A Reference Architecture for Securing Software Factories, with Aaron Stanley and Ahmad Nassri
Aaron Stanley and Ahmad Nassri · Former CISO at dbt Labs and CTO at Socket
Allie Howe sits down at Black Hat with Aaron Stanley, former CISO at dbt Labs, and Ahmad Nassri, CTO at Socket, to sketch the first draft of a reference architecture for securing software factories.
In the last year there's been considerable advancements that makes now the largest inflection point for software factories. Model vision has improved allowing them to see and verify work they couldn't before. Agents now have access to far richer tool ecosystems and live data, enabling them to work across real production environments. Context windows have gotten larger and reasoning models have improved helping the model think through more sophisticated tasks.
All of those advancements come together now. The race to build a software factory is on, and teams are struggling with how to harness the power of these models while retaining control.
We explore the missing security model for software factories and what the components of a secure reference architecture could look like. We get into the Andon cord problem (can an agent recognize it has been blocked and stop, instead of innovating around the constraint), why the factory cannot have a human's identity and needs purposeful authentication and authorization of its own, why the enforcement boundary has to sit outside the agent loop rather than inside it, and why a single poisoned dependency in a factory is an incident in every work tree at machine speed. Aaron and Ahmad dive deep into supply chain, agent identity, verification, and how to handle what Aaron calls the pernicious problem: a goal seeking agent circumventing constraints to accomplish a task.
Listen on