, and governed delegation, all enforced at runtime under Agent Runtime Governance. Your team leaves with a working reference implementation and a rollout plan.

Read more
June 12, 20268 min readAldo Pietropaolo

Announcing the Watchlight AI Beacon Plugin for the Claude Agent SDK: Governance for Agents That Spawn Agents

Watchlight AI Beacon now governs agents built on Anthropic's Claude Agent SDK. A one-line integration authorizes every tool call against policy, including the calls made by subagents, each under its own scoped authority so delegation never becomes privilege escalation. High-risk actions can be held for human approval, outbound traffic routes through a network proxy with no change to agent code, and the full delegation tree lands in a forensic, tamper-evident record. Two enforcement boundaries, one governance plane.

Read more
June 4, 20268 min readAldo Pietropaolo

Announcing the Watchlight AI Beacon Plugin for OpenClaw: Two Enforcement Boundaries for Agentic Runtimes

Watchlight AI Beacon now governs agents running on OpenClaw. A drop-in plugin authorizes every tool call against current policy, gates high-risk actions for human approval, and surfaces agents that probe the gate, while a network-layer proxy enforces the same policy at the wire. Two independent enforcement boundaries, one governance plane, no agent code changes.

Read more
May 24, 20265 min readAldo Pietropaolo

Announcing New Watchlight AI Services: Executive Briefing, Implementation, and Advisory Retainer

Three new Watchlight AI services for Agent Runtime Governance: an Executive Briefing for boards and senior leadership, an Implementation engagement that brings a governance architecture into production, and an Advisory Retainer that puts an ARG architect on call. Plus a new free 30-minute consultation that opens the conversation for any enterprise team.

Read more
May 21, 20267 min readAldo Pietropaolo

Not All Agents Are Equally Dangerous: Authority Blast Radius in Watchlight AI Beacon

Every CISO running AI agents in production eventually asks the same question: how worried should I be about this agent? Authority Blast Radius is the answer Watchlight AI Beacon gives, in a form a security team, a compliance officer, and an operator can all use.

Read more
May 15, 20269 min readAldo Pietropaolo

Announcing the Watchlight AI Beacon Plugin Suite: Runtime Governance Across Agent Frameworks

Watchlight AI Beacon ships runtime governance plugins for the agent frameworks enterprises are actually deploying: LangGraph, Google ADK, AWS Bedrock Agents, and MCP servers, plus a contract for custom in-house agents. One governance plane, the same policy and audit trail across every framework.

Read more
May 13, 202614 min readAldo Pietropaolo

AI Security Is Not Enough: The Case for Agent Runtime Governance

The existing AI security ecosystem inspects, classifies, and detects. It is necessary and valuable. It does not answer the question autonomous AI now demands: what is this system actually permitted to do, right now, given its intent, authority, and delegation chain? That answer requires a new control plane.

Read more
May 12, 20268 min readAldo Pietropaolo

Authorization Before Action: Plan, Act, Observe in AI Agent Runtime Governance

Every action an AI agent takes proceeds through three stages: Plan, Act, Observe. Governance attached only at the network gateway is governance after the decision. Authorization belongs at the plan stage, where it costs nothing to deny.

Read more
April 28, 20265 min readAldo Pietropaolo

How to Assess Your Organization's AI Agent Governance Readiness in 5 Minutes

Most organizations cannot answer basic questions about how their AI agents are governed. We built a free assessment tool that gives you a clear picture in 5 minutes: your maturity level, your specific gaps, and what to do next.

Read more
April 23, 20267 min readAldo Pietropaolo

Why Semantic Governance Is Not Enough for AI Agents

Semantic governance interprets what an agent means to do. Agent Runtime Governance controls what an agent is allowed to do. Interpretation is not enforcement. Enterprises need both.

Read more
April 20, 20268 min readAldo Pietropaolo

Verifiable Credentials and Agent Runtime Governance: Cryptographic Trust for Autonomous Systems

How does a peer agent, a downstream system, or an auditor verify that an AI agent is who it claims to be, has the authority it claims to have, and meets the governance requirements it claims to meet? Verifiable Credentials offer a cryptographic answer that works across trust boundaries.

