Year
- 2026
Category
- Insights
- Engineering
- Incident
- Product
Tag| Audit
- AI governance
- Approvals
- Audit
- Compliance
- Execution control
- Identity security
- MCP
- Privileged access
- Work Sessions
- Zero standing privilege
The AlpacaX blog—security, product thinking, and what we're learning as we build AI agent execution control.

Product
Product update: what the audit log stops keeping—and stops missing
Command audit records are now safer, with more precise control over server access and approval requests.

Insights
ISO 42001 Stage 1 checklist: the documentation to have ready before your audit
Stage 1 is a documentation and readiness review—the part of ISO 42001 you can actually prepare for in advance. Here's what an auditor expects on the table before Stage 2.

Insights
ISO 42001 audit checklist: the controls a policy document can't satisfy
You can pass Stage 1 on paperwork. Stage 2 asks what your AI agents actually did in production—and three Annex A controls decide whether you have the answer.

Insights
A command log won't tell you what your agent actually did.
A command log tells you what ran. An audit has to answer who, why, and with whose approval—for humans and agents alike.

Product
Work Sessions: the audit unit your CISO actually needs
Alpacon's Work Sessions turn fragmented audit timelines into one object—declared intent, approval gate, session-scoped sudo, unified record.