Product1 publisher3 min readPublished
Docker pipes every agent policy decision into your SIEM, and the evidence burden lands on platform teams
Docker AI Governance now streams every agent policy decision into the SIEM security already runs, with a searchable copy in Docker Cloud. Enforcement was the easy half.
The Product Desk · Product desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction
What happened
- Docker AI Governance now streams every policy decision in an organization into the SIEM the security team already runs, with a searchable record of all of it in Docker Cloud.
- Docker says customers can see what their agents did, and what their policy stopped them from doing.
- Docker's post frames enforcement as 'step one'.
- Docker says policy enforcement now reaches every developer machine.
- Docker says supply-chain compromises now reach the tools the industry trusts to defend itself, with Trivy and KICS among this year's targets.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
Docker says its AI Governance product now streams every policy decision an organization's agents trigger into the SIEM the security team already runs, with a searchable record of all of it kept in Docker Cloud [1]. That quietly changes the question platform teams get asked about agents: not whether an agent is permitted to do something, but whether you can produce the record of what it did and what you stopped [2].
The framing in Docker's own post is that enforcement is step one [3]. That is the honest read. A permissions model is a design artifact; a decision log is an operational one, and it has an owner, a volume, a retention policy, and a bill. The interesting half of the feed is the denials, because a blocked action is the only cheap proof that a control existed and fired. Allowed decisions are where the volume lives, and Docker also says policy enforcement now reaches every developer machine [4], which means the event source is now every laptop in the org rather than a handful of CI runners.
Docker's stated reason for pushing here is the state of the supply chain: compromises have reached the tools the industry uses to defend itself, with Trivy and KICS among this year's targets [5], and Docker CISO Mark Lechner called the latest wave "a permanent shift in the threat landscape" [6]. The company also says more than a quarter of production code is now AI-authored, with agents pulling dependencies at machine speed [7]. If that is roughly right, the auditability problem is not a future one.
What the announcement does not do is answer the questions a platform team needs before it can commit ingest budget. The source material names no supported SIEM products, no event schema, no retention window for the Docker Cloud copy, and no packaging or pricing detail for AI Governance [8]. Two systems of record also means two systems that can disagree, and nobody has said which one is authoritative when an auditor asks.
The rest of the release is the substrate this governance story sits on. Docker Hardened Images ships signed SBOMs and SLSA Build Level 3 provenance, on the argument that auditors should work from evidence rather than vendor claims [9]. The catalog has passed 4,000 hardened images alongside MCP servers, Helm charts and ELS images [10], drawing more than 3.5 million pulls a week with over a million builds running regularly to keep it patched [11]. That averages out to fewer than about 875 pulls per image per week [12], which tells you the distribution is long-tailed and a small number of images carry the traffic. Docker names Python as the most pulled image and among the first to ship fully hardened [13], and says n8n runs production on DHI [14]. Below the image line, Docker Hardened System Packages are built from upstream source in the same SLSA Build Level 3 pipeline, and DHI Enterprise customers can point apt or apk at Docker's hardened package repository for images they build themselves [15]. The Debian and Alpine package lists are public [16]. The stated goal is one provenance chain covering images, packages, charts and the tools agents call [17].
Watch for the schema and the SIEM compatibility list, because a decision feed you cannot parse into detections is just storage. Watch what a "policy decision" counts as, since that definition sets your ingest cost. And watch whether laptop-generated decisions can be tied back to a named human owner, because that is the field an auditor will actually want.