AI agent security overview
See what your AI agents are doing, what they can reach, and where risk is building.
Priority incident
● HIGH · P1AI agent accessed sensitive data outside its normal workflow
Finance assistant used a service identity to export 1,284 payroll records through Snowflake. This access path is new and the volume exceeds its observed baseline. Current evidence does not establish whether the action was malicious or approved.
Connected evidence
ILLUSTRATIVERecent agent activity
| Event | Agent / identity | Source | Risk | Time |
|---|---|---|---|---|
| Sensitive record export | Finance assistant svc-finance-ai | Snowflake | High | 9:42 AM |
| New OAuth grant issued | Support copilot svc-support-bot | Microsoft 365 | Medium | 9:18 AM |
| Unusual tool sequence | DevOps agent svc-platform-ops | AWS · EDR | Medium | 8:57 AM |
Enforcement at the action path
POLICY GATEEvaluate a tool call before execution. Apply the customer’s rules to agent identity, requested action, resource sensitivity, and context.
Incident response
Follow one evidence-backed case from suspicious agent activity through a verified simulated response.
Payroll data access by finance assistant
AI agent
finance-assistant-prod
Unexpected tool sequence
Identity
svc-finance-ai
OAuth token
Endpoint
fin-app-07
Runtime telemetry
Cloud / tool
Snowflake API
New access path
Business data
payroll-prod
1,284 sensitive records
Payroll resource is classified high impact.
1,284 records exported; usual activity is under 100.
This relationship was not observed in the prior 30 days.
The finance assistant exported payroll records through its service identity. This is anomalous and potentially high impact. The available evidence alone does not prove malicious intent. Confirm whether the export was requested and review the agent’s instruction and tool-call trace before acting.
Proposed response plan
APPROVAL REQUIREDRemediate root causes
FOLLOW-UPContainment limits immediate harm. Remediation closes the conditions that could let the attack path recur.
AI agents
An illustrative inventory of agents, their identities, tools, and sensitive access.
Agent inventory
SYNTHETIC EXAMPLE RECORDS| Agent | Owner | Identity | Connected tools | Data sensitivity | Governance |
|---|---|---|---|---|---|
| Finance assistant | Finance Ops | svc-finance-ai | Snowflake, internal API | High | Review |
| Support copilot | Customer Care | svc-support-bot | CRM, Microsoft 365 | Medium | Covered |
| DevOps agent | Platform Eng. | svc-platform-ops | AWS, Git, EDR | High | Covered |
| Research assistant | Unconfirmed | svc-research-ai | Web, document store | Medium | Owner needed |
Activity
Illustrative events normalized across AI, identity, endpoint, cloud, and data sources.
Correlated activity · today
DEMO EVENTSBulk payroll export initiated by Finance assistant
Snowflake · svc-finance-ai · 1,284 records · linked to INC-2048New agent-to-resource path observed
AI gateway · Finance assistant → payroll-prod · unseen in prior 30 daysAgent requested expanded database query scope
AI gateway · policy POL-07 requested reviewNew OAuth grant issued to Support copilot
Microsoft 365 · svc-support-bot · Mail.ReadWritePrompt injection attempt blocked at tool boundary
AI gateway · Research assistant · synthetic policy eventAI governance policies
Policy examples for agent identity, action scope, sensitive data, and human review.
Active policy examples
4 ACTIVEAction-path decision
SIMULATEDTool call includes identity, target, action, and context.
Data class: sensitive · record count: 1,284 · threshold: 100.
The action gate blocks the tool call before it runs—if enforcement is deployed on that path.
Integrations
A connected control plane concept for linking evidence and coordinating approved actions.
Illustrative sources
READ-ONLY IN DEMOJADEPUFFER-style defense view
ILLUSTRATIVEIdentify exposed framework and reduce ingress risk.
Use runtime telemetry, secret controls, short-lived credentials, and response from existing tools.
Link the principal to reachable cloud, on-prem, and data resources.
Enforce egress/data policies and block agent tool actions where the policy gate is present.