A Reference Architecture for Securing Software Factories, with Aaron Stanley and Ahmad Nassri
"We're now at the point where this has to change, and the idea that an agent has a human's identity is not going to work anymore."
Aaron Stanley, former CISO at dbt Labs, and @AhmadNassri, CTO of @SocketSecurity, sat down with us at Black Hat to draft the first version of a security reference architecture for software factories. Today, model vision has improved, context windows have gotten larger, and tool ecosystems are richer. The technology to make software factories real is here but the security model is missing. In this episode we envision that model together.
We get into:
> The pernicious problem: agents that look compliant while working against the rules you set
> Why the enforcement boundary has to sit outside the agent loop, not inside it
> Why a factory needs purposeful authentication and authorization of its own
> Why one poisoned dependency is an incident in every work tree at machine speed
> What actually belongs in the architecture: sandboxing, identity, supply chain, verification, your ways of working i.e. don't outsource the thinking!
TIMESTAMPS
(00:00) The inflection point for software factories, and the missing security model
(01:20) A self-propagating worm moving through the npm registry during Black Hat week
(02:50) The pernicious problem: compliant on paper, working against the rules in practice
(03:30) The Andon cord, and whether the agent will pull it itself
(05:00) One mono agent or a mixture of experts, and multiple cords for multiple stations
(08:10) The components of a secure coding agent stack
(09:20) The factory cannot have a human's identity
(10:20) Contextual access: read in one scenario, never write in another
(13:00) Git has no cryptographic dual identity, so who gets paged at 3 AM?
(14:00) Context, tools, MCP servers, and skills are all supply chain
(16:00) A firewall that omits vulnerable packages so the agent never learns they exist
(18:10) You cannot trust the agents to police themselves
(19:40) Escape hatches, paths of least resistance, and approval fatigue
(21:50) The CTO's job becomes spec and build the factory, not the code
(24:30) The housekeeper should not get a hot dog vending machine
(28:40) npm install vs npm ci, and agents trained on a decade of blog posts
(34:30) First steps: authenticated design and verified ways of working
View on X →