Approach
Five Control Areas for AI Agent Security
Review context, actions, tool surfaces, human oversight and evidence together.
The control areas
Content and context
Retrieved documents, messages and tool output may carry instructions that conflict with the user’s task.
Action control
Define permitted actions, resource boundaries and approvals outside the model.
Agent-native surfaces
The agent’s dependencies and stored context form part of its security boundary.
Human oversight
Route consequential actions to someone who can understand and authorise the proposed change.
Assurance and evidence
Connect requirements, test results and operational records without unnecessarily copying sensitive data.
Start with the action
Follow a high-risk operation from the user task through identity, data retrieval, tool invocation, approval and execution. Identify where each control is enforced and what happens if it is unavailable.
Start with a clear scope
Tell us which systems, actions and review requirements are in scope. We will discuss the work, responsibilities and deliverables before you commit.