Three Architectures, One Box

Status: Analysis / SACR, CrowdStrike and OpenAI, October 2026

Software Analyst Cyber Research (1 October 2026), CrowdStrike at Fal.Con (1 September 2026), OpenAI’s Defense Factory (October 2026)


CISO Perspective: An analyst, the largest endpoint vendor and the largest lab each published an architecture for securing AI agents in the same week, without seeing each other’s drafts. All three draw the same box in the same place: a check on the agent’s action before it runs, with the decision recorded, and the agent kept away from its own controls. What they argue about is where the check sits and who owns it. Before buying any of them, ask whether the check holds on the retry and whether the misses are published.

Three documents landed in the same week at the start of October. Each came from a different corner of the industry, and each drew a picture of how an enterprise should secure AI agents. None of the three authors had seen the others’ drafts. All three drew the same box in the same place.

The first was a research piece. On 1 October, Francis Odum at Software Analyst Cyber Research published “The Three Platform Shifts Reshaping Cybersecurity,” his read of what CrowdStrike and OpenAI had shown in September. The second was the vendor behind half of it. On 1 September at Fal.Con, CrowdStrike launched Falcon Guardian and, with it, a category map it calls AI Detection and Response. The third was the lab. OpenAI published its Defense Factory, the operation it uses to run security agents against its own code, with a diagram of the network it built to keep those agents in line.

Each one, in its own words.

Three stacks side by side, SACR, CrowdStrike and OpenAI, with the check on the action and the audit record highlighted in each
Three architectures, one box. Redrawn in words from the three documents; their drawings are theirs.

The analyst's map

Odum’s piece says the old categories are collapsing into three shifts. The one that matters for anyone running agents is the one he labels Enterprise Agent Security, and the subtitle under it is the best six words in the piece: “from access control to delegated-action control.”

Twenty-five years of security spend went into deciding who gets in. The agent passes every one of those checks, because it holds a real credential. The question moves to what it is allowed to do once inside, action by action.

Under that heading he draws six boxes: agent discovery and inventory, identity and delegation, policy and runtime controls, data and tool governance, infrastructure and environment, and audit, attestation and ownership. The arrow leaving the band carries the enforced policy down to the security operations center below it.

Near the end he shows a second drawing, a converged architecture he calls UADP v2. Five planes of context feed a shared decision layer. That layer pushes a decision to the point where the agent is about to act. The last box on the page, the one everything flows into, is labeled ARISE. Its job, in his words: “Validate intercepted agent action: allow, step-up, deny, pause, contain.”

His principle for the whole thing sits in a heading of its own: “Never let the agent be its own control plane.” The body under it is plainer still: “An agent can be allowed to reason and act, but it should not control its own permissions, credentials, or audit trail.”

The vendor's map

CrowdStrike’s version came a month earlier, with a product attached. George Kurtz put the argument in one paragraph at Fal.Con: “CrowdStrike pioneered EDR by making the endpoint the control point for stopping attacks. AI demands the same approach. AI hasn’t changed the attack, it has changed its speed. Governance alone can’t stop an agent already in motion. Falcon Guardian turns policy into protection, stopping threats where AI agents execute and before they can cause harm.”

The category slide behind the launch lists the parts of an AI estate it covers: data, models, prompts, agents, identities, infrastructure, interactions. Above them sits what CrowdStrike calls an AI control plane with four parts: identity, data protection, execution and remediation. Execution is a plane of its own. Under governance sit authorization and audit logs. The slide ends on three design principles: “Runtime, Not Posture.” “Unified, Not Point.” “Action Oriented.”

Take the product name off and read the principles again. The check happens at runtime, not in a posture report. The unit is the action.

The lab's map

OpenAI’s Defense Factory page is about something different on its face: a continuous operation that finds and fixes vulnerabilities in OpenAI’s own code, run by agents. The diagram of the network those agents live in is the part worth reading, because it shows what the lab built to keep its own agents from doing harm.

