6 min read
My Claude Guardrails
Claude Code can access our internal systems. Here are the guardrails: the policies that decide what my AI agent can actually reach, all published in our policy catalog.


5articles
Founder and CEO of Dtwo. Over two decades, Denis has taken security and SaaS products from concept to scale: he built Security Cloud Control Firewall Management (formerly Cisco Defense Orchestrator) from the ground up — now managing tens of thousands of devices across thousands of enterprises — and architected the cloud version of Aveksa's identity and access management platform that anchored its acquisition by RSA. He later co-founded Genie Life Sciences, a lab-automation company acquired by Eppendorf in 2024. Today he writes here about securing AI agents in the enterprise.
6 min read
Claude Code can access our internal systems. Here are the guardrails: the policies that decide what my AI agent can actually reach, all published in our policy catalog.


Engineering9 min read
Cheap implementation moved the work upstream. Every architectural decision is now recorded in the same repo as code. It becomes the context for everything built after it, and gets revised when we turn out to be wrong.

Security3 min read
The risk from AI agents isn't any one system — it's the path between them. Policy guards that path. It's hard to write — so we open-sourced a library of policies.

Security7 min read
Audit worked because people feared getting caught. AI agents don't — so agent security must shift from audit to authorization across every system.

security2 min read
Legacy security controls were built for humans, not AI agents — that's why agentic AI security and governance are breaking. Here's the gap, and how to close it.