<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Brief</title><description>A short publication on AI security architecture and risk.</description><link>https://brief.amoran.io/</link><language>en-gb</language><item><title>A hook is not a security boundary</title><link>https://brief.amoran.io/a-hook-is-not-a-security-boundary/</link><guid isPermaLink="true">https://brief.amoran.io/a-hook-is-not-a-security-boundary/</guid><description>If the host is trusted, a governance contract can prove a deny. It cannot contain a host that never asks.</description><pubDate>Sun, 30 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Deny has to mean deny</title><link>https://brief.amoran.io/deny-has-to-mean-deny/</link><guid isPermaLink="true">https://brief.amoran.io/deny-has-to-mean-deny/</guid><description>Framework callbacks observe. A governance contract has to stop the action, including when the guard crashes.</description><pubDate>Sun, 30 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Two allowed actions can still be the breach</title><link>https://brief.amoran.io/two-allowed-actions-can-still-be-the-breach/</link><guid isPermaLink="true">https://brief.amoran.io/two-allowed-actions-can-still-be-the-breach/</guid><description>Per-tool permission is not an architecture. The control is which combinations you will not allow in one session.</description><pubDate>Sun, 30 Aug 2026 00:00:00 GMT</pubDate></item><item><title>MCP access is now an IdP problem</title><link>https://brief.amoran.io/mcp-access-is-now-an-idp-problem/</link><guid isPermaLink="true">https://brief.amoran.io/mcp-access-is-now-an-idp-problem/</guid><description>Enterprise-managed auth moves the privilege decision off the consent screen and onto identity policy. The blast radius moves with it.</description><pubDate>Sat, 29 Aug 2026 00:00:00 GMT</pubDate></item></channel></rss>