Desmond Okafor-Hale
Structural analyst of incentives. Argues that most control failures are organisational choices wearing technical costumes, and names the choice.
Posts by Desmond
Intelligence cannot mint permission
Give an agent an API key and it inherits ambient authority. Prompt injection, a hallucination loop or an ordinary bug then executes consequential actions with no record b
Detection vendors are writing their own obituary, accurately
Bot defence rests on distinguishing automated traffic from human traffic by observation. The observable differences are disappearing, and the vendors say so on their own
Eighty machine identities per human, and not one has a signature behind it
NHI programmes start with discovery and end with a spreadsheet of thousands of identities whose owner field contains a team name, a departed employee, or nothing. Rotatio
Scope-blind tool approvals: approving a server is not approving its actions
Developers approve tool servers by name. A vulnerability class reported in AI-enabled editors during 2025 showed what a blanket approval covers: whatever the server'
The 'my agent did it' defence: disputing commitments nobody authorised
Contract law has well-developed doctrines for when a principal is bound by an agent's acts. Those doctrines assume an agent who can be examined, instructed and held
Payment envelopes versus rendered statements: two models of agent intent
Selective-disclosure JWTs bound what an agent may spend. They are well designed for that and they do not generalise to actions that are not payments — which is most of wh
Prior authorization by model: evidencing the clinician who denied the care
State rules and plan terms require a qualified clinician to make adverse determinations. The record is a case row with a reviewer name and a timestamp, and where review t
The letter of authorization: how client money leaves a custodian on a scanned signature
Standing letters of authorization are the dominant mechanism for third-party disbursements from advisory accounts. Neither the custodian nor the adviser can demonstrate t
Ninety-one percent of leaked secrets still work five days later
Security programmes measure rotation cadence. Attackers measure time-to-exploit, which is minutes. The gap between exposure and revocation is where every credential-drive
Black start, storm restoration, and the identity provider you cannot reach
Emergency procedures assume degraded conditions everywhere except identity. When single sign-on is unreachable, utilities fall back to break-glass accounts with shared pa
Filed under your bar number: the attorney who did not file
Paralegals, docketing clerks and outsourced filing services submit documents using attorneys' e-filing credentials. The record names the attorney. The attorney may n
Just-in-time elevation issues a credential, not a control
Privileged access management narrowed the window in which administrative power exists. Inside that window it is still unrestricted, and the window is usually hours long.
Behavioural biometrics cannot tell tired from impostor
Typing rhythm and mouse movement vary with fatigue, injury, hardware and mood. A model trained to spot deviation flags all of those, and misses a patient operative who ha
Proving out-of-band verification when the claim is filed
Funds transfer fraud cover typically requires verification through a second channel. Proving it happened, months later, from phone notes and memory, is where claims stall
A 1.2% click rate and a seven-figure wire out the door
Phishing simulation measures whether people click suspicious links. Executive impersonation does not involve a link, and the metric does not extend to it.
Anchoring a fraud investigation to something the attacker could not edit
Forensic reconstruction depends on logs from systems the attacker was inside. Every finding inherits that weakness, and opposing counsel knows it.
A hardware wallet protects the key, not the decision
The security model of a hardware signer is key isolation. Understanding a complex contract call is a different problem that a constrained device is not built to solve.
The dispatch release and the MEL deferral: two signatures that decide whether a flight is legal
Under domestic operating rules the captain and the dispatcher jointly exercise operational control, and an MEL deferral makes an otherwise unairworthy aircraft legal to f
A signed PDF and an action receipt are not the same artefact
Document signature frameworks were built for agreements people read. API execution needs something a machine can verify against a structured payload, in milliseconds, at
First notice of loss to payout: claimant identity across the claims lifecycle
Claims payments are directed to details captured during a phone call or portal session, often by temporary catastrophe staff, and paid quickly by design. Speed is a compe
Proctoring detects; it does not prove: assessment integrity without surveillance
Remote proctoring collects video, room scans and behavioural telemetry to guess whether the right person is working alone. It is invasive, litigated, and still produces a
Engineering release and configuration control: the drawing that went to production unapproved
A revision release authorises manufacture. The approval record is a PLM workflow state naming a user, and delegation during absence is universal and undocumented.
Inventory adjustments and release overrides: computing the gating threshold
Warehouse systems grant override and adjustment rights broadly because operations demand it. The question is not whether to gate them but above what value — and that is a