Writing · Pillar
AI, automation & vendor watch.
Emerging analysis, tracked to read direction rather than claimed as core thesis: the NANDA agent-identity question, RAPTOR and the duct-tape era of agentic security, MCP beyond chat, and vendor watch on Databricks Lakewatch and the SDPP cohort. The security-data measurements are the anchor; the broad-AI framing is here to map where the field is heading.
Vendor-watch layer, tracked to read direction; no book chapter by design · 5 essays
Listed from the front door down to the measured evidence. Start here marks the entry essay. The reading-level tag says whether you are about to read the frame (Orientation), the argument (Depth), or the narrowest first-party finding (Evidence). The durability tag flags whether a number is durable architecture or an Evidence-pinned result tied to a version or price and meant to be re-run.
- Start here OrientationDurable
The Gatsby Summer of AI.
AI maturity read through early-automotive history: past the horseless-carriage stage, building AI-native, but in a chaotic pre-seatbelt era where capability outran the safety infrastructure. The bill the glamour hides is measured, not felt — NL2KQL runs clean 97–99% of the time and returns the correct result set only about 58%.
Read →
- DepthEvidence-pinned
Security has an ontology. It doesn't have a semantic layer.
D3FEND settled security's knowledge layer; nothing binds that knowledge to tables and metrics. The schemas carry no metrics, the metric catalogs aren't machine-readable, the coverage formats exchange scores with no defined derivation, and the commercial products that do compute metrics publish no standard. Apache Ossie (incubating) is the first credible candidate to close the gap, verticals are organizing inside it now, and security isn't in the room.
Read →
- DepthEvidence-pinned
The security market has no one defining what you can own.
Vendors could ship security tools you can run, inspect, and air-gap, but nothing makes them, and no independent force scores whether a given tool lets you own it. The agentic rush is widening the gap. Sigma is the proof the open pattern wins when it has a champion; vendor MCP servers are the tell; the missing piece is a referee with a practitioner-ownability axis.
Read →
- DepthDurable
Agentic analysis reinvented Kimball. It skipped the measurement.
The 2026 consensus that AI agents need dimensional modeling, semantic layers, and governed ontologies is mostly right — and quiet about the one step that matters when the data is evidence. Autonomously-built mappings fail sound-but-wrong and silently; the answer is a deductive check that fails on a mapping that looks correct, model-independent, where a human review pass structurally can't. The AI-generated-OCSF-parser claim is the cleanest worked example: transformative only at production-grade accuracy.
Read →
- DepthEvidence-pinned
What's real vs marketed in the agentic SOC.
Claims about agentic security-data deserve a definition demand and an evidence tier, not a headline. The honest practitioner ceiling sits at 30-40% end-to-end, not the 90%+ the slides claim; the binding constraint is cross-vendor identity and trust (MIT's NANDA), not the automation percentage; the pipeline layer is where the migration risk consolidates. The durable fair-broker read on what ships, what doesn't, and what to plan for.
Read →