Security operations / Overview
BM
Tuesday, October 6, 2026 · Updated just now

AI agent security overview

See what your AI agents are doing, what they can reach, and where risk is building.

Active agents
24
Across 6 illustrative sources
Open incidents
3
1 needs review · 2 investigating
Policy violations · 24h
7
4 blocked · 3 require review
Verified risk removed
—
Run the simulation to see a verified outcome

Priority incident

● HIGH · P1
Needs human reviewINC-2048 · 9:42 AM

AI agent accessed sensitive data outside its normal workflow

Finance assistant used a service identity to export 1,284 payroll records through Snowflake. This access path is new and the volume exceeds its observed baseline. Current evidence does not establish whether the action was malicious or approved.

AGENT  finance-assistant-prodIDENTITY  svc-finance-aiRESOURCE  payroll-prod

Connected evidence

ILLUSTRATIVE
◇
Finance assistantAI agent · new data path
Flagged
♙
svc-finance-aiService identity · OAuth
Review
▣
Snowflake APIConnected tool · export
Linked
▤
payroll-prodSensitive data · 1,284 records
High impact

Recent agent activity

EventAgent / identitySourceRiskTime
Sensitive record exportFinance assistant
svc-finance-ai
SnowflakeHigh9:42 AM
New OAuth grant issuedSupport copilot
svc-support-bot
Microsoft 365Medium9:18 AM
Unusual tool sequenceDevOps agent
svc-platform-ops
AWS · EDRMedium8:57 AM

Enforcement at the action path

POLICY GATE

Evaluate a tool call before execution. Apply the customer’s rules to agent identity, requested action, resource sensitivity, and context.

Sensitive payroll exportBlock bulk export · route exception to reviewer
ENABLED
Prototype workspace · synthetic data. No customer systems are connected, no live policies are enforced, and no security action is executed. Prevention requires enforcement at the relevant agent/tool action path and supporting controls.
INVESTIGATE · CONTAIN · VERIFY

Incident response

Follow one evidence-backed case from suspicious agent activity through a verified simulated response.

INC-2048 · HIGH

Payroll data access by finance assistant

Awaiting review
◇

AI agent

finance-assistant-prod
Unexpected tool sequence

♙

Identity

svc-finance-ai
OAuth token

⌘

Endpoint

fin-app-07
Runtime telemetry

☁

Cloud / tool

Snowflake API
New access path

▤

Business data

payroll-prod
1,284 sensitive records

WHY IT WAS FLAGGED
Sensitive data access · +35

Payroll resource is classified high impact.

Volume outside baseline · +30

1,284 records exported; usual activity is under 100.

New agent-to-resource path · +20

This relationship was not observed in the prior 30 days.

EVIDENCE-GROUNDED SUMMARY

The finance assistant exported payroll records through its service identity. This is anomalous and potentially high impact. The available evidence alone does not prove malicious intent. Confirm whether the export was requested and review the agent’s instruction and tool-call trace before acting.

EV-9812EV-9814POL-07Drafted from synthetic evidence

Proposed response plan

APPROVAL REQUIRED
Pause finance assistantPrevent further tool calls while the case is reviewed
SIMULATED
Revoke svc-finance-ai session tokenScoped to the suspected session · preserve evidence first
SIMULATED
Restrict payroll export routeBlock bulk transfer pending authorization
SIMULATED
Re-read source systems and verifyConfirm the agent is paused and access is restricted
SIMULATED

Remediate root causes

FOLLOW-UP

Containment limits immediate harm. Remediation closes the conditions that could let the attack path recur.

Patch or isolate the exposed AI serviceTrack the vulnerable framework to a verified fixed version
SIMULATED
Rotate exposed credentialsReplace the suspected secret and check dependent services
SIMULATED
Reduce agent and identity permissionsRemove excess data and tool access; preserve approved workflows
SIMULATED
Verify closure across connected sourcesRe-check patch state, secret use, access policy, and data egress
SIMULATED
JADEPUFFER-style scenario: the demo separates immediate containment from durable fixes to exposure, credentials, permissions, and egress. Each follow-up needs its own owner, approval, and post-change evidence in a production product.
All response buttons run a local simulation. They do not contact or modify external systems.
DISCOVERY · IDENTITY · ACCESS

AI agents

An illustrative inventory of agents, their identities, tools, and sensitive access.

