Policy as Code Musings and News
Subscribe
Sign in
Home
Archive
About
Latest
Top
Discussions
Security Governance: Defense In Depth
Thinking through the layers we need to create to fully protect our data, infrastructure, systems, and people
May 22
•
John Brothers
2
Securing Atlassian Rovo: Fine-Grained Policy for AI Agents with PortcullisMCP
A PoC of agent-specific policy in action
May 19
•
John Brothers
1
2
The Risks of Dynamic Tool Discovery
Another reason you need an MCP Authorization Gateway
May 8
•
John Brothers
1
April 2026
More Insights re: working with Coding Agents
After writing this (below) I of course have a ton of additional thoughts on things I wish I had mentioned.
Apr 29
•
John Brothers
1
1
My Coding Agent Experience
Pros and Cons
Apr 27
•
John Brothers
3
AWS Bedrock AgentCore Policy
Reviewing AWS's MCP Authorization Policy Solution
Apr 24
•
John Brothers
2
1
Anthropic MCP SDK Design Vulnerability
From The Hacker News:
Apr 23
•
John Brothers
1
Policy as Code support for the EU AI Act
How can PaC help with compliance?
Apr 14
•
John Brothers
2
2
PortcullisMCP - an Open-Source Human-in-the-Loop Authorization Gateway for MCPs
You may have heard the stories about AI Agents going rogue and deleting databases, or codebases, or entire email repositories.
Apr 8
•
John Brothers
3
1
March 2026
Permit.IO - MCP Proxy Gateway
This morning, Permit announced an MCP Proxy Gateway. It offers:
Mar 18
•
John Brothers
2
Onyx AI Control Plane - an analysis
A new entrant in the AI authorization space: https://onyx.security/platform .
Mar 17
•
John Brothers
3
1
IronCurtain - AI Policy Enforcement
Enforcing governance of AI is difficult.
Mar 3
•
John Brothers
1
This site requires JavaScript to run correctly. Please
turn on JavaScript
or unblock scripts