Welcome. Short version of why this exists. Almost every AI feature running in production today is authenticating with one shared key that has far more rights than it needs, and almost everyone shipping those features knows it. Not because anyone is careless, but because identity never had a model for a caller that borrows a person's authority and then decides for itself what to do next. Nobody has published a good answer to that yet. So this room is for working it out with people who have to defend it in front of an auditor rather than argue about it online. What gets posted here is practical. Architecture teardowns, delegation and scoping patterns, tenant isolation failures and how they actually happen, model deployment tradeoffs, and lab builds you can stand up for nothing. Two rules. Nothing goes up from a production environment you do not own, and sanitize whatever you do post. Answer questions the way you would want yours answered. To introduce yourself, skip the job title. Post the thing you are building and the part of it you could not currently defend in a security review. That is more useful to you and to everyone reading.