Security, Identity & Governance¶
A practical field guide to controlling AI risk without losing operational clarity.
The map¶
This book connects threat modeling, identity, data and model protection, agent governance, and continuous assurance.
01 · Threat modelIdentify assets, boundaries, attackers, and abuse paths.
02 · Identity & accessControl which principal can take which action.
03 · Data & model securityProtect inputs, artifacts, outputs, and supply chains.
04 · Agent governanceBound delegated authority and consequential tool use.
05 · AssuranceConnect policy, evidence, monitoring, and incident response.
06 · ChecklistShip with enforceable controls and accountable exceptions.
A living book
Expand these chapters with controls, threat analyses, and governance decisions grounded in real systems.