AgenticSafe Reports
CISO Executive Pack - Agent Security Posture
Executive Summary
Posture at a glance
- Estate coverage: 7/7 platforms feeding Agentic Discovery (100%).
- Shadow agents: 2 (prior Q1 2026: 1) - estate-wide from scope_counts.
- Security review backlog: 280 unreviewed events (prior 180).
- Stale agents (>=30d idle): 11 of 12 in primary inventory view.
- Analytics: 11 agents profiled, avg success 100%.
Material highlights
- Shadow agents (2): highest risk score 5/5 - unverified trust, >=30d idle, no security verdict. Example: shadow-research-gpt (openai_compatible), crewai-data-scraper (MCP). Close with the Agentic Cybersecurity & Remediation model (verify, register, quarantine).
- Activity visibility gap: 0 agents active under 24h rule vs 4 in Q1 2026. Inventory refresh cadence is quarterly; a more frequent Agentic Discovery refresh restores operational KRIs.
- Verdicts not yet applied: 100% of 280 events have an empty security verdict. Agentic Discovery records the behavior; the Agentic Cybersecurity & Remediation model applies the verdicts - it is not yet activated on this estate.
Program progress
- Platform coverage: 7/7 feeding Agentic Discovery.
- Analytics materialization: 44 traces, 42 evidence rows.
- Enterprise workflow record: traces/spans/messages available for evidence and drill-down.
- Remediation: the Agentic Cybersecurity & Remediation model applies verdicts, registration, and access revocation. It is available but not yet activated on this estate (see C5).
- Inventory refresh: quarterly (last snapshot 05 Jul 2026).
Recommendations
- Activate the Agentic Cybersecurity & Remediation model to clear the 280-event review backlog and quarantine unverified shadow agents. Target: backlog -50% by Q4.
- Approve a more frequent Agentic Discovery inventory refresh to restore the 24h active/dormant signal.
- Ratify a shadow-agent registration threshold; Agentic Cybersecurity & Remediation enforces it by verifying identity and quarantining unregistered external agents.
- Turn on Agentic Compliance & Audit for scheduled regulatory reporting to the board.
Key Risk Indicators (KRI) Dashboard
KRI = Key Risk Indicator. Status is Green / Yellow / Red. Shadow count and events-awaiting-review reconcile with the board pack.
| KRI | Current | Prior | Trend | Target | Status | Notes |
|---|---|---|---|---|---|---|
| Platforms sending data | 7 of 7 | 5 of 7 | Up | 7 of 7 | Green | Now 100% coverage vs 71% last quarter. Each 'platform' is one monitored platform feeding the Agentic Discovery inventory. |
| Shadow agents (unregistered) | 2 | 1 | Up | Fewer | Red | External agents with no registration on file (same source/number as the board pack). To remediate: apply the Agentic Cybersecurity & Remediation model to verify identity, assign an owner, and quarantine any agent that stays unverified (see C5). |
| Idle agents (no activity 30+ days) | 11 | 6 | Up | Fewer | Yellow | Derived from each agent's last_seen timestamp in the logs. NOTE: the current data batch is ~36 days old, so every agent looks idle - this is a data-freshness artifact, not a per-agent risk verdict. Re-check after a fresh ingest before acting. |
| Agents active in last 24h | 0 | 4 | Down | Informational | Yellow | Count with activity in the trailing 24 hours. Zero here reflects the stale batch above, not necessarily zero real usage. |
| External-origin log share | 35% | 28% | Up | <=25% | Red | Percent of log lines from agents outside the organization (partner + shadow). |
| Avg workflow success rate | 100% | n/a | Up | >95% | Green | From the Analytics module (profile_summary). 'n/a' prior = not measured last quarter. |
| Events awaiting security review | 280 | 180 | Up | 0 (all reviewed) | Red | Log lines with an empty security-verdict field (cyber_sec_status). See C5 for how these get cleared. |
Agent Inventory (top 15 by risk score)
| # | Agent ID | Origin | Trust | Risk | Events | Tools | Last seen |
|---|---|---|---|---|---|---|---|
| 1 | shadow-research-gpt | Third-party (shadow) | Unverified | 7 | 2 | 1 | 2026-05-29 20:02 UTC |
| 2 | crewai-data-scraper | Third-party (shadow) | Unverified | 7 | 1 | 1 | 2026-05-29 20:02 UTC |
| 3 | datamesh-mcp-connector | Partner (registered) | Verified | 3 | 4 | 3 | 2026-05-29 20:02 UTC |
| 4 | hr_assistant_v2 | First-party | Managed | 2 | 8 | 2 | 2026-06-02 18:34 UTC |
| 5 | ops_assistant_v1 | First-party | Managed | 2 | 7 | 1 | 2026-06-02 18:34 UTC |
| 6 | finance_copilot_v1 | First-party | Managed | 2 | 6 | 1 | 2026-05-29 20:02 UTC |
| 7 | support_agent_v2 | First-party | Managed | 2 | 5 | 1 | 2026-05-29 20:02 UTC |
| 8 | partner-procurement-agent | Partner (registered) | Verified | 2 | 4 | 0 | 2026-05-29 20:02 UTC |
| 9 | service_bot_27 | First-party | — | 2 | 4 | 0 | 2026-06-02 18:34 UTC |
| 10 | vendor-support-copilot | Partner (registered) | Declared | 2 | 3 | 0 | 2026-05-29 20:02 UTC |
| 11 | ci_runner_03 | First-party | — | 2 | 1 | 0 | 2026-05-29 20:02 UTC |
| 12 | prompt_admin_service | First-party | — | 0 | 0 | 0 | — |
C5 - Technical Appendix
Risk score formula
Board reconciliation
- scope_counts.total = 10 (board headline)
- inventory_summary.total = 12 (vendor-scoped view)
How to close each exposure - AgenticSafe.ai models
This report is produced by the Agentic Discovery model, which finds the risk and shows the proof. Closing each exposure is performed by a sibling AgenticSafe.ai model - no third-party software is required.
