Writing · Pillar
AI, automation & vendor watch.
Emerging analysis, tracked to read direction rather than claimed as core thesis: the NANDA agent-identity question, RAPTOR and the duct-tape era of agentic security, MCP beyond chat, and vendor watch on Databricks Lakewatch and the SDPP cohort. The security-data measurements are the anchor; the broad-AI framing is here to map where the field is heading.
Vendor-watch layer, tracked to read direction; no book chapter by design · 4 essays
Listed from the front door down to the measured evidence. Start here marks the entry essay. The reading-level tag says whether you are about to read the frame (Orientation), the argument (Depth), or the narrowest first-party finding (Evidence). The durability tag flags whether a number is durable architecture or an Evidence-pinned result tied to a version or price and meant to be re-run.
- Start here OrientationDurable
The Gatsby Summer of AI.
AI maturity read through early-automotive history: past the horseless-carriage stage, building AI-native, but in a chaotic pre-seatbelt era where capability outran the safety infrastructure. The bill the glamour hides is measured, not felt — NL2KQL runs clean 97–99% of the time and returns the correct result set only about 58%.
Read →
- DepthEvidence-pinned
The security market has no one defining what you can own.
Vendors could ship security tools you can run, inspect, and air-gap, but nothing makes them, and no independent force scores whether a given tool lets you own it. The agentic rush is widening the gap. Sigma is the proof the open pattern wins when it has a champion; vendor MCP servers are the tell; the missing piece is a referee with a practitioner-ownability axis.
Read →
- DepthDurable
Agentic analysis reinvented Kimball. It skipped the measurement.
The 2026 consensus that AI agents need dimensional modeling, semantic layers, and governed ontologies is mostly right — and quiet about the one step that matters when the data is evidence. Autonomously-built mappings fail sound-but-wrong and silently; the answer is a deductive check that fails on a mapping that looks correct, model-independent, where a human review pass structurally can't. The AI-generated-OCSF-parser claim is the cleanest worked example: transformative only at production-grade accuracy.
Read →
- DepthEvidence-pinned
What's real vs marketed in the agentic SOC.
Claims about agentic security-data deserve a definition demand and an evidence tier, not a headline. The honest practitioner ceiling sits at 30-40% end-to-end, not the 90%+ the slides claim; the binding constraint is cross-vendor identity and trust (MIT's NANDA), not the automation percentage; the pipeline layer is where the migration risk consolidates. The durable fair-broker read on what ships, what doesn't, and what to plan for.
Read →