The guide covers the access and action layer of AI agent security: what an agent can touch, under whose authority and how a security team accounts for it afterward. Each section answers one question a CISO faces before letting agents act inside company systems.
Section 2 · The threat model
An agent will use all the access it is given
The question it answersWhy does an agent with broad access turn ordinary tasks into exposure?
Two real incidents, a deleted production database and a zero-click data leak, show how ordinary agent behavior becomes a security event.
Section 3 · The gap
Existing controls assume an actor the agent is not
The question it answersWhy do role-based access, SOC 2 and audit logs miss AI agents?
The guide shows where role-based access, SOC 2 CC6, audit logging and ISO/IEC 42001 each break when the actor is an agent.
Section 4 · The framework
Seven dimensions turn agent governance into checks a team can run
The question it answersWhat does secure AI agent implementation require?
Each dimension comes with what good looks like, how it fails and the question to put to any vendor or team.
- 1
Visibility
Can you show every agent running right now, the apps it can access and its last full session?
- 2
Authentication and credentials
If an agent's context is compromised, what credential does the attacker walk away with?
- 3
Authorization and policy
What evaluates a destructive action before it runs, and is the decision the same every time?
- 4
Human oversight
When does a person get interrupted, and what stops an injected prompt from faking an approval?
- 5
Audit
Can you export one complete agent session, with the human and the policy decision behind each action?
- 6
Deployment and data residency
Where is each agent request evaluated, and what does the governing layer keep afterward?
- 7
Lifecycle
Who created this agent, what access does it hold and how fast can all of it be revoked?
Section 5 · The architecture
Enforcement can sit in four places, and each is blind to something
The question it answersWhere should an agent control sit in the stack?
The guide compares a protocol gateway, SDK instrumentation, kernel monitoring and vendor integration, including the gateway approach Cakewalk builds.
Section 6 · The path
Start where the irreversible actions are
The question it answersWhere should a security team start with AI agent governance?
Visibility comes first, then the actions that cannot be undone, so a team does not have to fix everything at once.
Section 7 · In closing
The first ninety days do not require buying everything
The question it answersWhat can a security team do in its first ninety days?
Inventory the agents already running, gate destructive and external actions and remove standing secrets from agents that hold them.