Research article published in **ACM Queue** (vol. 24, no. 3 — thematic issue "LLMs") on **July 20, 2026**, authored by **Joseph Valente** (Director of Product Management, Alphabet Security) and **Michal Zalewski** (Distinguished Engineer, Alphabet Security strategist — the *lcamtuf* of offensive security). **CC BY 4.0** license, **29,143 downloads** in ten days, **a single bibliographic reference**: the 2014 **BeyondCorp** whitepaper. This is not incidental — the article explicitly positions itself as **BeyondCorp's generic successor** and takes on its function: *"publish the vision so the industry can align to it."* **Thesis**: the **application-boundary model is reaching end of life**. The three assumptions that underpinned BeyondCorp — *accessors are human, actions occur at human speed, the application is the right trust boundary* — are all three obsolete now that AI agents access data at **10 times the rate of humans** and reason over vast unstructured corpora. **Beyond Zero** therefore shifts the trust boundary **from the application to the individual action on the individual resource**, and investigation **from after-the-fact to real-time**. **Four-component architecture forming a loop**: *autonomous governance* (which uses AI to build a living **enterprise world model** — Who / What / How — by explicit analogy with a self-driving car's world model), *event intake* (server, client, and **agent activity** signals: prompts, execution plans, tool invocations), *reasoning engine* (hierarchical AI, **fast** for ABAC at access time and **slow** for inference over a sequence of actions; *allow / deny / challenge* verdict), and *challenge infrastructure* (reversible **challenges** — justification, security key tap, approval, **selfie** — vs. durable **containments**, sometimes lifted only after the security team interviews the employee and their manager). **The central design move is the floor/ceiling split**: **static policies** (the floor, statically verifiable) under a **dynamic reasoning engine** (the ceiling) — an explicit rejection of a *"fully dynamic, hard-to-statically-verify"* model. **The named attack vector**: **ambient authority**, the agent inheriting its human's full, often overprovisioned permissions. **Three reservations noted**: this is a **vision paper, not a war story** — zero production metrics, zero false-positive rate, zero deployment scale, whereas [[uber-engineering-agent-identity-crisis-zero-trust-spire-2026-05-21]] had published a P99 < 40 ms and thousands of agents in production two months earlier; an **internal order-of-magnitude inconsistency** (tens of millions of actions/s in the problem statement vs. thousands of decisions/s in the abstract and conclusion); and a **massive European blind spot** — the described system is also an employee-surveillance apparatus (selfie, client-side signals, baselining against the peer group), without a single line on GDPR, proportionality, or employee representative bodies.
#Beyond Zero#BeyondCorp#zero trust
**Joseph Valente** — Director of Product Management · en charge des efforts de sécurité entreprise au sein d'**Alphabet Security** ; son périmètre couvre l'ensemble des business units d'Alphabet (Google Ads, DeepMind, YouTube, Devices, Cloud). Précédemment à l'origine de ce qui est devenu le **Sovereign Cloud de Google** (l'offre de compute souverain de Google Cloud) — détail notable pour un lectorat européen. Avant Google : cofondateur de Pathify et Ebla · passage par Bain & Company.
Sierra blog post (December 10, 2024, Elliot Greenwald) laying out the **founding text of *outcome-based pricing*** for AI agents. **Pivot thesis**: AI agents that execute processes autonomously make possible an **entirely new pricing model** — ***"you pay only when the software achieves specific, valuable outcomes: outcome-based pricing."*** The article traces a **four-age genealogy of software pricing**: (1) **shrink-wrapped software** (1980s-90s, the floppy-disk/CD-ROM box at Fry's Electronics — *"Whether you actually used it or not, you paid for it"*) → (2) **SaaS / seat-based** (pioneered by **Salesforce**, followed by Google/Microsoft/Adobe — the Internet makes it possible to sell software *as a service*) → (3) **consumption-based** (**Amazon/AWS** and **Snowflake** — *"charged only for what you used"*) → (4) **outcome-based** (AI agents). **Canonical definition**: ***"outcome-based pricing is tied to tangible business impacts—such as a resolved support conversation, a saved cancellation, an upsell, a cross-sell, or any number of valuable outcomes. If the conversation is unresolved, in most cases, there's no charge."*** **Aligned-incentives principle**: ***"With outcome-based pricing, Sierra gets paid only when we complete a task for you. Our incentives are aligned."*** **Critique of seat-based pricing & the concept of *shelfware***: *"Unused seats sit idly on a proverbial store shelf, hence the derisive moniker 'shelfware'"* — thousands of dollars per year are paid per license, whether used or not. **Structural conflict for Fournisseurs CX legacy**: their revenue depends on seat-based pricing, yet *"the more effective their AI becomes, the fewer contact center seats their clients need—undermining the provider's own revenue model"* — an effective AI agent **cannibalizes** the revenue model of a vendor whose pricing rests on seats. **Granularity of the outcome**: a distinction between **simple resolutions** (answering a question) and **complex resolutions** (handling a case that requires a 20-minute L2 call); **escalations generally incur no charge**; **blended pricing** is possible (e.g., consumption-based for routing/greeting interactions). **Continuous-optimization commitment** on the vendor side: *"we continue to deploy concerted, directed optimizations to refine the agent's performance over time"* — the vendor stays aligned to improve performance since it is paid only for the outcome. Significance: posed in **late 2024**, this post **precedes and grounds** the entire 2026 debate on the agentic economy — it supplies the **vocabulary of the billing unit** (the completed *outcome* rather than the seat, usage, or token) that will later be taken up by Gupta (*cost of a completed outcome*, *token-to-outcome attribution*), Bain (*outcome-based pricing shifts revenue from fixed seats to labor/operations economics*), Ng (*pricing power anchored on the salary of the replaced employee*). With Sierra as the **reference example** cited by Bain (*autonomous customer issue resolution*), this text gives the **vendor-side view** of the mechanics that others analyze from the buyer side. Directly relevant to the firm's positioning on **agentic-delivery / value-based pricing** and to the **Cost Optimization** slot (the vendor-side counterpart of *cost per outcome*).
**Elliot Greenwald** — Sierra (entreprise fondée par Bret Taylor & Clay Bavor, plateforme d'agents IA conversationnels pour l'expérience client). Billet publié sur le blog Sierra le **10 décembre 2024**. Sierra est l'**exemple-référence** cité par Bain (*The $100-Billion SaaS Opportunity*) pour l'*autonomous customer issue resolution* · et fait l'objet de plusieurs fiches du dossier (recrutement AI-native, interview Plan/Build/Review).