Facio Blog

Practical notes on human-reviewed AI agents.

Payload-powered product notes, security writing, HITL patterns, and operational guidance from the Facio runtime: long sessions, Placet approvals, audit trails, memory, providers, channels, tools, and Docker-first operations.

Clear

Showing 31-35 of 53 articles in Security.

Security

Why Your DLP Cannot See the Agent: The Data Exfiltration Gap in AI-Native Architectures

Jun 10, 2026Security

Why Your DLP Cannot See the Agent: The Data Exfiltration Gap in AI-Native Architectures

Traditional DLP inspects the perimeter. AI agents operate inside it — reading customer records, summarizing financial PDFs, calling APIs. 78% of employees already use unsanctioned AI tools. Your content inspection was designed for a world where users paste data into form fields. Now the form fields think.

Security

Your Monitoring Says Green, Your Agent Is Wrong: The Observability Gap Killing Production AI

Jun 8, 2026Security

Your Monitoring Says Green, Your Agent Is Wrong: The Observability Gap Killing Production AI

Traditional monitoring can keep 99.99% availability while the agent's decisions degrade quality across the workflow. Decision integrity is the new observability surface — and OpenTelemetry's GenAI semantic conventions plus the new MCP tracing layer are finally making it tractable. Here's how to build for it.

Security

The Sentence That Stole an npm Token: How AI Agents Became the Third Class of Lateral Movement

Jun 7, 2026Security

The Sentence That Stole an npm Token: How AI Agents Became the Third Class of Lateral Movement

A single GitHub issue title — just a sentence — compromised a CI/CD pipeline and published a poisoned npm package. No network intrusion. No credential theft. Just an AI agent bridging an untrusted comment field and a privileged software supply chain. Welcome to agent-mediated lateral movement.