GGOLEMby DevOps Lab
OCTOBER 13, 2026 RELEASE · PR #170 / commit 894c8f37 · 100-function launch rubric · GA gated on verified release evidence
Customer-owned security at machine speed

Own the graph.
Own the response.

Golem unifies cloud posture, identity, code, software supply chain, data, Kubernetes and host runtime, external attack surface, network posture, Active Directory, AI-SPM and agent security in one inspectable platform — deployed in your environment with source code, Terraform, APIs and your choice of AI.

Your cloud · Your graph · Your policies · Your AI · Your data
GOLEM // AGENTGUARD + SECURITY GRAPHLIVE
Tool action reached a protected path
AGENT → MCP TOOL → CLOUD IDENTITY → CLASSIFIED DATA
TOOL_DESCRIPTORTrusted tool baseline digest verified
Verified
SENSITIVE_REACHGraph resolves classified-data reach
Review
EXACT_CALL_APPROVALHuman approval bound to exact arguments digest
Signed
POLICY: DETERMINISTICEVIDENCE: HMAC-SIGNED
100functions in the locked release rubric
12registered code / IaC scanners
96.8%project-reported backend test coverage
Oct 13release target, gated on verification
Release candidate
OCT 13
2026

The October 13 release is organized around one rule: capability claims must be backed by code and evidence. The launch plan targets 99–100 depth across supported launch practices, with 100 reserved for functions that pass their release tests and end-to-end proof.

PR #170 milestone

Azure CIEM is now a first-class graph.

  • Real Azure RBAC role-assignment graph nodes and scope relationships.
  • Owner, User Access Administrator, Contributor and custom-privileged-role findings.
  • Control-plane and data-plane wildcard privilege detection.
  • Service-principal and managed-identity privilege analysis.
  • Cross-subscription reach and group-inherited escalation paths.
  • Transitive Entra group-membership collection and shared admin-equivalence logic.
01 // Complete capability atlas

100 functions. One graph.

Every function below is part of the locked release rubric. “Current” means the capability exists in the codebase; “Release hardening” means the capability exists and is being deepened or validated for launch; “October 13 gate” means it is a required launch-track item planned before GA.

