Disabled Is Not Removed
Two Rovo disclosures show why agent governance cannot stop at an admin-console toggle. Security teams need to verify runtime capabilities, data reach, and egress independently.
notebook / tag
4 entries with this tag.
Two Rovo disclosures show why agent governance cannot stop at an admin-console toggle. Security teams need to verify runtime capabilities, data reach, and egress independently.
Project Perception puts red, blue, and green agents into a closed security loop. Autonomous remediation needs separate identities, signed evidence, deterministic policy, rollback, and independent validation.
I am using the Foundry Citadel reference platform to test how identity, network isolation, gateway policy, observability, and agent lifecycle controls fit together in a governed Azure deployment.
NIST AI RMF gives an AI security program its operating model: govern the work, map the context, measure the risk, and manage what happens next.