Product1 distinct publisher3 min readPublished
SiliconAngle's four-layer framework for agentic AI reads as identity and access work in new clothes. Its incident list makes that case better than its architecture does. The operator payload sits in one section.
The Product Desk · Product desk

Compiled by The Product DeskSomething wrong?How this is made
The version of this that shows up in a normal week is a ticket. Someone needs the new coding agent to read the repo and run migrations against staging, the credential that already exists does both, and it also works in production. No one signs off on giving an agent production write access. A queue does it.
SiliconAngle's load-bearing sentence is that in each of its four cases the agent did what it was built to do, and what failed was everything around it [6]. Sort those cases by what the failure touched and three of them are reach: the deleted PocketOS database, the hijacked Instagram accounts, and the private repository data researchers coaxed out of a GitHub agent [1][1][4][5].
The controls the piece actually specifies live in its Secure section, and none of them are novel. A permission set tied to the agent's specific role. Permissions limited to the task rather than to the integration. Logging of every action. A kill switch that cuts access the moment something looks wrong [8]. The Instagram case gets the most specific version of that treatment, where SiliconAngle's suggestion is tighter scoping plus a real-time check on what the bot was authorized to do [10].
As evidence, the incident list is thinner than the prescription it supports. One incident carries a duration, the two hours at Meta, while the timing on the other three is left unspecified [3][2].
The framing around the controls is worth reading slowly, because the four layers named as Sense, Decide, Act and Secure are also a product outline [7]. Sense means live connections to data wherever it sits, across departments and clouds, without centralising it first [16]. Decide means a store of decision history deep enough that an agent handling a routine request can see how the last 20 similar requests were resolved and what happened next [12]. SiliconAngle says closing the gap does not require an army of consultants, in the same argument that calls forward-deployed engineer the hottest job in tech [14][13].
Teams tend to treat the wide credential as a temporary feature of the pilot, on the assumption that the advisory phase ends before the access does. In practice the order usually runs the other way: the advisory phase ends, the credential never gets narrowed, and the agent's blast radius is whatever the integration account could always do.
Two axes are enough to sort your own deployments. Whether the agent can change state or only read it, and whether its credential is issued per task and revocable mid-run or is standing. Read-only on a standing credential is the data governance problem you already have on file somewhere. Write access on a standing credential with no per-action log is the quadrant that the PocketOS delete and the GitHub repository leak both sit in, and it is the one worth holding back until the kill switch and the log exist [1][5][8]. Accountability follows the credential: whoever holds it answers for it on Friday, even though the model choice usually belonged to someone else.
Ranked by verification strength, evidence, and original report placement.
The piece prescribes an architectural framework with four characteristics, named Sense, Decide, Act and Secure.
The Secure section calls for scoped identity, permissions limited to the specific task, a clear audit trail, a permission set tied to each agent's specific role, logging of every action an agent takes, and a kill switch to cut off an agent's access the moment something looks wrong.
The piece says the identity and access management best practices a company already applies to employees now need to be extended to non-human actors.
The piece says that in the Instagram incident, tighter scoping and a real-time check on what the bot was authorized to do might have caught the error.
The piece says that with better context drawn from how similar historical changes played out, the Meta outcome might have been avoided.
The piece says an agent handling a routine request should have access to how the last 20 similar requests were resolved and what happened as a result.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 30, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
leadership
Builders put doom at 10 to 50 per cent and expect binding rules only after the disaster1 distinct publisher
product
Half the incident clock goes to search, and telemetry tools cannot read the answer1 distinct publisher
invest
The remedy New Mexico won at trial is the one Meta's $18 billion settlement does not contain1 distinct publisher
build
The line JavaScript cannot cross, and who pays for going around it1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Four one-line incidents, none of them checked
Everything persuasive here rests on four failures described in four sentences, all from a single contributed column. No links, no filings, no company statements, no incident reports. Meta supplies the only duration, Instagram the only magnitude, and 'last month' is the sole gesture at timing. The prescriptive half of the column is fully verifiable — you can read the six Secure controls on the page — but the evidence that the world needs them is entirely one author's recollection.
Nothing running is shown
Sense, Decide, Act and Secure appear strictly as a prescription. No customer, deployment, product, pilot, or usage figure attaches to any of the four layers, and because the incidents themselves are undated they cannot even establish a timeline of agent failures in production. There is nothing here to measure uptake against.
The checklist is old; the architecture claim is new
Zavery says it himself in the Secure section — this is the identity and access discipline companies already apply to employees, pointed at non-human actors. Scoped identity, least privilege, audit trails and a kill switch are not a discovery. What is being sold above that is the idea of a novel four-layer architecture, plus an Act section arguing that returns require agents which execute rather than advise, placed a few hundred words after four cases where executing was exactly what went wrong. The narrower finding buried in the incident list is stronger than the framework wrapped around it, and only two of the four cases get a fix at all.
The remedy is described by the company selling it
The byline belongs to ServiceNow's president, chief product officer and chief operating officer, and the four layers map cleanly onto workflow orchestration and agent governance — the category his company competes in. The 'no army of consultants' line is a direct swipe at services-led AI delivery, which is the alternative to buying a platform. SiliconANGLE labels the piece as written for it and closes with its own marketplace and community appeals. None of that makes the incident pattern false; it does mean the diagnosis and the product were authored by the same hand.
Sure what was said, unsure what happened
We hold the complete text, so there is no ambiguity about the argument, the six controls, or which incidents were left unaddressed — those readings are solid. Whether a coding agent really wiped a production database at PocketOS, or what the two hours at Meta consisted of, is untested here and cannot be settled from what we have. The middling score is that split: high confidence in the analysis of the column, low confidence in the facts it asserts.