CurrentRelease hardeningOctober 13 gate
Platform architecture10 functions
  1. 01Customer-owned deployment / data planeCurrent
  2. 02Customer-owned security graph / storageCurrent
  3. 03Source delivered and customizableCurrent
  4. 04Bring-your-own AI / LLM providerCurrent
  5. 05Multi-cloud breadthRelease hardening
  6. 06Hybrid / on-prem supportCurrent
  7. 07API-first automationCurrent
  8. 08RBAC / SSOCurrent
  9. 09Audit / evidence loggingCurrent
  10. 10Enterprise scale / operational maturityOctober 13 gate
CSPM & compliance10 functions
  1. 11Cloud inventoryCurrent
  2. 12AWS CSPMCurrent
  3. 13Azure CSPMCurrent
  4. 14GCP CSPMCurrent
  5. 15OCI / Alibaba / additional providersRelease hardening
  6. 16Kubernetes Security Posture Management (KSPM)Current
  7. 17Compliance framework breadthCurrent
  8. 18Compliance evidenceCurrent
  9. 19Scheduled posture scanningRelease hardening
  10. 20Graph drift / historyCurrent
Identity & graph10 functions
  1. 21Cloud Infrastructure Entitlement Management (CIEM)Release hardening
  2. 22Effective permissionsRelease hardening
  3. 23Unused / excessive permissionsRelease hardening
  4. 24AWS trust graphCurrent
  5. 25Azure / GCP impersonationRelease hardening
  6. 26Privilege escalation discoveryCurrent
  7. 27Privilege risk / blast-radius scoringCurrent
  8. 28Security Graph breadthCurrent
  9. 29General graph reachabilityCurrent
  10. 30Toxic combinations / attack pathsCurrent
DSPM & data security10 functions
  1. 31Native-cloud DSPMCurrent
  2. 32Snowflake DSPMCurrent
  3. 33Databricks DSPMCurrent
  4. 34Salesforce DSPMCurrent
  5. 35SharePoint DSPMCurrent
  6. 36Google Drive DSPMCurrent
  7. 37Sensitive-data graphCurrent
  8. 38Data-access governanceRelease hardening
  9. 39Data Detection & Response (DDR)Current
  10. 40Cross-platform identity / data correlationOctober 13 gate
AppSec & supply chain10 functions
  1. 41Native SASTCurrent
  2. 42Software Composition Analysis (SCA)Current
  3. 43Secrets scanningCurrent
  4. 44Infrastructure-as-Code securityCurrent
  5. 45DAST / active application testingRelease hardening
  6. 46SBOM generationCurrent
  7. 47OSS license governanceRelease hardening
  8. 48Container image scanningCurrent
  9. 49Cosign / expected signerCurrent
  10. 50SLSA / deployment provenance enforcementCurrent
Developer & CI/CD10 functions
  1. 51GitHub repository / organization securityCurrent
  2. 52Bitbucket securityCurrent
  3. 53Native GitLab connectorOctober 13 gate
  4. 54CI/CD discovery / postureCurrent
  5. 55Webhook / event ingestionCurrent
  6. 56Build / deployment gatesCurrent
  7. 57PR / IDE feedback / remediationRelease hardening
  8. 58Code-to-cloud correlationCurrent
  9. 59Repository → pipeline → artifact → image graphCurrent
  10. 60CI/CD identity / tool governanceRelease hardening
Runtime & response10 functions
  1. 61Linux / Kubernetes runtimeCurrent
  2. 62VM runtimeRelease hardening
  3. 63Windows runtimeOctober 13 gate
  4. 64Serverless runtimeRelease hardening
  5. 65Drift / File Integrity Monitoring (FIM)Current
  6. 66Process detectionCurrent
  7. 67Network behaviorCurrent
  8. 68Kubernetes isolationCurrent
  9. 69Cloud IAM revoke / responseCurrent
  10. 70Host compliance / threat correlationCurrent
Detection & response10 functions
  1. 71Cloud threat-log ingestionCurrent
  2. 72AWS CloudTrailCurrent
  3. 73Azure / GCP activity logsCurrent
  4. 74Splunk integrationCurrent
  5. 75Datadog integrationCurrent
  6. 76Identity Threat Detection & Response (ITDR)Release hardening
  7. 77Exploit Prediction Scoring System (EPSS)Current
  8. 78CISA Known Exploited Vulnerabilities (KEV)Current
  9. 79AI incident triageCurrent
  10. 80Ticketing / alerts / SOARCurrent
External, API & network10 functions
  1. 81EASM subdomain discoveryCurrent
  2. 82Passive exposure intelligenceCurrent
  3. 83Typosquat monitoringCurrent
  4. 84Active external portsCurrent
  5. 85EASM → internal graphCurrent
  6. 86API inventoryRelease hardening
  7. 87API authentication postureCurrent
  8. 88Runtime API / WAAS protectionOctober 13 gate
  9. 89Network Security Posture Management (NSPM)Current
  10. 90Active Directory posture / DCSyncRelease hardening
AI & agent security10 functions
  1. 91AI workload / model inventoryCurrent
  2. 92AI / data / model attack pathsCurrent
  3. 93Shadow AI discoveryCurrent
  4. 94Agent permission / reach graphCurrent
  5. 95AI-agent red teamingCurrent
  6. 96Inline tool-call policyCurrent
  7. 97Prompt / payload injection detectionCurrent
  8. 98Session escalation detectionCurrent
  9. 99Human approval / reviewer trust / kill switchCurrent
  10. 100Signed evidence for gated AI actionsCurrent
02 // Application and supply-chain security

Specialized engines. One evidence model.

Golem does not pretend one scanner can understand every language and attack surface. The platform detects the repository's technology, runs the applicable engines, normalizes results, builds graph relationships and applies exploitability context.

CheckovIaC / cloud policy
BanditPython SAST
SemgrepMulti-language SAST
gosecGo security
SpotBugsJava analysis
ESLint SecurityJavaScript / TypeScript
BrakemanRuby / Rails security
Security Code Scan.NET / C# security
TrivySCA, secrets, images, SBOM
zizmorGitHub Actions security
GLsecGitLab CI security
AI Integration IndicatorsDeterministic AI integration discovery
OWASP ZAPDAST / authorized live testing
FalcoeBPF runtime detection
CosignSignature / signer verification
EPSS + KEVExploit-likelihood and known exploitation

The registered product code/IaC scanner registry contains 12 deterministic scanners. Runtime, DAST, signing and vulnerability-intelligence engines are additional platform components.

03 // AI & agent security

Secure the action — not only the prompt.

Golem's AI-security design treats the model as one component in a larger execution chain. The authorization path stays deterministic: the model can suggest, but policy and human approval decide whether a tool action proceeds.

