Writing
AI agent security and IAM
Essays and practical guides on credential management, MCP security, and least privilege for teams running AI agents.
PCI DSS for AI Agents: Requirements 7, 8 & 10
PCI DSS does not exempt AI agents. A practical guide to scoping agent access, applying least privilege, managing credentials, and producing audit evidence for payment workflows.
AI Agent Incident Response: Compromised Credentials
A four-step playbook for when an AI agent credential is compromised — contain by revoking the agent's token (not the key), assess blast radius from the audit log, decide on notification, then harden before restoring access.
Prompt Injection and AI Agent Credential Theft
Prompt injection redirects an agent's actions using malicious content it reads. Credentials are the highest-value target. Scoped access limits what a successful injection can do — you can't sanitise your way out.
Replit Agent Credentials: Scope Agent Access
Replit Agent can read every Secret in your workspace — no per-session scoping, no audit trail. A scoped MCP connection gives each Agent session its own identity, audit log, and revocable access.
Azure Key Vault for AI Agents: Credential Scoping
Azure Key Vault stores credentials well, but managed identities don't distinguish between agents. A policy layer on top adds per-agent scope, approval gates, and action-level audit logs without touching your vault setup.
GDPR for AI Agents: Data Protection and Breach Response
GDPR applies to any AI agent that processes EU personal data. How data minimisation, Article 32 technical measures, and 72-hour breach notification map to per-agent credential design.
HIPAA for AI Agents: Technical Safeguards for PHI
HIPAA's Technical Safeguards apply to AI agents that access PHI. How audit controls, unique user identification, and transmission security map to per-agent identity and scoped credentials.
n8n AI Agent Credentials: Scope Workflow Access
n8n stores credentials centrally — every AI agent node gets the same full-access key. A scoped MCP connection gives each workflow its own identity, audit trail, and revocation.
API Credential Management: Storage, Scope, and Rotation
A systems guide to storing, scoping, rotating, and revoking API credentials, including the additional controls autonomous agents require.
Windsurf AI Agent Credentials: Scope Cascade Access
Windsurf's Cascade agent inherits full-access credentials by default. A scoped MCP connection narrows access to the task and adds an audit trail without changing how Windsurf works.
Secret Scanning for AI Codebases: Limits and Gaps
Secret scanning catches credentials in committed files and git history. AI agents add an exposure surface it wasn't built for: credentials in prompts and agent logs. Here's how to close the gap.
Service Accounts vs. Agent Tokens: What's the Difference
Service accounts were built for predictable infrastructure automation. AI agents aren't predictable in the same way — and the mismatch creates real security problems when teams reach for service accounts out of habit.
Scoping Salesforce API Access for AI Agents
Most teams give their AI agent a Salesforce API key and move on. That key can read every contact, update every opportunity, delete every record. Here's how to scope it correctly — per agent, from day one.
SOC 2 for AI Agent Teams: CC6, CC7, and CC9
SOC 2 doesn't have AI-agent-specific controls yet — but agents touching production data fall under CC6, CC7, and CC9. Here's how to map per-agent identity and audit logs to what auditors want.
What Is a Secrets Broker for AI Agents?
A secrets manager stores your credentials. A secrets broker controls which AI agent can retrieve them, under what conditions, and what it can do with them. Here's why the distinction matters.
MCP Config File Security: Don't Put API Keys in mcp.json
Credentials in .cursor/mcp.json or .claude/mcp.json are readable by every process on your machine, often committed to git, and shared across every agent with no audit trail. Here's the fix.
Zero Trust for AI Agents: Practical Principles
Zero trust means every credential request is verified, scoped, and logged — regardless of where the agent runs. Here's what the four core primitives look like in practice.
Doppler and Gazebo for AI Agent Secrets
Doppler handles secret storage and environment sync. Gazebo adds per-agent identity, approval gates, and action-level audit logs on top. Here's how to layer them without changing your existing Doppler setup.
