MONDAYMOVE

One concrete action.

Every Monday.

COMING UP

32

identity

Map one agent's authority.

The model is rarely the risk. The risk is the connections — what data flows in, what tools it can call, what authority it operates under. If you can't answer these three questions for one agent, you definitely can't answer them at scale.

33

governance

Write the one-page security narrative for the board.

The CISO role got pulled into the boardroom at exactly the moment security became an engineering problem again. The leaders who keep both audiences are the ones who can speak in plain English about what the program actually does. That skill is built one draft at a time.

34

forward moves

Treat one agent as a first-class principal.

Agents are going to be the dominant actors in your environment within 24 months. The programs that started treating them as principals — with identity, authorization, and audit — are the ones that won't have to retrofit it under pressure later. Start now, with one.

35

access

Move one access decision out of the endpoint.

Zero trust became a marketing tier because most "deployments" left the policy on the endpoint. Real zero trust is access decisions expressed as code, in a place you can audit. The pattern that worked for SASE is the same pattern that works for AI gateways.

36

data

Read one week of DLP alerts you've been ignoring.

The new exfiltration path is a chat window. DLP rules built for email and endpoints don't see prompts. The pattern in the alerts is more useful than any single ticket — it tells you what behavior your existing tools were never designed to govern.

ALL MOVES

Every move, in order.