0% read on this device
Browse the curriculum

Start Here

Vision

First Principles

Operating Model

Domain Model

Agent Factory

Runtime Architecture

AI Engineering

Autonomous Workflows

Verification & Delivery

Factory Platform

Quality Engineering

Security & Governance

Case Studies

Labs

Interview Practice

Research Journal

Reference

Curriculum/Security & Governance/A focused view of boundaries, contracts, state, authority, failure paths, and tradeoffs drawn from this chapter.
Security & Governance15 min readchapterQuick Read

Workload Identity, Secrets, Privacy, and Compliance

Define who or what acts, which authority it receives, how credentials are delivered, and how information obligations persist across the factory.

Status: Review readyRisk: criticalLifecycle: intent · execute · verify · deliver · learnContent reviewed 2026-08-30Maturity guide →
Claim boundaryThis is curriculum guidance. It does not by itself prove a production implementation.
architecture mode

A focused view of boundaries, contracts, state, authority, failure paths, and tradeoffs drawn from this chapter.

Whiteboard exercise

Reconstruct and defend this chapter’s architecture.

Reconstruct the architecture, name each boundary, and defend the tradeoffs.

securitygovernance15 min chapter
Open the source exercise

Trace one Attempt from a human-approved WorkOrder through workload identity to repository, model, artifact, and deployment tools. Add cross-region data, cancellation, secret leakage, and a deletion request. Mark every control and retained audit fact.

4. Tradeoffs and alternatives

Fine-grained credentials reduce blast radius and increase integration cost. Shared credentials simplify setup and undermine attribution and revocation. Long retention aids forensics and increases privacy exposure. Minimize by default and define exceptions. Self-hosting can improve control while shifting security and reliability obligations to the operator.

5. Current Mission Control Implementation

The current curriculum covers authentication, authorization, service identity, tenant boundaries, secret handling, audit, evidence retention, supply-chain provenance, policy, and approvals.

It does not yet provide a complete workload-identity federation design, just-in-time credential flow, delegated authorization chain, data inventory, deletion workflow, residency policy, intellectual-property and license controls, or formal compliance mapping. Those controls require organizational and platform implementation beyond chapter-level architecture.

External review

Review this chapter.

Challenge a claim, boundary, missing failure mode, unclear term, or unsupported evidence statement.

  • Claim
  • Boundary
  • Failure
  • Evidence