From Spec to Standard: How AARM Became the Conformance Bar for Agent Runtime Security, with Herman Errico (Vanta, AARM)
Herman Errico · Product Manager for Technical Research at Vanta
We sit down with Herman Errico, Product Manager for Technical Research at Vanta, to dig into AARM (Autonomous Action Runtime Management), the spec he wrote to define a new security category for agents that take real actions rather than just generate text. We get into why the action boundary is the security boundary, why the model, prompt, and orchestration layers are the wrong places to enforce it, and why a runtime needs five authorization decisions, allow, deny, modify, step-up, and defer, instead of a binary yes or no. Herman also explains why he shipped a spec instead of a product, then donated it from Vanta to the Cloud Security Alliance so the industry can compete on execution instead of marketing, and how to reason about which context an agent can actually trust.
Listen on