AgentGuard inline tool-call controlEvery integrated agent can call Golem before executing a tool. Policy can allow, block, monitor or require approval.
Exact-call approval bindingHuman approval is cryptographically tied to the exact agent, session, tool, arguments, destination and resource. Change the call and the approval no longer applies.
MCP / tool descriptor integrityGolem fingerprints the trusted tool description and schema, detects descriptor drift / rug-pull behavior and carries the descriptor digest into signed evidence.
Security-graph reachAgent identity and requested resource can be resolved against privileged roles, code execution and DSPM-classified data rather than evaluated as prompt text alone.
Session escalation + kill switchDetects tool switching after a denial and can terminate a session so later evaluations are blocked.
Signed execution evidenceEvery gated call can produce a signed evidence bundle covering decision, policy, approval, argument digest, trusted descriptor digest and execution result.
AI-agent red teamingAuthorized live testing supports static jailbreaks plus adaptive PAIR, Best-of-N and TAP-style attack strategies with judge-model verdicts.
BYO model / data sovereigntyUse Bedrock, Azure OpenAI, Vertex AI, commercial APIs or a local/private model while keeping the platform, policies and security graph customer-controlled.
04 // Real-world attack patterns

How Golem would help.

These are defensive mappings to publicly reported incidents — not claims that Golem was deployed at either organization or that one product could guarantee prevention.

Hugging Face · July 2026

AI-agent-driven intrusion into data processing.

Hugging Face disclosed that a malicious dataset abused code-execution paths in a data-processing pipeline and that the intrusion was driven end to end by an autonomous AI-agent system.

1 · Code & supply chain: SAST/SCA/secrets/IaC plus provenance can surface dangerous loader/template paths and vulnerable dependencies before deployment.
2 · Runtime: Falco, process/file/network observations and image-to-workload correlation expose what the processing worker actually executes.
3 · Identity & data: CIEM + DSPM graph the worker identity's reachable secrets and classified data.
4 · Agent security: AgentGuard policies, tool reach and exact-call approvals constrain integrated agents that can invoke sensitive tools.
5 · Response & DFIR: isolate/kill/revoke workflows capture pod/node/process/network/DNS evidence before containment and verify the action afterward.
Read Hugging Face's incident disclosure ↗
FBI personnel data breach · September 2026

Protect the path to high-value identity data.

Reuters reported that attackers claimed access to highly sensitive FBI personnel information; Reuters verified portions of leaked material while the FBI investigated the incident.

1 · EASM: CT logs, DNS, passive exposure intelligence and authorized active scanning identify Internet-facing attack surface and shadow assets.
2 · Vulnerability priority: CVE + EPSS + KEV + Internet reachability focus response on vulnerabilities that are both exposed and more likely or known to be exploited.
3 · Identity: CIEM and ITDR correlate privileged access, escalation paths and suspicious authentication behavior.
4 · Sensitive data: DSPM/DDR map sensitive personnel data and unusual access/export behavior into the same graph.
5 · Detection and response: Cloud/log ingestion, SIEM connectors, alerting, tickets and approval-gated response turn correlated evidence into action.
Read Reuters' breach reporting ↗
05 // October 13 release gates

The roadmap is the release checklist.

These are the planned completion tracks before the October 13 release. The objective is 99–100 capability depth across supported launch practices, but a function is labeled 100 only after its release tests, integration proof and evidence pass.

Identity & CIEM

  • Complete Azure CIEM depth and effective-permission proof
  • Complete GCP CIEM depth and effective-permission proof
  • Global identity resolution across cloud, IdP, SaaS and data identities
  • Unified ITDR graph and identity-behavior correlation
  • Cross-platform DSPM/DDR identity correlation
  • Active Directory attack graph depth

API & application defense

  • Complete API inventory and API-to-backend security graph
  • Runtime API attack detection
  • Runtime API blocking / WAAS enforcement adapters
  • Authenticated DAST / API testing depth
  • OpenAPI contract validation and machine-safe API semantics
  • Machine-to-machine Golem API authentication / service identities

Runtime & response

  • Windows Runtime Defender real-host certification
  • AWS serverless runtime depth
  • Azure/GCP serverless runtime depth
  • Response framework 2.0 with verification across containment actions
  • Full-platform Track A with verified response and closure
  • Full-platform Track B for CSPM / CIEM / IAM proof
  • Expanded runtime forensics and signed incident evidence

Developer & supply chain

  • Native GitLab connector and merge-request workflow
  • PR / MR annotations and remediation workflow
  • Customer-managed OSS license policy and attribution output
  • Exact PipelineRun → commit → image provenance
  • Admission-time signature / provenance enforcement
  • CI/CD identity and tool attack graph

