FIELD NOTES

Research for
working Defenders.

Short, technical, and grounded in operational reality.

28 AUG 2026
AI SECURITY

The first 60 minutes of an AI security incident

A commander-and-operator timeline for stopping autonomous activity, revoking unsafe authority, preserving evidence, and bounding downstream impact.

11 MIN READ
14 AUG 2026
AI SECURITY

Label before retrieval: securing data before AI touches it

A control architecture for preserving ownership, classification, authorization, retention, and tenant boundaries through RAG and agent memory.

12 MIN READ
31 JUL 2026
AI SECURITY

Guardrails that can say no: OPA policy enforcement for AI agents

A practical architecture for independent policy decisions at agent tool boundaries, with approval binding, failure behavior, and audit requirements.

9 MIN READ
17 JUL 2026
AI SECURITY

Incident response for autonomous AI agents

A practical framework for scoping identity, memory, tools, and delegated actions when an AI workflow goes wrong.

8 MIN READ
03 JUL 2026
DETECTION

What to log before your first AI incident

The minimum viable telemetry model for prompts, retrieval, policy decisions, tool execution, and human approvals.

6 MIN READ
19 JUN 2026
PLAYBOOK

Ransomware containment under pressure

A technical decision framework for isolation, control-plane protection, evidence preservation, and staged recovery.

12 MIN READ