FIELD NOTE / LINKEDIN
The customer outcome is the asset.
The short film, the complete written thought, and the evidence behind it.
The LinkedIn conversation link will follow its public release.
The customer outcome is the asset.
Video caption
The customer outcome is the asset.
New tools expand the perimeter without changing the old hook.
Track principals, capabilities and recertification triggers.
My rule: Change review begins when authority changes.
Narration uses Eric's authorized AI voice clone.
#EricFieldNotes
Full written post / accessibility read
A leader hears that the coding-agent hook blocked a production change. That is useful, but the protected thing is the customer tenant. The question is whether any identity controlled by that workflow could still change it through another connector or service credential.
A developer adds an MCP integration. Operations gives a worker a cloud token. A supervisor can delegate. The original policy file may be unchanged, yet the set of paths from agent to tenant has grown. Nobody gets a warning from the old green log.
For each consequential action, name the service owner who can enumerate credentials and endpoints. Record which routes were canary-tested, which service checks apply and who reviews a new connector. Use short-lived scoped credentials where available; do not mistake their short lifetime for authorization by itself.
Ask for a route matrix and a target receipt readback before calling a behavior enforced. Re-run it when tools, workers, service roles or tenant policy change. That small operating discipline protects the customer outcome while agents and their host features evolve.
Narration uses Eric's authorized AI voice clone.
#EricFieldNotes
Four-beat scene transcript
1. The customer outcome is the asset.
A leader hears that the coding-agent hook blocked a production change. That is useful, but the protected thing is the customer tenant. The question is whether any identity controlled by that workflow could still change it through another connector or service credential.
Visual: An agent transcript is only one part of the evidence.
2. Authority grows silently.
A developer adds an MCP integration. Operations gives a worker a cloud token. A supervisor can delegate. The original policy file may be unchanged, yet the set of paths from agent to tenant has grown. Nobody gets a warning from the old green log.
Visual: New tools expand the perimeter without changing the old hook.
3. Assign a route owner.
For each consequential action, name the service owner who can enumerate credentials and endpoints. Record which routes were canary-tested, which service checks apply and who reviews a new connector. Use short-lived scoped credentials where available; do not mistake their short lifetime for authorization by itself.
Visual: Track principals, capabilities and recertification triggers.
4. Make the control perimeter explicit.
Ask for a route matrix and a target receipt readback before calling a behavior enforced. Re-run it when tools, workers, service roles or tenant policy change. That small operating discipline protects the customer outcome while agents and their host features evolve.
Visual: Change review begins when authority changes.
Research and claim limits
- OWASP Authorization Cheat Sheet (S229)
- GitHub Actions OIDC (S231)
The examples identified as illustrative or simulated are design probes, not reported incidents. Vendor specifications do not establish workload performance.