Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Project Perception and green-team security: what changes for IAM teams?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 12518
Topic starter  

TL;DR: Microsoft’s security post argues that the next generation of defence will depend less on alert generation and more on validated corrective action, with blue agents investigating risk and green agents fixing it across a six-layer stack. The implication is clear: security programmes that stop at detection will keep producing backlog, not resilience.

NHIMG editorial — based on content published by Senserva: Rethinking security for the age of AI

Questions worth separating out

Q: How should security teams separate detection from remediation in AI-assisted security operations?

A: Separate them by design and governance, not just by team name.

Q: Why does context matter so much in agentic security systems?

A: Because agents cannot make reliable decisions from partial telemetry.

Q: What do security teams get wrong about AI-powered remediation for NHIs?

A: Teams often assume that faster remediation is automatically safer.

Practitioner guidance

  • Define a green-team approval model Map which remediation actions can be executed only after human validation, which can be pre-authorised, and which must always remain manual.
  • Unify the context sources your security decisions depend on Join identity configuration, patch state, vulnerability data, and logs before feeding prioritisation or remediation logic.
  • Treat remediation as a privileged workflow Apply auditability, rollback, and change control to every automated or AI-assisted fix.

What's in the full article

Senserva's full post covers the operational detail this post intentionally leaves for the source:

  • Microsoft’s direct quotations on the red, blue, and green team definitions
  • The six-layer stack description linking signals, context, models, harness, agents, and actuators
  • Senserva’s own implementation perspective on how blue and green functions share one operational model
  • The source article’s mapping of remediation output to Microsoft security benchmarks, NIST, CIS, SOC 2, and HIPAA

👉 Read Senserva's analysis of Microsoft's agentic security architecture →

Project Perception and green-team security: what changes for IAM teams?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 12102
 

Green-team security is the overdue correction to alert-first security operations. For decades, the industry optimised for discovery and investigation, then pushed remediation into separate queues that rarely had enough context to act quickly. Microsoft’s framing is useful because it recognises that finding risk is not the same as closing it. Practitioners should treat remediation as a first-class security function, not a downstream operational courtesy.

A question worth separating out:

Q: Who is accountable when an AI system changes infrastructure configuration?

A: Accountability should sit with the programme owner responsible for the AI system and the change governance process that approved its operating scope. If the system can alter configuration, then the access model, logging model, and change approval model all need explicit ownership, otherwise responsibility becomes distributed until no one can defend the outcome.

👉 Read our full editorial: Project Perception shifts security from findings to remediation



   
ReplyQuote
Share: