Skip to main content

Knowledge is Power

All resources

By Topic

By Content Type

Knowledge Center Governance & Compliance

AI Agent Audit Trails and Immutable Logging

An AI agent audit trail is a durable record of what an agent did, under whose credentials, and in what context.

Blog Discovery & Posture

The Golden Catalog Is a Comforting Fiction

Pre-approved agent template libraries optimize for control over a static asset, when the thing they're trying to control isn't static at all.

Hanah Darley
Knowledge Center Cost Intelligence

Agent Cost Governance and Cost Attribution

How organizations attribute, predict, and control what autonomous agents spend — and why cost and security are the same instrumentation problem.

Knowledge Center Discovery & Posture

AI Agent Posture Management

The continuous practice of connecting what an agent is configured to do, what it can actually reach, and what it's actually doing — and how that differs from identity governance and point-in-time AI-SPM scans.

Knowledge Center Observability & Detection

AI Agent Security vs EDR

Exactly what EDR covers for AI agents, what it structurally can't, and where agent security sits alongside the controls already deployed.

Knowledge Center Observability & Detection

AIDR (AI Detection and Response)

What AIDR means, how it differs from AI-SPM and guardrails, and the question that separates real AIDR from monitoring with a new name.

Knowledge Center Discovery & Posture

Shadow AI and Agent Sprawl

What shadow AI is, how it differs from agent sprawl, why surveys and gateways miss it, and how detection actually works.

Knowledge Center Observability & Detection

Agent Harnesses

What actually turns a model into an agent — and why security controls have to target that layer, not the model itself.

Knowledge Center Remediation

Agent Lifecycle Hooks

Where hooks sit in an agent's execution, what they can and can't protect against, and how they compare across major platforms.

Deep Research Discovery & Posture

A Guide to Agent Skills

A working model for where agent skills actually create risk — and six practices for folding them into the governance you already run.

Knowledge Center Protocols & Interoperability

MCP vs Skills

MCP servers and agent skills solve different problems and are often confused as competing standards.

Deep Research Discovery & Posture

A Guide to Agent Control

Geordie’s Field Guide shows the control points Anthropic, OpenAI, AWS, and Microsoft have built in natively – and where each falls short.

Advisory Threat Research

Technical Advisory: TeamPCP Supply Chain Campaign

A threat actor compromised the Trivy vulnerability scanner and used stolen CI/CD secrets to cascade into Checkmarx, LiteLLM, and 50+ npm packages.

Giuseppe Trovato
Advisory Threat Research

Technical Advisory: n8n Unauthenticated Remote Code Execution (Ni8mare)

Critical unauthenticated remote code execution vulnerability in n8n workflow automation allows attackers to exploit content-type confusion in Form webhook file upload processing to read arbitrary files, steal credentials, and execute arbitrary code on the server.

Giuseppe Trovato
Advisory Threat Research

Technical Advisory: n8n Remote Code Execution via Expression Injection

Critical remote code execution vulnerability in n8n workflow automation platform allows authenticated users to execute arbitrary code on the server through specially crafted workflow expressions that escape the sandbox isolation.

Giuseppe Trovato
Blog Governance & Compliance

Governing AI Agents: Best Practices to Scale Safely

Building on research from Berkeley, this article outlines five barriers to enterprise AI adoption and the AI governance best practices to overcome them with visibility and accountability.

Hanah Darley
News Company News

Why We're Building Geordie

We started Geordie to build the governance layer for AI agents.