FIELD NOTES
Research for
working Defenders.
Short, technical, and grounded in operational reality.
The first 60 minutes of an AI security incident
A commander-and-operator timeline for stopping autonomous activity, revoking unsafe authority, preserving evidence, and bounding downstream impact.
Label before retrieval: securing data before AI touches it
A control architecture for preserving ownership, classification, authorization, retention, and tenant boundaries through RAG and agent memory.
Guardrails that can say no: OPA policy enforcement for AI agents
A practical architecture for independent policy decisions at agent tool boundaries, with approval binding, failure behavior, and audit requirements.
Incident response for autonomous AI agents
A practical framework for scoping identity, memory, tools, and delegated actions when an AI workflow goes wrong.
What to log before your first AI incident
The minimum viable telemetry model for prompts, retrieval, policy decisions, tool execution, and human approvals.
Ransomware containment under pressure
A technical decision framework for isolation, control-plane protection, evidence preservation, and staged recovery.