Year
- 2026
Category
- Product
- Insights
- Engineering
- Incident
Tag| Approvals
- AI governance
- Approvals
- Audit
- Compliance
- Execution control
- Identity security
- MCP
- Privileged access
- Work Sessions
- Zero standing privilege
The AlpacaX blog—security, product thinking, and what we're learning as we build AI agent execution control.

Product
Product update: what gets decided before a command runs
Choose how far commands are gated, confirm the server account during approval, and give automation credentials of its own.
Taeyeong BaekGTM Associate · September 8, 2026

Insights
Out-of-band approval: why an agent's own channel can never be the one that approves
An AI agent that can approve a review on its own execution channel isn't gated at all. Why out-of-band approval separates the channel, not the person.
Marco KwakHead of GTM · August 28, 2026

Product
Product update: what the audit log stops keeping—and stops missing
Command audit records are now safer, with more precise control over server access and approval requests.
Taeyeong BaekGTM Associate · August 25, 2026

Insights
AI governance on paper vs. governance during the task
A near-miss doesn't change your policy. It changes the question leadership asks about it.
Eunyoung JeongFounder & CEO · August 11, 2026

Product
Product update: the judgment behind every approval
See the reasoning behind each approval request, without bringing agent runs to a halt.
Taeyeong BaekGTM Associate · August 11, 2026

Insights
JIT access control is for humans. What should we have for AI agents?
Just-in-time access governs whether an agent gets in, and when. It says nothing about what the agent does once inside.
Eunyoung JeongFounder & CEO · July 14, 2026