Agentic Thoughts

Ideas for governing AI-assisted software delivery.

Practical explorations of architecture models, policy decisions, requirements and implementation guidance for teams building with AI coding tools and agents.

Model the intent. Apply the policy. Guide the build. iSecureByDesign helps apply configured policies to structured architecture models and produce requirements and guidance. It does not perform a threat model autonomously.

About this series: Agentic Thoughts are AI-assisted explorations of evolving product ideas and real-world applications. They are reviewed for direction and clarity, but do not necessarily describe committed features or formal advice.

Where to begin

Three useful entry points

28 explorations

Tool-specific examples

AI coding governance

9

How Do You Govern AI Coding Assistants?

A practical approach to governing GitHub Copilot, Cursor and other AI coding assistants with architecture context and reviewable controls.

What Is AI Coding Tool Policy Management?

AI coding tool policy management connects architecture models and security controls to requirements and implementation guidance for coding assistants.

Centralised Policy Management for AI Code Assistants: A Practical Guide

Learn how centralised policy management keeps AI coding guidance consistent, architecture-aware and traceable across repositories and teams.

What Should an AI Coding Tool Policy Include?

Use this AI coding tool policy checklist to cover architecture, data access, permissions, security controls, review evidence and evaluation.

AI Coding Assistant Governance: Governing GitHub Copilot, Cursor and Similar Tools

How teams can govern GitHub Copilot, Cursor and other AI coding assistants with architecture context, security constraints and review expectations.

AI Coding Rules, Steering Files and Repository Instructions: What's the Difference?

Understand the difference between AI coding rules, steering files, Cursor rules, Copilot instructions and repository guidance.

Centralised Policy Management for AI Coding Assistants

How centralised policy management keeps AI coding guidance connected to architecture instead of scattered across prompts, repositories and review checklists.

AWS Kiro Steering Files: From Architecture Models to Agent Guidance

Explore how architecture models and policy controls can provide project-specific context for AWS Kiro steering files without replacing requirements or organisational governance.

How to Generate Steering Files for AI Coding Tools from Architecture Models

Learn how architecture models, policy controls and specification blocks can produce focused steering files for AI coding tools such as Kiro, Cursor and Copilot.

Architecture and secure-by-design

9

How Do Architecture Models Become AI Coding Requirements?

How architecture models can become policy-backed AI coding requirements through components, controls, specifications and evaluation criteria.

OWASP Secure-by-Design Framework vs Architecture-Linked Requirements

Compare the OWASP Secure-by-Design Framework with system-specific architecture requirements for AI-assisted software development.

What Does Secure-by-Design Architecture Mean?

Secure-by-design architecture explained: how security analysis, controls and requirements can influence architecture before implementation begins.

What Does a Secure-by-Design Policy for AI-Assisted Software Development Include?

A practical structure for secure-by-design policies that connect architecture, security objectives, controls, AI coding guidance and evaluation.

How to Create Architecture-Aware Rules for GitHub Copilot and Cursor

How to create architecture-aware rules for GitHub Copilot and Cursor from system components, security objectives, policies and implementation constraints.

Architecture Constraints for AI Coding Tools

How architecture and security constraints can guide AI coding tools toward approved boundaries, controls and implementation patterns.

How to Turn an Architecture Diagram into AI Coding Requirements

How to turn an architecture diagram into requirements and implementation guidance that AI coding tools can use and teams can review.

What Does a Secure-by-Design Policy for AI-Assisted Software Development Look Like?

See what a secure-by-design policy for AI-assisted development can include, from architecture objectives and controls to testable implementation requirements.

Secure-by-Design Requirements for AI-Generated Code

How system-specific security requirements help teams guide and evaluate AI-generated code beyond generic secure coding prompts.

Agent control and containment

10

Your AI Coding Agent Has Requirements. But Who Is Steering It?

Why AI coding agents need both architecture-derived requirements and persistent steering instructions to build software within the intended security boundaries.

Can AI Agents Escape Isolated Environments?

What reported AI-agent containment incidents suggest about sandbox design, layered controls and evaluating agent access before production use.

How to Control AI Agent Network Access

How to define and review network egress, approved services, package sources and external actions for AI agents.

How to Evaluate AI Agent Containment Before Production

How to test AI-agent containment with explicit boundaries, failure cases, monitoring evidence and repeatable evaluation criteria.

How to Threat Model an AI Agent Sandbox Escape

A practical approach to threat modelling AI agents, sandbox boundaries, network paths, credentials and connected tools before deployment.

Least Privilege for AI Agents: Tools, Credentials and Data

How to apply least privilege to AI agents by modelling tools, credentials, data stores, actions and approval boundaries.

What Access Should an AI Agent Have?

A practical least-privilege framework for deciding which files, tools, credentials, data and actions an AI agent should access.

What Does an AI Agent Sandbox Need to Protect?

How teams can use architecture models and policy controls to define what an AI agent sandbox must isolate, monitor and prevent.

Why AI Agent Isolation Is Not Enough

Why secure AI-agent design needs layered controls for identity, tools, network access, monitoring and recovery in addition to isolation.

How to Create GitLab Duo Agent Configuration YAML from Architecture Models

Learn how to turn architecture and security controls into GitLab Duo agent-config.yml settings for flow execution and network access.