Enforcing Pod Security on AKS with Azure Policy and OPA Gatekeeper

Detecting insecure pods on Azure Kubernetes Service is not the same as preventing them. Here is how Azure Policy and OPA Gatekeeper move enforcement to admission time, so a misconfigured workload never reaches the cluster.

June 13, 2026 · 3 min · Yogesh Thanvi

Mapping CSPM to Microsoft Defender for Cloud: From Findings to Enforcement

Defender for Cloud is excellent at telling you what is misconfigured. A finding is not a fix. Here is how I turn cloud security posture management on Azure from a dashboard of alerts into enforcement that blocks and remediates, using Azure Policy deny effects and admission-time control on AKS.

June 13, 2026 · 4 min · Yogesh Thanvi

Governing AI Systems at Scale: From Risk Models to Real Enforcement

Frameworks tell you what outcomes to achieve. They do not tell you how to instrument your system to produce them. That gap, between risk models and real enforcement, is where most AI governance programs are stuck.

June 12, 2026 · 4 min · Yogesh Thanvi

Building Trust in AI Systems: Why You Cannot Test It In

Testing samples an AI system’s behavior at one moment. Trust requires governing that behavior continuously. Here is the trust triad, governance, validation, and monitoring, and why conflating the three is the mistake that breaks at scale.

June 11, 2026 · 4 min · Yogesh Thanvi

From Detection to Enforcement: Making CSPM Actually Stop Misconfigurations

Most Cloud Security Posture Management tools detect misconfigurations and stop there. Detection without enforcement leaves the exposure in place. Here is what changes when policy-as-code blocks and remediates at admission time.

June 9, 2026 · 3 min · Yogesh Thanvi

Engineering Trust: Building Systems That Prove Compliance Continuously

In cloud-native and AI-driven systems, compliance can no longer be a periodic activity. It has to be continuously demonstrated. Here is the architecture for engineering that trust.

June 8, 2026 · 6 min · Yogesh Thanvi