DEV Community

Imran Siddique profile picture

Imran Siddique

CPO, Opaque Systems | Agent Governance & Confidential Computing | Creator, Agent Governance Toolkit | ex-Microsoft Azure

Two caps, two enforcement points

Two caps, two enforcement points

Comments
4 min read

Want to connect with Imran Siddique?

Create an account to connect with Imran Siddique. You can also sign in below to proceed if you already have an account.

Already have an account? Sign in
The evidence standard that needs a gate to count

The evidence standard that needs a gate to count

Comments
4 min read
Every control plane writes the log that describes its own behaviour

Every control plane writes the log that describes its own behaviour

Comments
5 min read
Five Docker Sandboxes CVEs this year, all in the doors

Five Docker Sandboxes CVEs this year, all in the doors

Comments
5 min read
Agent Mesh: what it assumes about your agents

Agent Mesh: what it assumes about your agents

Comments
5 min read
Verified, with nothing hashed

Verified, with nothing hashed

Comments
4 min read
Every Dependency Is a Promise Your System Has to Keep

Every Dependency Is a Promise Your System Has to Keep

Comments
3 min read
One repository answered the same question twice on 11 September

One repository answered the same question twice on 11 September

Comments
4 min read
The alias check I wired up was bypassed in September 2025

The alias check I wired up was bypassed in September 2025

Comments
5 min read
Deep-dive: how the public TRACE Registry is built to be distrusted

Deep-dive: how the public TRACE Registry is built to be distrusted

Comments
9 min read
The authentication fix that changed no authentication

The authentication fix that changed no authentication

Comments
4 min read
Your trace knows what the agent did. It does not know what you allowed.

Your trace knows what the agent did. It does not know what you allowed.

Comments
5 min read
The release forbade the swap and left the signal opt-in

The release forbade the swap and left the signal opt-in

Comments
5 min read
The fix shipped three weeks before the bug had a name

The fix shipped three weeks before the bug had a name

Comments
4 min read
The finding was correct and eight weeks late

The finding was correct and eight weeks late

Comments
4 min read
What your agent can prove after the second hop

What your agent can prove after the second hop

Comments
6 min read
Two normative sentences went missing when one tasks spec superseded another

Two normative sentences went missing when one tasks spec superseded another

Comments
5 min read
Your telemetry and your evidence are not the same record

Your telemetry and your evidence are not the same record

Comments
5 min read
The tool list was advertised, the resolver decided

The tool list was advertised, the resolver decided

Comments
4 min read
The MCP registry checks that the repository URL looks like GitHub

The MCP registry checks that the repository URL looks like GitHub

Comments
5 min read
The platform bit that means the opposite of what the doc says

The platform bit that means the opposite of what the doc says

Comments
4 min read
The attestation everyone cites cannot be looked up any more

The attestation everyone cites cannot be looked up any more

Comments
5 min read
My quickstart ends in FAIL, and that is the correct answer

My quickstart ends in FAIL, and that is the correct answer

1
Comments 1
3 min read
Sovereign verifiability takes three layers. A2A just secured the foundation.

Sovereign verifiability takes three layers. A2A just secured the foundation.

Comments
8 min read
The LiteLLM compromise is not in any of the places you would look for it

The LiteLLM compromise is not in any of the places you would look for it

Comments
4 min read
What the encrypted reasoning paper actually counted

What the encrypted reasoning paper actually counted

Comments
4 min read
What a signature does not prove

What a signature does not prove

Comments
8 min read
Two of the three endpoints checked authorization

Two of the three endpoints checked authorization

Comments
4 min read
The approval prompt stops working after fifty clicks

The approval prompt stops working after fifty clicks

Comments
4 min read
You downloaded a model. What did you actually get?

You downloaded a model. What did you actually get?

Comments
4 min read
The best agent detector in production catches 67%. Plan for the rest.

The best agent detector in production catches 67%. Plan for the rest.

Comments
6 min read
Our Quickstart Did Not Work, And That Is The Interesting Part

Our Quickstart Did Not Work, And That Is The Interesting Part

Comments
4 min read
The industry scheduled the proof. Here is what provable inference has to prove.

The industry scheduled the proof. Here is what provable inference has to prove.

Comments
6 min read
Nobody was negligent. The layer was missing.

Nobody was negligent. The layer was missing.

Comments 1
6 min read
Soon Every Agent Will Have a Verifiable Identity. Then Comes the Harder Part.

