The Arrakis Blog

Practical writing on AI agent security, permission boundaries, audit practices, and governance for enterprise teams.

Abstract map visualization showing attack surface vectors across an AI agent network

Priya Nair

Mapping the Attack Surface of Autonomous AI Agents

AI agents introduce a new category of attack surface: not the model itself, but the tools it can call and the data it can reach.

Read
Abstract flowing data stream visualization showing multi-agent workflow monitoring

Dmitri Volkov

Real-Time Monitoring Patterns for Multi-Agent Workflows

When agents hand off context to other agents, monitoring each one in isolation misses the cross-agent patterns that matter most.

Read
Abstract audit trail visualization showing chronological sequence of events

Marcus Webb

How to Audit What Your AI Agents Actually Did

Your agents ran overnight and processed 4,000 documents. Now your compliance team asks what they accessed. What can you actually tell them?

Read
Abstract visualization contrasting two different identity and access model structures

Priya Nair

Agent Identity vs. Human Identity: Different Access Models

Human identities are durable and person-scoped. AI agent identities are ephemeral and task-scoped. Your access model needs to handle both.

Read
Abstract visualization of expanding permission boundaries with network scope creep

Marcus Webb

Five Signs Your AI Agents Have Scope Creep

Scope creep in AI agents is rarely intentional. It accumulates through convenience decisions that each look reasonable in isolation.

Read
Abstract structured framework visualization with layered governance architecture

Priya Nair

Building a Governance Framework for Autonomous AI Systems

Governance frameworks for AI agents do not need to be heavyweight. A minimal, enforceable framework beats a comprehensive one that nobody uses.

Read
Abstract visualization of incident investigation trace through agent session paths

Dmitri Volkov

The Incident Response Problem When Your Agent Did It

When a human triggers an incident, you know who to call. When an AI agent triggers one, the path back to cause is murkier than you expect.

Read
Abstract visualization of privileged function calls flowing through enterprise system layers

Marcus Webb

LLM Tool Calls and Enterprise Security Monitoring

Tool calls are where LLM agents interact with the real world. They are also the right abstraction layer for security monitoring.

Read
Abstract zero-trust network visualization with verification checkpoints on every connection

Priya Nair

Zero-Trust Principles Applied to AI Agent Networks

Zero trust assumes breach and verifies every request. The principle applies cleanly to AI agent networks if you treat each agent as an untrusted identity.

Read
Abstract decision tree branching visualization with decision capture nodes

Dmitri Volkov

Why Logging Agent Decisions Matters More Than Actions

Most agent monitoring logs what the agent did. The more valuable log is why the agent did it -- the decision chain that led to the action.

Read
Abstract bridge visualization connecting traditional compliance structures with modern AI systems

Marcus Webb

Getting Compliance Teams to Take AI Agents Seriously

Risk and compliance teams are used to auditing human processes. Getting them aligned on AI agent risk requires a different conversation.

Read

New articles in your inbox.

We publish a few times per month. No marketing emails, only posts when we publish something.