← All posts

Platform & Architecture

229 posts on platform & architecture.

Oracle AI Security: IAM, API Keys, Guardrails, and the Request Boundary

OCI Generative AI separates resource authorization, model credentials, and content guardrails. IAM policies decide which groups can manage or use service resources. Generative AI API keys authenticate calls to hosted models, while guardrails provide content moderation and detection of prompt injection or PII. A production review should preserve those layers and add identity-bound policy to each HTTP inference request.

ai-securitycloud-securityidentity-and-authorizationpolicy-enforcementzero-trustllm-security
Read post →

SAP AI Core Security: Tenant Boundaries Stop Short of Request Authorization

SAP AI Core uses XSUAA service-key credentials, tenant-aware resource groups, namespace isolation, and sandboxed workloads. Those controls establish who can reach the service and where runtime objects belong. An AI request still needs a content-aware authorization decision that binds the originating identity, prompt classification, model route, and policy version before inference.

ai-securitycloud-securityidentity-and-authorizationzero-trustpolicy-enforcement
Read post →

Replit Agent Security: Four Control Boundaries to Test

Replit assigns Agent harness security to its platform while customers own generated-code review, prompt hygiene, sensitive-action approval, and third-party Skill or MCP vetting. Agent security scans add source and static analysis, but Replit calls them incomplete. A credible review tests the Agent, generated application, deployment, and routed model-request boundaries separately.

ai-securityagentic-aidevsecopszero-trustpolicy-enforcement
Read post →

Perplexity Enterprise Audit Logs: Rich Query Evidence Still Needs Policy Context

Perplexity Enterprise Audit Logs stream query, answer, file, login, settings, and Comet agent events to a customer webhook in real time. The documented schema includes a UUID, timestamp, event type, user email, IP address, user agent, session ID, and event metadata. This gives investigators unusually rich activity evidence. A policy review should still test delivery failure handling, retention, content exposure, and the absence of an enterprise authorization decision in the event schema.

ai-securityauditforensic-auditcomplianceagentic-aiidentity-and-authorization
Read post →

OpenAI Agent Builder Audit Logs: The Admin API Records the Org, Not the Agent Run

OpenAI exposes an Audit Logs API that lists recent user actions and configuration changes for an organization, reached with an admin credential carrying the Audit Logs read scope. The documented surface is administrative: credential creation, user and role changes, login attempts, project modifications. Agent Builder workflows execute inside that organization, and the runs themselves sit outside the event list the Admin API publishes.

ai-securityaudit-logsagentic-aicomplianceidentity-and-authorization
Read post →

NVIDIA NIM Security: What an NGC API Key Authenticates and What It Does Not

An NGC API credential pulls NIM container images from nvcr.io and authenticates calls to NVIDIA-hosted endpoints. It works at the registry and account level rather than as a per-request authorization mechanism. Once a NIM container is running in your own cluster, access control belongs entirely to the deployment platform, and platforms including NVIDIA Run:ai default to public access with no authentication on the inference endpoint.

ai-securityself-hosted-llmidentity-and-authorizationzero-trustarchitecture
Read post →

NVIDIA NIM Audit Logs: Why a Successful Inference Leaves No Record by Default

NVIDIA NIM writes structured logs to stderr, exposes vLLM Prometheus metrics unchanged at /v1/metrics, and forwards X-Request-Id and W3C traceparent headers for distributed tracing. The default log level is WARNING, which means a successful inference produces no log line at all. Nothing in the documented telemetry records a caller identity, an authorization outcome, or the content of a request.

ai-securityaudit-logsself-hosted-llmobservabilityarchitecture
Read post →

Notion AI Security: What Page Permissions, the Audit Log, and Workspace Controls Cover

Notion AI answers from the pages a user can already open, so its exposure is the existing permission graph rather than a new one. Enterprise workspaces add an audit log with 365-day retention across eight event categories, CSV export, and real-time SIEM streaming by webhook. Notion states it does not use customer data to train models. What none of those controls do is evaluate a specific prompt against a policy before it reaches a model.

ai-securityaudit-logsidentity-and-authorizationshadow-aicompliance
Read post →

n8n Security: What Project RBAC, External Secret Stores, and Log Streaming Cover

n8n Enterprise groups workflows into projects, assigns access by project role, pulls credentials from external secret stores, and streams events to syslog, a webhook, or Sentry. Those controls decide who may edit a workflow and where its secrets come from. When an AI Agent node calls a model, the model receives the workflow credential, so the human who triggered the run leaves no identity on the request.

ai-securityidentity-and-authorizationagentic-aiaudit-logsarchitecture
Read post →

Mistral Security: What Workspaces, SCIM, and Admin-Role API Keys Cover

Mistral organizes access around an organization containing workspaces, with roles, groups, SCIM provisioning, and SAML single sign-on managed from the Admin Panel. Workspaces carry their own usage limits and rate tiers, and Admin API calls require a key held by an Admin-role user. All of that governs who joins the account and which workspace they land in. The inference request itself authenticates with a bearer key that names no human.

ai-securityidentity-and-authorizationllm-securityzero-trustarchitecture
Read post →

Mistral Audit Logs Record Who Changed the Account, Not Who Called the Model

Mistral ships audit logs on Enterprise plans, enabled by default for every workspace with no setup required. Each entry carries a timestamp, an actor that can be a user or an API credential, an event, a target resource, and metadata. The documented event list covers authentication, credential management, workspace changes, user management, and settings. Inference requests are absent from that list, and log export is not supported.

ai-securityaudit-logscompliancellm-securityidentity-and-authorization
Read post →

Microsoft 365 Copilot Security: What Entra ID, Sensitivity Labels, and XPIA Classifiers Cover

Microsoft 365 Copilot inherits the tenant permission model rather than introducing a new one. The Semantic Index honors the user identity-based access boundary, Purview Information Protection encryption and usage rights are respected, and XPIA classifiers screen for cross-prompt injection before model execution. Each of those controls answers a question about the data. None of them evaluates whether a permitted user should be making this particular request.

ai-securitymicrosoft-365identity-and-authorizationprompt-injectionzero-trust
Read post →