Field notes on AI-native security operations
Practical writing on governed autonomy, reversible response, evidence, and the engineering behind safe automation. Our first posts are on the way.
Authority to act: how to automate response without losing control
The authority ladder — observe, approval, pre-authorized, contractual-auto — and why business-critical assets should never auto-run.
Reversible by design: undoing a containment action safely
Terminal-state fail-safe attribution, and why a reversal must only ever touch the effect your own run created.
Redaction fences and the zero-config floor
Why an empty AI-egress policy must mean 'redact everything', never 'send everything' — and how we enforce it at the boundary.
Fleet-wide actions deserve a different gate
Breadth is its own risk axis. Why tenant-wide IOC blocks are always approval-first and human-run, independent of reversibility.
Evidence you can defend: chain of custody in practice
Hashing on capture, provenance metadata, legal hold vs retention, and building a regulator-ready export pack.
Running detection & response for many tenants at once
Per-tenant isolation, consolidated operations, and the guardrails that make multi-tenant SOC work safe.
Get the first posts
We'll email you when we publish. No newsletter spam — just the writing.
Notify me at contact@nirvet.com