Learn
Explainers
Plain-English explainers on agent security and spend, one question per page. Each one defines the term, shows what breaks without it, cites the incident or number behind the claim, and ends with the questions worth putting to a vendor. No background assumed.
What is an MCP gateway?
The checkpoint between your agents and the tools they call, and what the current spec changed about it.
What is agent identity?
Why each agent needs an identity of its own, and what breaks when a handful of them share one service account.
Does RBAC work for AI agents?
Where role-based access control strains once the thing holding the role is software that acts in a loop.
What is an LLM gateway?
Where AI spend gets attributed, capped, and routed, and why the bill gets away from teams without one.
Shadow AI policy: what it should cover
The AI tooling nobody approved, and a checklist for the policy that brings it back into the open.
The OWASP Agent Control Standard
OWASP's open standard for controlling agents at runtime: what v0.1.0 defines, what is missing, and what to do now.
AIVSS, explained
The scoring system that extends CVSS for agents, how the numbers are built, and what to do with a score.
These pages come out of the weekly briefing. The Permission Layer is a free weekly read on agent security and spend, written for the people who sign off on deployments. Get the next issue.