LinkedIn Weekly

David Lee's Workspace · generated Sunday 2026-07-26 9:04 AM ET

Last week — post-mortem · Jul 19 - Jul 25, 2026

21,069Impressions
73Engagements
3Posts
6,881Followers
+27Follower gain
+4%Impr. WoW

Three posts, one clear winner and two that leaked reach. The Slack-thread humor post hit 1.3x and carried the week. The 'Story Time: DARIUS Lives' post opened by apologizing for posting late and delivered a flat 0.0x. Impressions held near 3k a day on the 7.28 NY momentum, but total engagement fell to 73 and the week landed 47% below your 30-day baseline. The lesson repeats: value up front wins, buried or self-referential value dies.

Best 1.3x · 890 impressions

Every security team has had this meeting. The boss says AI security is now a quarterly goal. Everybody nods. And two people immediately open a text thread titled how in the $*#! are we pulling this off.

View on LinkedIn →
Worst 0.0x · 1 impressions

Story Time with Dave: DARIUS Lives. The first time I watched Iron Man, everyone else fell for the suit. I fell for JARVIS.

View on LinkedIn →
What worked What missed Apply this week
4-week trend
WeekPostsImpr.Eng.Best
Jun 21-2715,454 841.3x
Jun 28-Jul 0411,969 530.9x
Jul 12-18218,391 1021.5x
Jul 19-25321,069 731.3x

This week — drafts + pre-mortem · Jul 28 - Aug 01, 2026

3 high-signal drafts saved to Supergrow. All grounded in real events and the newsletter arc (agentic AI security, NHI, MCP spec). The 7.28 NY event is the anchor for Post 1. Drafts only. You approve and publish in Supergrow.
Post-event dated anchor — 7.28.26 NY AI Security (10/10)
10/10

Why now: Post-event follow-through while the event is still fresh. Dated hooks (7.28.26) are David's proven 1.5x format. This time it carries the full argument — practitioners building now, not waiting for a standard — which was the exact fix the Jul 12-18 review called for.

7.28.26 is behind us.

Two hours in a room with people who are actually building AI security programs, not just talking about them.

Here is what I keep thinking about: we have been here before.

30 years ago, nobody thought human identity needed governance until the breach happened. Now we are watching the same movie with AI agents, and the credits have already started rolling.

The people in that room yesterday are not waiting for a standard to tell them what to do. They are building now, making decisions now, and living with those decisions now.

That is the part no analyst report captures.

If you were there, what was the one thing that stuck with you?
Pre-mortem (100%)

Perfect 10/10 across all criteria including Content DNA. No changes needed.

MCP spec drops — the identity gap nobody is talking about (9/10)
9/10

Why now: The MCP spec (Jul 28 release) is live and timely. David's angle is expert and specific: MCP answers the plumbing, identity governance is still the practitioner's problem to solve. Newsletter Issue 08 has the MCP insert staged — this post drives readers there.

The MCP spec dropped this week. Most people skimmed it. I didn't.

Here is the part that nobody in security is talking about yet: MCP defines how AI agents call tools and services. It does not define what those agents are allowed to do.

That gap is the identity problem.

When a human calls an API, there is an identity behind that call. There is a credential, a session, an audit trail. When an AI agent chains ten tool calls together, who is the identity? What scope was granted? Who approved it?

The spec answers the plumbing. The governance question is still yours to solve.

Are you building MCP-connected tools in your environment right now?
Pre-mortem (90%)

9/10. Top fix applied: added 'Most people skimmed it. I didn't.' to hook for authority and contrast. Content DNA note: slightly more formal than David's warmest posts — the 'I have read it' authority opener is intentional and strong, tradeoff accepted.

30-year déjà vu — we built this playbook, we just haven't applied it (9/10)
9/10

Why now: Mirrors the historical-framing format David has used before. The PAM/IGA/secrets-management progression is instantly recognizable to the IAM practitioner audience and grounds the agent-identity argument in 30 years of evidence. Personal field observation added to close the Content DNA gap.

We built PAM because privileged accounts became the target.

We built IGA because identity lifecycle got out of hand.

We built secrets management because credentials sprawled across every service.

Thirty years of building the same solution to the same problem. We know how to govern identity at scale.

What we have not done is apply it to the new identities showing up in our environments every day. I have been in rooms where no one could name who owns an agent running in their environment. That is the problem.

Agents with more access than most of your contractors. No lifecycle management. No review cycle. No one accountable for them.

The problem is not new. The urgency is.

Are you treating your agents like the privileged identities they already are?
Pre-mortem (90%)

9/10. Top fix applied: added 'I have been in rooms where no one could name who owns an agent running in their environment. That is the problem.' to anchor in personal experience and push Content DNA to full alignment.