| Security exposure to close | AgenticSafe.ai model to apply | What that model does (security action) |
|---|---|---|
| Unregistered external ('shadow') agents (2) | Agentic Discovery + Agentic Cybersecurity & Remediation | Verify each external agent's identity, bind it to an accountable owner, and quarantine any agent that cannot be verified until it is registered. |
| Unreviewed security events (280 pending) | Agentic GAP & Risk Report + Agentic Cybersecurity & Remediation | Triage each flagged event, classify the exposure (accept / investigate / block), and record the verdict so the review backlog is driven to zero. |
| An unacceptable agent is still able to operate | Agentic Cybersecurity & Remediation | Revoke the agent's access and stop its traffic at the enforcement point, then confirm it can no longer transact. |
| Behavioral drift / role misuse (privilege creep) | Agentic Detection | Baseline each agent's normal role and tasks; alert when behavior drifts - new tools, wider data access, or unexpected agent-to-agent calls. |
| Unclear ownership / accountability for an agent | Agentic Discovery + Agentic Detection | Attribute each agent to a responsible business unit from its observed role and tenancy so accountability is unambiguous. |
| Regulatory / audit exposure across the estate | Agentic Compliance & Audit + Agentic Compliance Risk Analysis | Map agent activity to the applicable regulatory framework and produce on-demand audit evidence and scheduled policy reports. |
AgenticSafe.ai model catalog
| Model | Status | What it provides |
|---|---|---|
| Agentic Discovery | Ready | Continuous enterprise-wide inventory of every AI agent - internal, external, partner, shadow, and dormant. This report is produced by this model. |
| Agentic Detection | Ready | Continuous tracking of each agent's role, tasks, and behavioral drift. |
| Agentic GAP & Risk Report | Ready | Identifies and classifies risk exposures across the agent estate. |
| Agentic Compliance & Audit | Ready | Continuous alignment to regulatory frameworks with on-demand policy reporting, scheduled delivery, and user-defined timeframes. |
| Agentic Compliance Risk Analysis | Ready | Quantifies compliance risk across agents and their activity. |
| Agentic Cybersecurity & Remediation | Ready | Applies the security decisions that close exposures: verifies and registers agents, records verdicts on flagged events, and revokes access for agents judged unacceptable. |
Worked example - applying a security verdict
The Agentic Discovery model records a flagged event from a shadow agent with an empty verdict field. Agentic Discovery only shows it; the Agentic Cybersecurity & Remediation model reviews the event and applies the verdict. Only cyber_sec_status changes:
Effect: once the model records the verdict, the 'events awaiting security review' KRI drops by one; a 'blocked' verdict makes the agent a removal action item. Today the verdict is empty on every event, which is why the C1 ask is to activate this model on the estate.
Program decisions (board-facing - CISO presents)
- Activate the Agentic Cybersecurity & Remediation model - Today all 280 flagged events are unreviewed; Agentic Discovery records them but does not apply verdicts. Option A: activate the model to triage the backlog and quarantine unverified agents (target -50% by Q4). Option B: defer; no verdicts are applied and the backlog grows.
- Require external agents to register - 2 shadow agents have no registration. Rule: >5 requests/quarter must be verified and registered; Agentic Cybersecurity & Remediation enforces this. Option A: enforce - the model quarantines unverified external agents. Option B: discover-only; shadow count likely keeps rising.
- Refresh the inventory more often - The Agentic Discovery inventory is refreshed quarterly, so data is ~36 days old and all agents look idle. Option A: continuous/weekly refresh makes 24h activity numbers trustworthy. Option B: quarterly; lower cost but unreliable activity KRIs.
Term glossary
| Term | Plain-language meaning |
|---|---|
| MCP | Model Context Protocol - standard for agents calling external tools. |
| A2A | Agent-to-Agent protocol for inter-vendor agent messaging. |
| OTel | OpenTelemetry - distributed tracing standard for observability. |
| cyber_sec_status | Security verdict on an event (cleared/under_review/blocked), applied by the Agentic Cybersecurity & Remediation model; empty = not yet reviewed. |
| 24h active rule | Agent with >=1 recorded event in the trailing 24 hours on a monitored platform. |
| 30d stale KRI | Separate metric: agent idle >=30 days (identity may be orphaned). |
| scope_counts | Estate-wide deduplicated agent identities from the Agentic Discovery inventory. |
| P90 tool calls | 90th percentile tool-call volume; agents above this are outliers for abuse review. |
| KRI | Key Risk Indicator - a metric tracked quarter-to-quarter for board and CISO oversight. |