Skip to content
GitHub Agentic Workflows

Meet the Workflows: Security & Compliance

Peli de Halleux

Great to have you back at Peli’s Agent Factory!

In our previous post, we explored operations and release workflows that handle the critical process of shipping software - building, testing, generating release notes, and publishing. These workflows need to be rock-solid reliable because they represent the moment when our work reaches users.

But reliability alone isn’t enough - we also need security. When AI agents can access APIs, modify code, and interact with external services, security becomes paramount. How do we ensure agents only access authorized resources? How do we track vulnerabilities and enforce compliance deadlines? How do we prevent credential exposure? That’s where security and compliance workflows become our essential guardrails - the watchful guardians that let us sleep soundly at night.

These agents are our security guards, keeping watch and enforcing the rules:

Security workflows were where we got serious about trust boundaries. The Security Compliance agent manages entire vulnerability remediation campaigns with deadline tracking - perfect for those “audit in 3 weeks” panic moments. We learned that AI agents need guardrails just like humans need seat belts.

The Firewall workflow validates that our agents can’t access unauthorized resources, because an AI agent with unrestricted network access is… let’s just say we sleep better with these safeguards. These workflows prove that automation and security aren’t at odds - when done right, automated security is more consistent than manual reviews.

After all this serious infrastructure talk, let’s explore the fun side: agents that bring joy and build team culture.

Continue reading: Creative & Culture Workflows →


This is part 8 of a 16-part series exploring the workflows in Peli’s Agent Factory.