← All posts

Platform & Architecture

229 posts on platform & architecture.

Windsurf Audit Logs: Reading the Current Devin API Evidence

Windsurf audit logs now require a terminology check. Cognition's current documentation exposes enterprise audit events through Devin API v3, while legacy Windsurf Enterprise remains an authentication and billing qualifier. The v3 endpoint supports service-user RBAC and time filters. It also supports action filters and cursor pagination, with actor fields in the response. Investigators still need a separate request-policy record for routed AI HTTP calls.

ai-securityauditforensic-auditidentity-and-authorizationagentic-ai
Read post →

Zapier AI Security: Separate Workflow Controls from Model Routes

Zapier governs AI-enabled automation through publishing controls, app access, managed connections, model restrictions, audit records, AI Guardrails, and scoped MCP tools. Those controls operate inside Zapier. An independent policy gateway covers a narrower path: authenticated LLM inference requests that a supported integration explicitly routes through an external HTTP enforcement point.

ai-securityagentic-aillm-securitypolicy-enforcementidentity-and-authorization
Read post →

WRITER Security: Map Platform Controls to the Model Route

WRITER combines identity validation, permissions, approval flows, activity traces, model controls, and governed access to connected systems inside its enterprise AI platform. A security review should verify those native controls and then inventory every separate LLM route. Independent request authorization applies only where authenticated HTTP model traffic is explicitly routed through an enforcement gateway.

ai-securityllm-securityzero-trustpolicy-enforcementidentity-and-authorization
Read post →

Vertex AI Security: Five Native Controls and the Request Gap

Vertex AI security now sits under Google''s Gemini Enterprise Agent Platform name. Google documents separate controls for residency and customer-managed encryption keys, plus service perimeters and provider access visibility. It also documents retention. Their availability varies by model and operation. A routed AI request still needs caller-aware policy before inference when project IAM represents a shared application rather than the originating person or agent.

ai-securitycloud-securityidentity-and-authorizationzero-trustpolicy-enforcement
Read post →

Snowflake Cortex Security: A Preventive Hardening Review

Snowflake Cortex security requires explicit control over AI function privileges, model RBAC, inference geography, runtime guardrail scope, and Trust Center scanner coverage. A preventive review assigns owners and tests denied paths before production. External policy enforcement applies only to customer-controlled authenticated HTTP LLM traffic routed through a separate proxy.

ai-securitycloud-securityidentity-and-authorizationzero-trustpolicy-enforcement
Read post →

ServiceNow AI Security: Separate Guardian, Roles, and Request Policy

ServiceNow AI security combines in-platform AI Guardian checks, administrative roles, application configuration, and the Generative AI Controller connection to third-party models. A useful review tests each boundary separately, confirms the guardrail scope for every skill, and adds an external request-policy decision only where customer-controlled authenticated HTTP traffic can be routed through it.

ai-securityprompt-injectionidentity-and-authorizationpolicy-enforcementcloud-security
Read post →

Snowflake Cortex Audit Logs: Build the Evidence Chain Across Views

Snowflake Cortex audit evidence is distributed across function usage, agent usage, query history, and access history. Investigators need explicit joins, latency notes, historical-coverage qualifications, and a preserved correlation value. A separate policy-decision record adds request authorization only for customer-controlled authenticated HTTP LLM calls routed through an external gateway.

forensic-auditauditai-securityai-governancecompliance
Read post →

SAP Joule Security: Four Boundaries to Test Before Production

SAP Joule security starts with an OAuth user session, continues through application permissions, and relies on TLS plus configured SAP BTP destinations for network communication. Those controls answer different questions. A production review should test the identity on the request, the permissions applied in each connected application, the route used for outbound traffic, and the policy decision made for the prompt before it reaches an LLM.

ai-securityidentity-and-authorizationzero-trustpolicy-enforcementcloud-security
Read post →

SAP Joule Audit Logs: Three Records That Answer Different Questions

SAP Joule audit evidence is split across conversation logs, user-level exports, and security-event records for Joule Studio, classic edition. Conversation logs can preserve the initiating global user ID, timestamps, conversation ID, user input, Joule responses, and feedback. Configuration evidence lives in a different service, and storage depends on tenant choices made during onboarding.

ai-securityforensic-auditauditcomplianceai-governance
Read post →

Salesforce Einstein Audit Logs: Build a Decision Evidence Package

Salesforce says the Einstein Trust Layer securely logs prompts and outputs plus interactions and feedback data, with audit and feedback data stored in Data 360 for reporting and Flow alerts. That is a detailed platform record. A security review should test retrieval and access alongside retention, correlation, and the policy decision behind one interaction instead of treating log presence as proof of complete lineage.

ai-securityauditforensic-auditai-governanceidentity-and-authorization
Read post →

Replit Agent Audit Logs: The 30-Day Evidence Window

Replit Enterprise audit logs cover more than 50 event types, including Agent activity, and support portal exports plus SIEM streaming. Their default retention is 30 days, and a failed audit event never blocks the underlying action. Security teams need to distinguish this administrative activity record from an independent, per-decision record of HTTP model requests.

ai-securityauditforensic-auditagentic-aiidentity-and-authorization
Read post →

Perplexity Enterprise Security: SSO, Sharing Controls, SCIM, and the Request Gap

Perplexity Enterprise gives administrators controls for SSO, SCIM provisioning, public sharing, file downloads, repository changes, attachments, connectors, and incognito retention. These controls govern account access and workspace behavior. A security review should also identify which HTTP AI routes the enterprise controls, because a valid workspace member can still submit sensitive content unless a request-level policy evaluates the principal, payload, and destination before model access.

ai-securitycloud-securityidentity-and-authorizationzero-trustpolicy-enforcementdata-loss-prevention
Read post →