Facio Blog

Practical notes on human-reviewed AI agents.

Payload-powered product notes, security writing, HITL patterns, and operational guidance from the Facio runtime: long sessions, Placet approvals, audit trails, memory, providers, channels, tools, and Docker-first operations.

Clear

Showing 11-15 of 44 articles in Security.

Security

Your Agent's Reasoning Is the Audit Trail You Cannot Reconstruct: Why Decision Tracing Is the Missing Primitive in 2026 AI Observability

Jul 2, 2026Security

Your Agent's Reasoning Is the Audit Trail You Cannot Reconstruct: Why Decision Tracing Is the Missing Primitive in 2026 AI Observability

Your agent made 47 tool calls in the last hour. You can see what tools it called, what arguments it passed, what responses it received. You cannot see why. The reasoning that produced the call — the model's interpretation, the alternatives considered, the selection rationale — is invisible. Decision tracing makes it visible.

Security

The Network Boundary Your AI Agent Bypasses Every 30 Seconds: Why Egress Filtering Is the Last Line of Defense for AI Agent Data Exfiltration

Jun 30, 2026Security

The Network Boundary Your AI Agent Bypasses Every 30 Seconds: Why Egress Filtering Is the Last Line of Defense for AI Agent Data Exfiltration

Your agent calls 47 external endpoints per hour. The data flowing through those calls contains customer PII, internal documents, and credential tokens. The egress firewall sees HTTPS to github.com — it cannot see the tool call's arguments. Egress filtering must operate at the agent's tool invocation layer, not at the network layer.

Security

Your AI Agent Is the New DLP Blind Spot: Why 72% of AI Agent Pilots Have No Data Protection Layer

Jun 27, 2026Security

Your AI Agent Is the New DLP Blind Spot: Why 72% of AI Agent Pilots Have No Data Protection Layer

Traditional DLP cannot see agent-to-agent data flows, cannot redact sensitive content in tool calls, cannot enforce prompt-level redaction, and cannot audit cross-system leakage. The data exfiltration gap (covered in the Facio analysis from June 2026) is now the single largest ungoverned data channel in most enterprises.

Security

Your AI Agent Pulled 100,000 Malicious MCP Server Pulls Last Quarter: The Supply Chain Attack Class Nobody Is Indexing

Jun 26, 2026Security

Your AI Agent Pulled 100,000 Malicious MCP Server Pulls Last Quarter: The Supply Chain Attack Class Nobody Is Indexing

The Phoenix Security Malware Package Intelligence corpus now indexes 657 malicious package-versions across 59 supply chain campaigns — and AI agent dependencies (MCP servers, agent skills, LLM tool packs) are the fastest-growing category. The agent's blast radius is the union of every tool it has ever pulled.

Security

AI Agents Outnumber Your Employees 45:1: The Non-Human Identity Crisis Nobody Is Governing

Jun 25, 2026Security

AI Agents Outnumber Your Employees 45:1: The Non-Human Identity Crisis Nobody Is Governing

In a typical 2026 enterprise with 5,000 human employees, the identity directory contains 50,000–250,000 non-human identities — and AI agents are the fastest-growing category. 78% of organizations have no formal AI identity policies, even as agents gain admin-level access to customer data, financial tools, and production systems.