AppSec
Start with control that fails or holds
The fastest route is a measured case study plus one implementation/discovery collection or one benchmark collection. That gives you runtime evidence plus a sharper way to compare control quality.
Independent research and operating notes on AI Software Delivery Control.
CAISI / Field Notes
This is the interpretation layer beside CAISI research. Start with the rollout pressure on the table: coding agents, audit evidence, unknown MCP or tool reach, long-lived credentials, selective approvals, or CI/CD workflows that now act with inherited authority.
AppSec
The fastest route is a measured case study plus one implementation/discovery collection or one benchmark collection. That gives you runtime evidence plus a sharper way to compare control quality.
CISO / Security leadership
The sprawl collection is the cleanest entry point if you need a governance-first reading on visible adoption, approval opacity, and evidence quality. The governed adoption collection is the follow-on if you need a leadership operating model for saying yes without losing control.
Engineering / Platform
The framework series explains the repo, workflow, and proof patterns. The governed adoption collection is the follow-on if you need the leadership layer around standards, sanctioned paths, and staged rollout.
GRC / Audit
The audit route is strongest when it starts with proof packets, approval records, validation outcomes, and re-review triggers before a broad rollout creates evidence gaps.
Guide
A first-review path for teams approving coding agents without slowing every prompt or local suggestion.
Reference
A proof-packet model for reconstructing AI-assisted delivery actions during audit or review.
Reference
A practical approval model for risky actions at the execution boundary.
Reference
The first practical inventory for what AI-assisted engineering workflows can touch, change, approve, and prove.
Guide
A concrete control path for PRs, GitHub Actions, CI/CD, credentials, workflow changes, and proof trails.
Reference
A practical page for evaluating tool reach, invocation context, credentials, approval triggers, and proof.
Reference
A practical page for reducing standing-token and inherited-identity risk across agents, CI/CD, tools, and release paths.
Field note
Why the missing artifact is an Agent Action BOM, not another generic AI inventory.
Field note
Why OAuth grants, tokens, and connected-tool permissions need to be reviewed as action authority, not only data access.
Field note
What OpenClaw incidents, malicious skills, and exposed agent infrastructure show about authority-bearing workflows.
Framework
An OSI-inspired model for separating compute, models, memory, orchestration, tools, authority, control, and domain action.
Field note
Why the risk is not only generated code, but delivery authority across PRs, CI/CD, credentials, tools, and release paths.
Field note
Which workflow acted, with what authority, who approved it, and what proof remains?
Field note
MCP matters, but CI/CD, scripts, credentials, repo automations, package paths, and releases matter too.
Field note
Identity is an input. The action path is the control question.
Framework essays
Repo contracts, orchestration, isolation, evaluation, proof, and maturity.
Executive adoption
Platform standards, sanctioned pathways, approval discipline, and rollout sequencing.
Reports
Interpretation layers for the two published research reports.
Evaluation
Scenario, efficacy, proof, and pilot language for evaluation-grade review.
Methods archive
Implementation context for discovery, MCP reach, policy before action, signed traces, and CI regressions.
Hub
Durable artifacts for inventory, approval, proof, CI/CD control, maturity, and stack-level reasoning.
Field guide
A practical entry point to CAISI's main concepts, control layers, and role-based starting paths.
Reference
Plain-language definition of the artifact CAISI uses to map action exposure across software delivery.
Reference
Practical checklist for GitHub Actions, CI/CD, credentials, approval, and proof.
Glossary
Plain-language definitions for write paths, execution boundaries, proof packets, approval mediation, and related terms.
Author
Profile page for the CAISI author behind the operating notes, benchmark language, and implementation essays.
Primary artifacts
Use the research hub when you want the measured report, the artifact links, and the exact scope of the claim before reading interpretation or a framework.
Reusable artifacts
Frameworks turn current field notes into artifacts teams can use during rollout, audit, platform standardization, and review.