Discovered agents
24
Across illustrative systems
With sensitive access
6
Review least privilege
Unowned identities
2
Owner confirmation needed
Policy-covered
18
75% of demo inventory

Agent inventory

SYNTHETIC EXAMPLE RECORDS
AgentOwnerIdentityConnected toolsData sensitivityGovernance
Finance assistantFinance Opssvc-finance-aiSnowflake, internal APIHighReview
Support copilotCustomer Caresvc-support-botCRM, Microsoft 365MediumCovered
DevOps agentPlatform Eng.svc-platform-opsAWS, Git, EDRHighCovered
Research assistantUnconfirmedsvc-research-aiWeb, document storeMediumOwner needed
Agent discovery, identity mapping, and inventory values are mock records for the prototype.
AUDITABLE EVENT STREAM

Activity

Illustrative events normalized across AI, identity, endpoint, cloud, and data sources.

Correlated activity · today

DEMO EVENTS
9:42:08 AM

Bulk payroll export initiated by Finance assistant

Snowflake · svc-finance-ai · 1,284 records · linked to INC-2048
9:41:52 AM

New agent-to-resource path observed

AI gateway · Finance assistant → payroll-prod · unseen in prior 30 days
9:40:19 AM

Agent requested expanded database query scope

AI gateway · policy POL-07 requested review
9:18:02 AM

New OAuth grant issued to Support copilot

Microsoft 365 · svc-support-bot · Mail.ReadWrite
8:31:45 AM

Prompt injection attempt blocked at tool boundary

AI gateway · Research assistant · synthetic policy event
The event timeline is generated from fixed, fictional prototype data.
DEFINE WHAT AGENTS MAY DO

AI governance policies

Policy examples for agent identity, action scope, sensitive data, and human review.

Active policy examples

4 ACTIVE
Block bulk access to sensitive dataBlock export above 100 records · require reviewer override
Restrict agent tool scopeAllow only approved tools for each agent identity
Review new identity grantsHold unfamiliar OAuth permissions for human review
Require approval for containmentPause, revoke, isolate, or block only after authorized approval

Action-path decision

SIMULATED
Agent requests payroll export

Tool call includes identity, target, action, and context.

Policy checks the request

Data class: sensitive · record count: 1,284 · threshold: 100.

Decision: DENY + notify reviewer

The action gate blocks the tool call before it runs—if enforcement is deployed on that path.

Coverage limit: an action gate can stop a risky agent tool call. It does not, by itself, stop an initial server exploit or activity outside the enforced path.
These are policy concepts in a local simulation. They are not enforced against real agents.
CONNECT THE EXISTING SECURITY STACK

Integrations

A connected control plane concept for linking evidence and coordinating approved actions.

Prototype status: these are illustrative connectors only. No accounts or customer systems are connected. Production integration requires customer-authorized APIs, scoped permissions, and source-specific validation.

Illustrative sources

READ-ONLY IN DEMO
AI GatewayAgent identity · prompts · tool calls
MOCK
Microsoft Entra IDIdentity · OAuth grants · sign-ins
MOCK
AWS / CNAPPCloud resources · exposure · audit trail
MOCK
EDR / endpointHost signals · process activity · isolation state
MOCK
Snowflake / dataData classification · query and export events
MOCK

JADEPUFFER-style defense view

ILLUSTRATIVE
Exposed AI service

Identify exposed framework and reduce ingress risk.

Compromise and credential theft

Use runtime telemetry, secret controls, short-lived credentials, and response from existing tools.

Identity and lateral movement

Link the principal to reachable cloud, on-prem, and data resources.

Data access or exfiltration

Enforce egress/data policies and block agent tool actions where the policy gate is present.

Reviewer: Ben McPherson · Workspace owner
Scope: INC-2048 · Simulated actions only