Soon Every Agent Will Have a Verifiable Identity. Then Comes the Harder Part.

Comments
4 min read
The most important sentence in the Hugging Face disclosure is the one about what did not happen

The most important sentence in the Hugging Face disclosure is the one about what did not happen

Comments
3 min read
Open Weights Don’t End the Custody Problem. They Sharpen It.

Open Weights Don’t End the Custody Problem. They Sharpen It.

Comments
4 min read
Soon There Will Be More Agents Than Users. Here Is the Trust Layer That Makes That a Good Thing.

Soon There Will Be More Agents Than Users. Here Is the Trust Layer That Makes That a Good Thing.

Comments
5 min read
Your Policy Engine Can Lie. Ours Can’t.

Your Policy Engine Can Lie. Ours Can’t.

Comments
8 min read
How Do You Prove an AI Agent Did What You Said It Did?

How Do You Prove an AI Agent Did What You Said It Did?

Comments
6 min read
Prove What Your Agent Was, Not Just Who Called It

Prove What Your Agent Was, Not Just Who Called It

Comments
5 min read
Every regulated AI deployment hits the same wall. The compliance review asks: prove the agent handled our data according to...

Every regulated AI deployment hits the same wall. The compliance review asks: prove the agent handled our data according to...

Comments
1 min read
Every regulated AI deployment hits the same wall: prove the agent handled our data...

Every regulated AI deployment hits the same wall: prove the agent handled our data...

Comments
1 min read
A signed JWT proves who called your API. It proves nothing about the agent that made the call. Not which system prompt...

A signed JWT proves who called your API. It proves nothing about the agent that made the call. Not which system prompt...

Comments
1 min read
New edition of Proof, Not Promises is live.

New edition of Proof, Not Promises is live.

Comments
1 min read
[Part 5] 20 Hard Questions About AI Agent Governance That Nobody Is Asking

[Part 5] 20 Hard Questions About AI Agent Governance That Nobody Is Asking

Comments
3 min read
If you want to understand what Agent Governance Toolkit actually does, this is the best place to start. This video explains...

If you want to understand what Agent Governance Toolkit actually does, this is the best place to start. This video explains...

Comments
1 min read
[Part 4] 20 Hard Questions About AI Agent Governance That Nobody Is Asking

[Part 4] 20 Hard Questions About AI Agent Governance That Nobody Is Asking

Comments
2 min read
[Part 3] 20 Hard Questions About AI Agent Governance That Nobody Is Asking

[Part 3] 20 Hard Questions About AI Agent Governance That Nobody Is Asking

Comments
3 min read
[Part 2] 20 Hard Questions About AI Agent Governance That Nobody Is Asking

[Part 2] 20 Hard Questions About AI Agent Governance That Nobody Is Asking

Comments
2 min read
20 Hard Questions About AI Agent Governance That Nobody Is Asking

20 Hard Questions About AI Agent Governance That Nobody Is Asking

Comments
3 min read
Governing Google ADK Agents with Microsoft’s Open-Source Toolkit: A GCP-Native Guide

Governing Google ADK Agents with Microsoft’s Open-Source Toolkit: A GCP-Native Guide

Comments
4 min read
Running AI Agent Governance on AWS, No Azure Required

Running AI Agent Governance on AWS, No Azure Required

Comments
5 min read
Observability for Non-Deterministic Systems: A Framework for AI Agent Reliability

Observability for Non-Deterministic Systems: A Framework for AI Agent Reliability

Comments 1
3 min read
Securing AI agents with agent governance

Securing AI agents with agent governance

Comments 1
10 min read
OpenShell + Governance Toolkit: Engineering the Complete Agent Security Stack

OpenShell + Governance Toolkit: Engineering the Complete Agent Security Stack

Comments
3 min read
Running 11 AI Agents in Production: How the Agent Governance Toolkit Secures Our Workflows

Running 11 AI Agents in Production: How the Agent Governance Toolkit Secures Our Workflows

Comments
4 min read
Engineering the Agent Hypervisor: OS Primitives for Multi-Agent Systems

Engineering the Agent Hypervisor: OS Primitives for Multi-Agent Systems

Comments
3 min read
The Architect’s Dilemma: Skills, Agents, or an Operating System?

The Architect’s Dilemma: Skills, Agents, or an Operating System?

Comments
3 min read
Engineering Safety: A Layered Governance Architecture for GitHub

Engineering Safety: A Layered Governance Architecture for GitHub

Comments
2 min read
loading...