Read more
April 16, 20268 min readAldo Pietropaolo

The 5 Decisions IAM Cannot Make (But AI Agents Force You To)

Traditional IAM answers who an agent is and what it can generally access. AI agents introduce a different class of question: should this agent perform this specific action, right now, in this context, for this goal, under this delegation chain? That is not an identity question. It is a runtime governance question.

Read more
April 16, 20268 min readAldo Pietropaolo

MCP Isn't Broken. It's Missing a Control Plane.

The recent attention on MCP-related risks is being framed as a bug or a developer mistake. The deeper lesson is architectural. AI agents are being given connectivity and capability without a runtime layer that decides whether a specific action should proceed.

Read more
April 15, 20267 min readAldo Pietropaolo

You Can't Secure What You Don't Govern: The Case for Agent Runtime Governance

A growing wave of solutions can detect when an AI agent does something wrong. But detection happens after execution has begun. The question enterprises should be asking is not 'what went wrong?' but 'was this action ever authorized in the first place?'

Read more
April 14, 202610 min readAldo Pietropaolo

Principle 12: Multi-Agent Coordination

The final principle. When agents work together, governance complexity does not just increase — it changes shape. Single-agent governance is necessary. It is not sufficient. Principle 12 completes the framework.

Read more
April 8, 20267 min readAldo Pietropaolo

Announcing the Agent Execution Graph: See Every AI Agent Action as It Happens

AI agents act at machine speed across systems, but security teams have no real-time picture of what is actually happening. The Agent Execution Graph changes that. It is a live, queryable graph of every agent action, every policy decision, and every delegation hop, materialized as events flow.

Read more
April 8, 20268 min readAldo Pietropaolo

Endpoint Detection: Why EDR Alone Cannot Govern AI Agents at Runtime

Endpoint Detection and Response answers what happened on a system. Agent Runtime Governance answers what should be allowed to happen. Both are necessary. Neither can substitute for the other.

Read more
April 4, 20268 min readAldo Pietropaolo

Execution Lineage: Tracing How Every AI Agent Action Happened

Your AI agents are making thousands of decisions per hour. When your CISO asks 'how did that agent get access to our CRM?', can you answer in under 60 seconds? Most platforms tell you what happened. Execution Lineage tells you how.

Read more
April 3, 20265 min readAldo Pietropaolo

Announcing the Watchlight AI Founding Design Partner Program

Today we are opening the Founding Design Partner Program: a small cohort of organizations collaborating with us to define how autonomous AI agents should be governed at runtime. This is a milestone we have been building toward for a long time.

Read more
April 1, 202610 min readAldo Pietropaolo

Principle 11: Tool and Service Governance

An agent with ungoverned tool access is an employee with the master key to every system in the building and no record of which doors they opened. Tools are how agents act on the world. If you do not govern tool access, you do not govern agent behavior.

Read more
March 24, 202610 min readAldo Pietropaolo

Principle 10: Safe Failure Semantics

Agents will fail. The question is not whether, but how. Traditional software fails in predictable ways. Agents fail mid-plan, mid-delegation, mid-action, with partial state scattered across systems and other agents still operating on assumptions that are no longer valid. If your failure model does not account for this, you do not have one.

Read more
March 23, 202610 min readAldo Pietropaolo

Principle 9: Observability and Auditability

You can govern every agent action with identity, authority, and formal policy — and still have no idea what is actually happening at scale. Observability is not logging. Auditability is not log retention. Without both, governance is a claim you cannot prove.

Read more
March 18, 202610 min readAldo Pietropaolo

Principle 8: Governed Memory and State

Agents accumulate context -- conversation history, tool results, user data, business logic. Ungoverned memory is a data governance nightmare. If you can't classify it, scope it, expire it, and delete it on demand, you don't have governance. You have a liability.

Read more
March 11, 202610 min readAldo Pietropaolo

Principle 7: Agent Runtime Policy Enforcement

Policy that lives in the prompt is a suggestion. Policy in the control plane -- formal, versioned, evaluated on every action -- is governance. Agent Runtime Policy Enforcement is the difference.

Read more
March 9, 202610 min readAldo Pietropaolo

Principle 6: Human-in-the-Loop as First-Class Capability

Human oversight is not error handling. It is a designed operational mode -- and agents that cannot request, wait for, and incorporate human judgment are not governed.

