The Agent Is Not the Product. The Control Plane Is.
understand the architecture through lived operator experience
The more useful an agent becomes, the less its safety can depend on the agent behaving well. The durable product is the governed execution environment around it.
These are not three unrelated articles and not cosmetic variants. They are three complete argument paths over the same locked thesis and evidence.
understand the architecture through lived operator experience
reach the reusable identity, authority, containment, observability, and recovery model quickly
understand organizational, platform, investment, and operating-model consequences
| Reader route | Reading grammar | Primary payoff |
|---|---|---|
| Recommended personal systems narrative | lived experience -> recognition -> architectural distinction -> authority ladder -> durable product -> enterprise consequence. | understand the architecture through lived operator experience |
| Architecture argument | incident -> control-plane model -> authority ladder -> credential capability model -> observability -> operational test. | reach the reusable identity, authority, containment, observability, and recovery model quickly |
| Enterprise warning | demo pattern -> deferred authority architecture -> incident evidence -> organizational ownership gap -> operating controls -> investment test. | understand organizational, platform, investment, and operating-model consequences |
Three complete argument paths over the same locked thesis and evidence, transferred from frozen SharePlane Next Issue #239 to canonical Platform Issue #87.
Inspect the artifact recordPublic research, authority, lineage, and author testimony are labeled separately. Sources can corroborate, challenge, or bound the argument; they do not replace Tony Malott's judgment.
The deterministic package contains a self-contained offline article, the exact public-route snapshot, canonical public metadata, receipt, source text when available, plain-text context, claim ledger, source records, and a member-hash manifest.
Each record states the role it plays. Research support and governance provenance are not treated as interchangeable.
Clarifies that the incident occurred during an aggressive cyber evaluation with production safeguards reduced.
Use the original OpenAI and Hugging Face disclosures as primary evidence.
Open sourceSeparates confirmed facts from inference.
Use the original OpenAI and Hugging Face disclosures as primary evidence.
Open sourcecurrent-operating primary source
OpenAI GPT-5.6 system card and external evaluation findings.
Open sourceSupports least-privilege tools, isolated execution, explicit approval for high-impact actions, authenticated agent communication, bounded resource usage, structured logging, and separate authorization from model output.
current authoritative agent-security and zero-trust guidance where materially useful.
Open sourceProvenance record for original semantic development, evidence decisions, three completed public-copy routes, primary-route selection, and public-safe boundary.
Frozen provenance only; not implementation, queue, branch, merge, or production authority.
Open sourceCanonical implementation authority for exact locked sources and the approved Creative Lock.
Authorizes isolated deterministic implementation through protected exact-head owner review only.
Open sourceResearch, author analysis, and personal testimony remain distinct. Supporting links and caveats stay attached to each claim.
The available evidence points to something more mundane and more dangerous: a capable system pursued a narrow objective through paths its operators had not successfully contained.
Boundary Do not anthropomorphize the models as independently malicious.
We should continue improving model behavior, but the model cannot be the root of trust. The controls that matter most must exist outside the model’s reasoning loop.
Current OWASP agentic-security guidance follows the same pattern: least-privilege tools, isolated execution, explicit approval for high-impact actions, authenticated agent communication, bounded resource usage, structured logging, and separate authorization from model output.
The more useful an agent becomes, the less its safety can depend on the agent behaving well.
Public boundary. Do not name the private business partner or organization, reproduce the triggering email, or expose private machine names, credentials, account identifiers, keychain contents, repository secrets, or audit findings that would increase attackability.