Skip to main content

Case Studies

Real incidents. Specific enforcement gaps. What each failure reveals about the boundary between AI observation and AI control.

How we use case studies

  • Each entry maps a cited incident report to specific enforcement-gap classes.
  • Tags name the failure mode: credential scope, approval, and audit evidence.
  • Deep analysis is on the blog; this page stays an index.

PocketOS production database deletion in 9 seconds

April 27, 2026

A coding agent handling a staging credential mismatch traversed outside scope, used a privileged Railway token, and deleted production data with backups in one irreversible call. The incident shows enforcement failure at credential scope, approval gating, and pre-execution evidence boundaries.

CREDENTIAL TRAVERSALAPPROVAL GATEAUDIT CHAIN
Read the enforcement analysis

More case studies are added as incidents occur. The pattern is always the same: observation without enforcement.

Need to evaluate your audit posture?

We work with platform engineers and compliance teams to identify where observation ends and enforcement must begin.