Multi-Agent Credential Management: The Sharing Problem
In a multi-agent pipeline, every agent that shares a credential is a liability. Here's how credentials should actually flow through an agent chain.
How to Secure Claude Code's API Access
Claude Code is running in your repo with your API keys in scope. Most developers haven't thought about what that means for credential security.
HashiCorp Vault Agent and AI Credentials
Vault Agent handles Vault authentication for infrastructure services. AI agent credential management sits above it — per-agent identity, approval gates, and audit logs. How the two layers compose.
RBAC for AI Agents: Does Role-Based Access Control Work?
RBAC works for agents — but only if you drop the assumption that makes it useful for humans. Here's what breaks, what to use instead, and how HashiCorp Vault's policy model fits in.
AI Agent Credential Management: Provision, Audit, Revoke
An operating model for provisioning, scoping, monitoring, and revoking agent credentials across a real developer stack.
AI Agent Permissions: Service, Action, and Data Scope
A permission-design guide for AI agents: define service, action, and data boundaries before issuing any credential.
1Password and Gazebo for AI Agent Credentials
1Password for Claude handles web login credentials for browsing agents. Gazebo handles programmatic API credentials for coding agents. They solve different layers of the same problem and can run together.
AI Agent Security Checklist: Cursor, Replit, and Copilot
Six things to do before shipping AI agents to production — scoped credentials, approval gates, audit logs, and a revocation path that doesn't take down everything else.
OAuth 2.0 for AI Agents: Client Credentials Explained
OAuth 2.0's client credentials grant was designed for services, not autonomous AI agents. Here's what breaks at agent scale and what a better pattern looks like.
HashiCorp Vault and Gazebo for AI Agent Access
Vault handles infrastructure-grade secret storage. Gazebo adds per-agent identity, approval gates, and action-level audit logs on top — without changing how Vault is operated. How the two layers compose.
AWS Secrets Manager for AI Agents: IAM Roles vs Tokens
IAM roles are the right answer for AI agents running inside AWS. The moment your agent needs Stripe, GitHub, or Vercel too, you need scoped tokens instead. Here's where the boundary is and how to handle both sides of it.
Pasting API Keys into AI Agent Prompts: The Risk
It works — that's the problem. When you paste an API key into an agent's prompt, the key enters conversation logs, model context, and provider infrastructure you don't control. Here's where it actually goes.
API Key Rotation vs. Revocation for AI Agents
Rotation replaces a key everywhere it's used. Revocation cuts one agent's access without touching anything else. Why revocation is the right default for agents — and what you need in place.
Why Environment Variables Are Insecure for AI Agents
Environment variables feel like a secure way to pass credentials to AI agents. They're not. Here's why the process environment is a shared bus, not a secrets store — and what to do instead.
AI Agent Secrets Management: 6 Best Practices
A practical operating checklist for securing AI agent credentials: scoped identities, access logs, revocation, and keeping keys out of prompts.
IAM for AI Agents: Identity Architecture Explained
The identity architecture for autonomous agents: scoped profiles, brokered credentials, approval gates, and lifecycle controls beyond human IAM.
Secrets Management for AI Agents: Core Controls
A reference architecture for keeping agent credentials out of prompts: vault storage, brokered access, scoped policy, audit logs, and revocation.
Least Privilege for AI Agents: A Practical Guide
What least privilege means when the actor is an AI agent — and how to implement it without rebuilding your credential management from scratch.
How to Set Up a Cursor Agent with Scoped Service Access
Stop putting raw API keys in your .env. Connect Cursor to Gazebo and give your agent exactly the access it needs — nothing more.
MCP Security: What Developers Need to Know
MCP expands your agent's surface area. Every tool exposed over MCP is a potential credential leak or injection vector — unless you scope access at the agent level.
Why AI Agents Shouldn't Share API Keys
The blast radius problem with shared credentials — and how to apply least privilege to every AI agent you run.
Give your agents the access they need
Scoped credentials, audit logs, one-click revocation — for every AI tool you run.
Get started free