Cloud SQL: database location does not finish the security review
Regional administrative API endpoints raise an architecture question: where do the operations that manage your data travel?
Read article ↗Selected news and practical analysis on cloud, identity, DevSecOps and AI security.
Explore the 50-article collection ↓
Regional administrative API endpoints raise an architecture question: where do the operations that manage your data travel?
Read article ↗The agent security debate calls for a concrete architecture decision: which changes may an agent execute without approval?
Read article ↗Content produced with AI assistance for Thiago Silva’s website. Independent editorial analysis; it does not represent clients or employers.
50 short articles on architecture decisions, identity, APIs, DevSecOps, cloud and AI security. A January–September editorial reading path to explore by topic.
Collection published on September 12, 2026. Months organize the reading path; they are not earlier publication dates.
Clear responsibilities prevent ownerless permissions.
Read article ↗Reviewing only the main application misses integrations.
Read article ↗Device changes and recovery also establish trust.
Read article ↗A user role alone does not explain resource access.
Read article ↗Building code and authorizing production are different decisions.
Read article ↗A sustainable policy needs script owners.
Read article ↗Risk depends on how the browser sends session authority.
Read article ↗Application encryption changes exposure boundaries and operations.
Read article ↗A shared credential hides distinct operational decisions.
Read article ↗Request counts can hide large differences in work.
Read article ↗Inventory must connect to running software.
Read article ↗An approved image still depends on deployment permissions.
Read article ↗Public responses and internal diagnostics serve different audiences.
Read article ↗Model states between ingestion, inspection and use.
Read article ↗An exceptional procedure can redefine trust.
Read article ↗Pipeline dependencies deserve code-level scrutiny.
Read article ↗CDN, proxy and application may produce different settings.
Read article ↗Repositories represent environments only when differences are reconciled.
Read article ↗Rules must understand the operation's domain.
Read article ↗Knowing an identifier is not authorization evidence.
Read article ↗Each consumer must know which tokens it may accept.
Read article ↗Changing the active key does not end historical dependencies.
Read article ↗Boundaries must account for shared resources.
Read article ↗External documents may inform answers without granting permissions.
Read article ↗Event volume is not investigation capability.
Read article ↗An agent's tool catalog needs governance.
Read article ↗Technical identity alone does not explain the user's request.
Read article ↗Correct database and API controls cannot fix ambiguous cache keys.
Read article ↗High coverage can conceal important alternative paths.
Read article ↗Connection destinations are part of the exposure boundary.
Read article ↗Mobile apps, browsers and backends have different boundaries.
Read article ↗Changing the standard does not update every account.
Read article ↗Flexible filters need a bounded contract.
Read article ↗Removing source access may leave usable copies.
Read article ↗Individually correct endpoints can form an incorrect workflow.
Read article ↗Integrations must survive certificate changes.
Read article ↗Central storage does not replace rehearsed revocation.
Read article ↗Behavior depends on more than the model file.
Read article ↗Assign ownership for each control.
Read article ↗Diff size does not measure security impact.
Read article ↗Generation speed does not replace behavioral understanding.
Read article ↗The easiest path often determines actual behavior.
Read article ↗The feature needs destination and behavior boundaries.
Read article ↗Logout becomes distributed across multiple consumers.
Read article ↗Rebuilding at the last step can change the trust unit.
Read article ↗Useful diagrams connect threats to actions and owners.
Read article ↗Users should authorize the parameters producing the effect.
Read article ↗The browser padlock describes only part of the architecture.
Read article ↗Minimization starts before storage protection choices.
Read article ↗Component severity is an input, not the whole context.
Read article ↗Get new articles in your RSS reader. Copy the feed address and add it to Feedly, Inoreader or another reader.