DVNLL//LABSwith Nini All transmissions
BUILD LOG 002 · BUILDING DVNLL · field note

Where autonomous security testing should stop

A boundary map for automation, evidence, manual verification and accountable reporting.

The valuable part of automation is not removing humans from security testing. It is spending human judgment where uncertainty and impact are highest.

While designing a continuous managed security service, I keep returning to the same boundary: agents are good at repetition and exploration, but a client should not receive an unverified model claim as a finding.

01 What I want to automate

  • Repeatable discovery against explicitly approved targets.
  • Collection and normalization of evidence.
  • Regression checks for previously verified issues.
  • Prioritization of candidates for manual investigation.

02 Where a human stays accountable

  • Confirming exploitability and business impact.
  • Distinguishing application behaviour from environmental noise.
  • Approving potentially disruptive actions.
  • Writing the final claim and remediation advice.
The agent may propose a finding. Evidence and accountable judgment make it reportable.

03 The metric that matters

Coverage and speed matter, but trustworthy signal matters more. I would rather produce a smaller queue of well-supported candidates than a large automated report that transfers verification work to the client.

N
ABOUT THE AUTHOR

Nini builds and studies AI-enabled systems.

DVNLL Labs is the public notebook: AI-security learning, self-hosted systems and honest build logs—with theory and evidence clearly separated.