<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Olivares AI — Blog</title><description>Technical writing on operating AI agents safely: access mapping, least-privilege drift, auditing Claude Code and MCP, and self-hosted governance.</description><link>https://olivares.ai</link><language>en</language><item><title>Audit evidence a verifier can check offline</title><link>https://olivares.ai/blog/audit-evidence-offline-verification</link><guid isPermaLink="true">https://olivares.ai/blog/audit-evidence-offline-verification</guid><description>How a hash-chained ledger with per-event Ed25519 signatures and OSCAL export produces audit evidence an external verifier can confirm independently.</description><pubDate>Sat, 11 Jul 2026 00:00:00 GMT</pubDate><category>audit</category><category>ledger</category><category>OSCAL</category><category>Ed25519</category><category>compliance</category></item><item><title>Governing MCP servers with RFC 9728 and RFC 8707 — what actually works</title><link>https://olivares.ai/blog/governing-mcp-servers-rfc-9728-8707</link><guid isPermaLink="true">https://olivares.ai/blog/governing-mcp-servers-rfc-9728-8707</guid><description>Trace the OAuth 2.1 flow MCP mandates after a protected server returns 401, what RFC 9728 and RFC 8707 provide, and the security pitfalls.</description><pubDate>Sat, 11 Jul 2026 00:00:00 GMT</pubDate><category>MCP</category><category>RFC 9728</category><category>OAuth</category><category>security</category></item><item><title>Ephemeral credentials for Claude Code with workload identity federation</title><link>https://olivares.ai/blog/ephemeral-credentials-claude-code-workload-identity</link><guid isPermaLink="true">https://olivares.ai/blog/ephemeral-credentials-claude-code-workload-identity</guid><description>Static API keys never expire, share identity, and silently shadow federation. WIF replaces them with attested JWT exchange for short-lived per-session tokens.</description><pubDate>Sat, 11 Jul 2026 00:00:00 GMT</pubDate><category>WIF</category><category>ephemeral-credentials</category><category>Claude Code</category><category>workload-identity</category></item><item><title>Inside the hooks PEP: deny-closed policy inside Claude Code</title><link>https://olivares.ai/blog/hooks-pep-deny-closed-policy-claude-code</link><guid isPermaLink="true">https://olivares.ai/blog/hooks-pep-deny-closed-policy-claude-code</guid><description>How a PEP classifies every Claude Code hook event into gating, context, or observe, wires the correct output schema per event, and deny-closes unknown events.</description><pubDate>Sat, 11 Jul 2026 00:00:00 GMT</pubDate><category>Claude Code</category><category>hooks</category><category>policy-as-code</category><category>deny-closed</category></item><item><title>Permitted vs observed: drift as a first-class finding</title><link>https://olivares.ai/blog/permitted-vs-observed-drift-finding</link><guid isPermaLink="true">https://olivares.ai/blog/permitted-vs-observed-drift-finding</guid><description>Drift between what an AI agent is permitted to do and what it is observed doing becomes a structured, classified finding with confidence levels.</description><pubDate>Sat, 11 Jul 2026 00:00:00 GMT</pubDate><category>least-privilege</category><category>drift</category><category>access-map</category><category>observability</category></item><item><title>Self-hosted governance next to the Claude apps gateway: a co-deployment guide</title><link>https://olivares.ai/blog/self-hosted-claude-apps-gateway-co-deployment</link><guid isPermaLink="true">https://olivares.ai/blog/self-hosted-claude-apps-gateway-co-deployment</guid><description>Anthropic&apos;s apps gateway handles OIDC auth for Claude. Your estate is more than Claude. This is the co-deployment architecture that governs both paths.</description><pubDate>Sat, 11 Jul 2026 00:00:00 GMT</pubDate><category>self-hosted</category><category>Claude</category><category>co-deployment</category><category>architecture</category></item><item><title>What your AI agents can actually reach: mapping agent access on real infrastructure</title><link>https://olivares.ai/blog/map-what-your-ai-agents-can-reach</link><guid isPermaLink="true">https://olivares.ai/blog/map-what-your-ai-agents-can-reach</guid><description>An AI agent holds credentials, is permitted some actions, and is observed doing others. The access map shows the gap — and where least-privilege quietly broke.</description><pubDate>Fri, 05 Jun 2026 00:00:00 GMT</pubDate><category>agent-access</category><category>least-privilege</category><category>observability</category><category>audit</category></item><item><title>Auditing Claude Code and MCP servers in self-hosted environments</title><link>https://olivares.ai/blog/auditing-claude-code-and-mcp-self-hosted</link><guid isPermaLink="true">https://olivares.ai/blog/auditing-claude-code-and-mcp-self-hosted</guid><description>Build an auditor-grade trail for Claude Code and MCP servers without leaving your perimeter: per-agent identity, a hash-chained ledger, untrusted MCP signals.</description><pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate><category>MCP</category><category>Claude Code</category><category>audit</category><category>self-hosted</category></item><item><title>Least-privilege drift: catching over-privileged AI agents before an incident</title><link>https://olivares.ai/blog/least-privilege-drift-for-ai-agents</link><guid isPermaLink="true">https://olivares.ai/blog/least-privilege-drift-for-ai-agents</guid><description>How to spot least-privilege drift in AI agents by comparing permitted access with observed behavior and enforcing policy at access time.</description><pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate><category>least-privilege</category><category>ai-agents</category><category>policy-as-code</category><category>audit</category></item><item><title>Self-hosted AI governance and data residency: the strongest GDPR story</title><link>https://olivares.ai/blog/self-hosted-ai-governance-data-residency-gdpr</link><guid isPermaLink="true">https://olivares.ai/blog/self-hosted-ai-governance-data-residency-gdpr</guid><description>Why self-hosting an AI platform is the strongest data-residency posture under GDPR: the governance tool never receives your data. Edges, not payloads.</description><pubDate>Wed, 13 May 2026 00:00:00 GMT</pubDate><category>data-residency</category><category>gdpr</category><category>self-hosted</category><category>ai-governance</category></item><item><title>Passive discovery vs proxies: inventorying AI agents without sitting in the data path</title><link>https://olivares.ai/blog/passive-discovery-vs-proxies-ai-agents</link><guid isPermaLink="true">https://olivares.ai/blog/passive-discovery-vs-proxies-ai-agents</guid><description>Two ways to see your AI agents: an inline proxy with high blast radius, or passive discovery from logs, OpenTelemetry and an eBPF backstop. An honest tradeoff.</description><pubDate>Wed, 06 May 2026 00:00:00 GMT</pubDate><category>passive-discovery</category><category>observability</category><category>eBPF</category><category>least-privilege</category></item></channel></rss>