AI Across the SDLC, Part 3: What to Build Before You Give Agents Write Access
Once an AI agent can push to Git, prompt injection becomes an authorization problem. Six things to build before agents get write access: a scoped identity, policy outside the model, a sandbox, MCP review, advisory CI, and traces.