What I Learned Building an Identity Broker With Coding Agents
Lessons from 10 months of building the open-source Agentic Identity Broker with coding agents: Spec Kit, tests that tested nothing, 6 harness switches, and review.
Lessons from 10 months of building the open-source Agentic Identity Broker with coding agents: Spec Kit, tests that tested nothing, 6 harness switches, and review.
My HTW Berlin guest lecture explains why agentic engineering moves AppSec toward harness design, platform constraints, and measurable risk.
Agentic engineering amplifies architectural entropy at machine speed. The answer is not more security gates but fewer decisions: shift security down into platforms.
Automatic dependency updates spread compromised packages faster than humans can react. Version pinning, provenance verification, and repository proxies turn blind trust into controlled trust.
How AppSec teams can keep up with coding agents: fix findings inside the agent loop, ship security tooling to agents, and manage risk with SRE and platform teams.