Security & Governance
Articles about Security & Governance, with practical notes on AI-written enterprise software, governed data, application development, and agent workflows.
- Published
Power Platform Lock-In: Dataverse, Azure, and the Self-Host Tradeoff
Power Platform is already inside the Microsoft tenant, but self-hosting, Dataverse export, AI usage pricing, and sovereignty requirements matter for long-running systems.
Security & Governance IT Leaders DataversePower AppsPower Platform - Published
Is Lovable Safe for Production? The Access-Control Review Problem
Lovable can turn a sentence into a full-stack app, but production data depends on access control the accountable builder must be able to inspect, understand, and approve.
Security & Governance Developers Lovable - Published
Open vs. Closed Enterprise Ontologies: Who Owns the Business Semantic Layer?
Five platforms shipped a business semantic layer between Nov 2025 and Aug 2026, and most opened an MCP read path while keeping the definition inside. Protocol-open, definition-closed — and the ownership question got sharper.
Security & Governance Business Leaders OntologySemantic layerMCPFabric IQUnity CatalogSnowflakePalantirLooker - Published
EU AI Act Audit Readiness: Can Your AI Runtime Produce Evidence?
When an auditor asks for the full record of one AI decision, model quality is not enough. Your runtime must show authorization, evidence, oversight, and audit history.
Security & Governance IT Leaders - Published
AI Agent Pricing: Per-Action Billing vs. Self-Hosted Runtime Cost
At $0.10 per Agentforce action, a successful agent can make usage-based pricing rise quickly. Compare per-action billing with a self-hosted runtime before you scale.
Security & Governance Business Leaders AI agentsAgentforce - Published
Enterprise AI Ontology: Why the Definition and Runtime Should Be Open
Ontology MCP went GA in June 2026 — the vendors made the agent interface an open protocol themselves. Definitions are following. The runtime is the layer nobody opened, and that is where portability actually lives.
Security & Governance Business Leaders OntologyMCPPalantir - Published
Where AI Agent Permissions Are Enforced: Row-Level Security, Field Masking, and Tool Gates
Everyone agrees an AI agent should respect permissions. The real question is where the check runs. Filtering the model's output is too late — enforcement belongs in the query, the field, and the tool gate.
Security & Governance IT Leaders AI agentsAgent permissions - Published
Self-Hosted AI Application Platforms: Why the Runtime Belongs to You
Once AI reads business data, triggers workflows, generates applications, and calls tools, enterprises need control over the runtime that governs objects, permissions, tools, approvals, and audit evidence.
Security & Governance IT Leaders -
PublishedHow AI Agents Stay Inside Enterprise Permission Boundaries
Enterprise teams do not need AI agents to become unrestricted administrators. They need agents that act as controlled users, inherit permissions, route risky actions for approval, and leave an audit trail.
Security & Governance IT Leaders AI agentsAgent permissions