Graph, data & AI

  • Versioned toxic-combination / risk-rule engine
  • Graph deletion events and programmable drift rules
  • Unified Security Graph Explorer depth
  • AI analyst coverage for every finding type
  • Detection-rule approval / version / rollback lifecycle
  • DSPM connector depth and governance workflows
  • Threat-event normalized schema
  • EASM HTTP / API / TLS discovery depth
  • NSPM configuration history / risk / change intelligence
  • AgentGuard management UI and policy simulator
  • Agent / MCP / tool supply-chain graph completion
  • Agent red-team benchmark expansion

Enterprise proof

  • Report / JUnit / evidence parity
  • Durable enterprise job plane
  • Backup / disaster recovery / upgrade proof
  • Connector health / SLO dashboard
  • Scale, chaos and soak certification
  • Release evidence pack proving every supported launch-domain gate
Release objective: 99–100 across supported launch practices.100 is a proof standard, not a marketing label. If a release gate does not pass, it remains a release-candidate item until evidence is complete.
06 // Competitive positioning

Different architecture. Serious coverage.

Wiz and Cortex Cloud are major enterprise platforms. Golem's positioning centers on customer ownership, inspectability, deterministic AI action governance, rapid code-level extensibility and one graph connecting code, cloud, identity, data, runtime and agents.

Decision areaGolemWizCortex Cloud
Delivery / controlCustomer-owned source + Terraform + graph + evidenceVendor-operated platformVendor-operated platform with sensors/agents where applicable
Security GraphCode → pipeline → image → workload → identity → data → runtime → agent, with declared/observed/confirmed edge evidenceMature Wiz Security GraphBroad Cortex exposure and runtime context
Azure CIEMPR #170: real RBAC assignments, transitive groups, privileged roles, service principals, managed identities, cross-subscription reachMature multi-cloud CIEMMature effective-permission / identity security
Native SASTNative multi-engine SAST through the registered scanner frameworkNative SAST and code-to-cloud workflowsThird-party SAST ingestion documented alongside broader Code Security
Supply-chain integritySBOM + SPDX + licenses + Cosign + expected signer + SLSA provenance + graph lineageBroad software-supply-chain securityBroad code / artifact / runtime security
AI / agent governanceExact-call approval digest, tool baseline digest, graph reach, kill switch and signed action evidenceAI-APP, AI runtime protection, Wiz MCP, agents/workflowsUnified AI-SPM, AgentiX and native MCP support
AI provider choiceCustomer chooses cloud or local modelWiz AI ecosystemPalo Alto AI ecosystem
Runtime evidencePod/node + process tree + network connections + DNS config before containment, then response verificationRuntime sensor and cloud contextDeep runtime / XDR / response capabilities
Network posturePAN-OS + Cisco IOS-XE + MikroTik, graph correlation and approval-gated network responseCloud/network exposure contextBroad Palo Alto network/security ecosystem
CustomizationInspect, modify, test and ship the product code in your environmentVendor platform configuration / APIsVendor platform configuration / APIs

Vendor capabilities change rapidly. Comparison language is intentionally limited to publicly documented features and Golem code verified for this October 2026 release cycle.

Implementation model

Your team keeps the keys.

DevOps Lab does not take over the client's environment. We train, code, design, troubleshoot and help implementation; the client's authorized staff executes changes in its own cloud, endpoints, network, repositories and production systems.

Model 1

200-hour Enablement & Handoff

Deployment planning, integration help, training, supported fixes and handoff. Updates/upgrades remain supported when the customer does not independently fork the supported core.

Model 2

300-hour Full Support & Development

Up to 20 hours/week, dedicated engineering support plus direct lead-architect involvement for integrations, custom development and implementation.

The Golem model

Control all the way down.

  • Inspectable source code
  • Terraform-delivered stack
  • Customer-owned Security Graph
  • Policy-as-code controls
  • Local / private-model support
  • Signed evidence trail
  • Replaceable scanner adapters
  • Human-gated response
One security story

From code to action.

The release architecture is designed to connect repository and pipeline evidence to artifacts, images, cloud resources, identities, classified data, live runtime behavior and agent actions — then preserve the evidence needed to explain why a decision was made and whether the response actually worked.

October 13, 2026

Security you can inspect, change and own.

Review the code, test the platform against your environment, or talk with DevOps Lab about an October 13 deployment and proof-of-value plan.