The control plane has three boxes: workload orchestration, policy enforcement and a credential proxy. The agents hold no credentials of their own. They borrow them, scoped, for the task in front of them. Every container carries an environment identity and a host monitoring agent. Across the whole system runs a layer the page calls security and audit, with three parts: host activity, infrastructure security, and agent audit.

The page says what the people do: “People review consequential changes and independently verify deployed fixes.” Greg Brockman’s essay from August, “The Defender’s Window,” says it another way. He describes systems “that require multiple independent controls to fail simultaneously for something catastrophic to occur,” with automated responses that are “bounded” and humans “responsible for the highest-impact decisions.”

What the three agree on

Put the three drawings side by side and the overlap is hard to miss.

The unit of control is the action, not the prompt and not the login. SACR says delegated-action control. CrowdStrike says action oriented. OpenAI puts policy enforcement in front of every workload.

The check comes before the action runs. ARISE validates the “intercepted” action. Kurtz says “before they can cause harm.” OpenAI’s agents cannot reach a credential the proxy has not handed them.

The decision is recorded. Audit, attestation and ownership in one drawing; audit logs in the second; agent audit in the third.

People set the policy and take the consequential calls. All three say it in nearly the same words: set policy, approve consequential actions, handle exceptions.

And one more, easy to miss. All three keep the agent away from its own controls. It does not hold its permissions, write its audit trail or approve its own actions. SACR’s heading says never. OpenAI’s proxy enforces it. CrowdStrike puts the enforcement on the endpoint, outside the agent’s reach.

Table: what SACR, CrowdStrike, OpenAI and Mountain Theory each call the check on the action, what it decides and what is kept
The same box, four vocabularies.

What they argue about

Where the check sits. CrowdStrike says the endpoint, because that is where the agent executes and where CrowdStrike already lives. SACR draws three insertion points and a shared decision layer above them, because an analyst does not have to pick. OpenAI puts it in the control plane of its own private network, because it owns the whole stack.

Who owns it. A platform vendor says the platform. A lab says its own engineering. An analyst draws a fabric any of them could plug into.

Those arguments will run for years, and a buyer does not have to settle them. A buyer has to ask two questions of whoever is selling the box.

The two questions

Two cards: does the check hold on the second try, and are the misses published

Does the check hold on the second try? A blocked agent does what agents do: it looks for another route. In July, Sysdig watched an agent write six scripts in five minutes and 24 seconds to get past its own failures. A check that stops the first attempt and not the retry is a speed bump. Ask to see the retry blocked, and the workaround after it.

Are the misses published? Every one of these architectures will catch most things. The question is what each one lets through, and whether the vendor will show you. Ask for the test protocol and the recorded run. If the answer is a slide, that is the answer.

We built the box the three of them drew: a check between an AI agent’s decision and its execution, against rules written in plain English, with the decision logged. We published the protocol and the runs, including the ones we missed. Ask every vendor in all three diagrams for the same.

The model still decides. The action does not run until it has been checked.

Dates and credit

Francis Odum and Software Analyst Cyber Research, “The Three Platform Shifts Reshaping Cybersecurity: Lessons From CrowdStrike & OpenAI,” 1 October 2026. The three-shift architecture, the converging operating model and the UADP v2 drawing are SACR’s.

CrowdStrike, “CrowdStrike Unveils Falcon Guardian to Secure AI Agents Where They Execute: On the Endpoint at Runtime,” press release, Austin and Las Vegas, 1 September 2026; the AIDR category architecture slide from Fal.Con 2026; the Falcon Guardian data sheet. George Kurtz is CrowdStrike’s CEO and founder.

OpenAI, “Defense Factory,” openai.com, October 2026, including the private network diagram and the five-step defensive loop; Greg Brockman, “The Defender’s Window,” 17 August 2026.

Sysdig, Michael Clark, “JADEPUFFER evolves,” 20 July 2026, for the six scripts in five minutes and 24 seconds.

Mountain Theory’s published runs and the Recorded Run Protocol: mountaintheory.ai/proof.

Scroll to Top