Adding a scan task to one Azure DevOps pipeline is easy. Keeping the same control active across hundreds of YAML and classic builds is not. Kangl Pipeline Security Runtime turns coverage into centrally managed state rather than a task every team must remember to maintain.
How the Security Runtime works
The Runtime holds eligibility, enrollment, provider configuration, and enforcement mode centrally. During pipeline execution it applies the correct security behavior to eligible builds. Azure DevOps Pipeline Decorator is one technical mechanism underneath this flow; it is an implementation detail, not the module teams operate.
Why they are ideal for security scanning
- Coverage by default: new pipelines are covered from their first run.
- No YAML sprawl: one implementation instead of hundreds of copies.
- Central upgrades: fixing the scan step once fixes it everywhere.
- Deliberate exclusion: opting out becomes a visible, governable act.
The operational catch
Organization-wide execution means a bad configuration can also have organization-wide impact. Running the Security Runtime safely demands a global kill switch for emergencies, per-pipeline enable and disable state, conditions that respect eligibility, and observability into where the control actually ran.
Kangl provides those controls as one managed Runtime: central settings, a global kill switch, per-pipeline and bulk control, drift detection with Force Sync, and an audit history of every change.