Read more
March 4, 202610 min readAldo Pietropaolo

Principle 5: The Plan-Act-Observe Lifecycle

An AI agent doesn't just execute a single action. It plans, acts, observes, and adapts — often across dozens of steps. If your runtime governance can only evaluate individual actions in isolation, you can't detect plan deviation, goal drift, or an agent that's quietly doing something it never said it would do.

Read more
February 27, 202611 min readAldo Pietropaolo

Principle 4: Deterministic Control Planes

You can define perfect identity, purpose, and authority for your agents — but if the agent itself decides whether to follow the rules, you don't have governance. You have suggestions. Governance for AI agents requires a deterministic control plane that sits outside the agent and cannot be bypassed.

Read more
February 24, 20269 min readAldo Pietropaolo

Principle 3: Authority Is Explicit, Scoped, and Time-Bound

An identified agent with a declared purpose still needs one more thing before it acts: authority. And authority for AI agents can't work the way it works for humans. It must be explicitly granted, scoped to the task at hand, and expire the moment the task is done.

Read more
February 19, 20266 min readAldo Pietropaolo

Why Agent Runtime Governance Is the Missing Layer in IAM

IAM was built for humans. AI agents break every assumption in that model. This post introduces our new position paper defining the gap, the category, and the minimum requirements for Agent Runtime Governance.

Read more
February 16, 20269 min readAldo Pietropaolo

Principle 2: Explicit Purpose, Goals, and Intent

Knowing who an agent is isn't enough. You need to know why it exists, what it's trying to achieve right now, and what specific action it's taking at this moment. Purpose, goal, and intent are three different things — and your governance depends on getting all three.

Read more
February 12, 20268 min readAldo Pietropaolo

Principle 1: Agent Identity Is Mandatory

Every AI agent operating in your enterprise needs a stable, unique, cryptographically verifiable identity. No identity means no execution. Here's why service accounts and API keys aren't enough — and what agent identity actually requires.

Read more
February 10, 20265 min readAldo Pietropaolo

12 Non-Negotiable Principles for Agent Runtime Governance

Traditional governance was designed for a world where humans initiate every action. AI agents break that model. Watchlight AI's whitepaper defines 12 non-negotiable principles for Agent Runtime Governance — a new discipline for organizations deploying autonomous agents in production.

Read more
February 4, 202610 min readAldo Pietropaolo

Agent-Native Constraints: Why AI Agents Need a Guidance Layer

Traditional enforcement-only security models force AI agents to discover their boundaries through failures. A guidance layer that communicates constraints upfront transforms how agents operate—and how effectively we can govern them.

Read more
February 3, 20268 min readAldo Pietropaolo

Why Legacy IGA Fails for AI Agents

Identity Governance and Administration platforms were built for a world of human employees with predictable lifecycles. AI agents break every assumption they were designed around.

Read more
January 26, 20269 min readAldo Pietropaolo

Agentic AI Security: What Enterprises Need to Know

AI agents are transforming enterprise operations—but they introduce security challenges that traditional controls weren't designed to handle. Here's what security leaders need to understand about securing autonomous AI systems.

Read more
January 21, 202610 min readAldo Pietropaolo

Secure Data Foundations: The Prerequisite for AI Success

AI is only as good as its data. For organizations handling sensitive personal, infrastructure, and operational datasets, building secure data foundations isn't optional—it's the prerequisite for every AI initiative that follows.

Read more
January 20, 20268 min readAldo Pietropaolo

Why AI Agents Need Intent-Based Authorization

Traditional authorization asks 'What can this identity access?' For AI agents, we need a different question: 'Why is this agent taking this action, and does it align with approved business objectives?' This paradigm shift is essential for securing autonomous AI.

Read more
January 15, 202612 min readAldo Pietropaolo

AI Agent Security: Why Authentication Alone Isn't Enough

The BodySnatcher vulnerability (CVE-2025-12420) exposed critical gaps in how we secure AI agents. Authentication and authorization aren't enough. Learn the security layers needed for agentic AI: delegation, context propagation, privileged access management, and semantic audit trails.

Read more

We value your privacy

We use cookies to enhance your browsing experience, analyze site traffic, and personalize content. You can choose to accept all cookies or customize your preferences. Learn more