Clarion Street
Home Posts Github Unifi

Governance

  • Aug 29, 2026 Certifying the Loop: Access Control and Audit in Agentic Workflows

    An agent is a loop whose branches are decided at runtime by the model, which a fixed control catalog like CMMC cannot enumerate. Access Control and Audit and Accountability break first. The emerging fix moves authorization outside the loop and makes the execution trace the audit artifact.

  • Aug 29, 2026 Beyond the Prompt: The Audit Trail Is the New Security Boundary

    Three years of LLM security were spent on the input. The next boundary is proving what an agent did after the prompt left the model, which means turning execution traces into audit trails that are complete, tamper-evident, and portable across vendors.

  • Aug 28, 2026 Auditing the Unpredictable: The Compliance Gap in Agentic Infrastructure

    Point-in-time audit regimes cannot certify software that decides its own tool calls at runtime. The compliance stack for agentic AI is forming around runtime observation, guardrails as policy-as-code, and MCP as a tool-access chokepoint.

© 2026 Clarion Street