Back to Reports

AgenticSafe Reports

CISO Executive Pack - Agent Security Posture

Reporting period: Q2 2026 | Prior period: Q1 2026 | Snapshot: 05 July 2026, 18:50 UTC

Executive Summary

Posture at a glance

  • Estate coverage: 7/7 platforms feeding Agentic Discovery (100%).
  • Shadow agents: 2 (prior Q1 2026: 1) - estate-wide from scope_counts.
  • Security review backlog: 280 unreviewed events (prior 180).
  • Stale agents (>=30d idle): 11 of 12 in primary inventory view.
  • Analytics: 11 agents profiled, avg success 100%.

Material highlights

  • Shadow agents (2): highest risk score 5/5 - unverified trust, >=30d idle, no security verdict. Example: shadow-research-gpt (openai_compatible), crewai-data-scraper (MCP). Close with the Agentic Cybersecurity & Remediation model (verify, register, quarantine).
  • Activity visibility gap: 0 agents active under 24h rule vs 4 in Q1 2026. Inventory refresh cadence is quarterly; a more frequent Agentic Discovery refresh restores operational KRIs.
  • Verdicts not yet applied: 100% of 280 events have an empty security verdict. Agentic Discovery records the behavior; the Agentic Cybersecurity & Remediation model applies the verdicts - it is not yet activated on this estate.

Program progress

  • Platform coverage: 7/7 feeding Agentic Discovery.
  • Analytics materialization: 44 traces, 42 evidence rows.
  • Enterprise workflow record: traces/spans/messages available for evidence and drill-down.
  • Remediation: the Agentic Cybersecurity & Remediation model applies verdicts, registration, and access revocation. It is available but not yet activated on this estate (see C5).
  • Inventory refresh: quarterly (last snapshot 05 Jul 2026).

Recommendations

  • Activate the Agentic Cybersecurity & Remediation model to clear the 280-event review backlog and quarantine unverified shadow agents. Target: backlog -50% by Q4.
  • Approve a more frequent Agentic Discovery inventory refresh to restore the 24h active/dormant signal.
  • Ratify a shadow-agent registration threshold; Agentic Cybersecurity & Remediation enforces it by verifying identity and quarantining unregistered external agents.
  • Turn on Agentic Compliance & Audit for scheduled regulatory reporting to the board.

Key Risk Indicators (KRI) Dashboard

KRI = Key Risk Indicator. Status is Green / Yellow / Red. Shadow count and events-awaiting-review reconcile with the board pack.

KRI Current Prior Trend Target Status Notes
Platforms sending data 7 of 7 5 of 7 Up 7 of 7 Green Now 100% coverage vs 71% last quarter. Each 'platform' is one monitored platform feeding the Agentic Discovery inventory.
Shadow agents (unregistered) 2 1 Up Fewer Red External agents with no registration on file (same source/number as the board pack). To remediate: apply the Agentic Cybersecurity & Remediation model to verify identity, assign an owner, and quarantine any agent that stays unverified (see C5).
Idle agents (no activity 30+ days) 11 6 Up Fewer Yellow Derived from each agent's last_seen timestamp in the logs. NOTE: the current data batch is ~36 days old, so every agent looks idle - this is a data-freshness artifact, not a per-agent risk verdict. Re-check after a fresh ingest before acting.
Agents active in last 24h 0 4 Down Informational Yellow Count with activity in the trailing 24 hours. Zero here reflects the stale batch above, not necessarily zero real usage.
External-origin log share 35% 28% Up <=25% Red Percent of log lines from agents outside the organization (partner + shadow).
Avg workflow success rate 100% n/a Up >95% Green From the Analytics module (profile_summary). 'n/a' prior = not measured last quarter.
Events awaiting security review 280 180 Up 0 (all reviewed) Red Log lines with an empty security-verdict field (cyber_sec_status). See C5 for how these get cleared.

Agent Inventory (top 15 by risk score)

# Agent ID Origin Trust Risk Events Tools Last seen
1shadow-research-gptThird-party (shadow)Unverified7212026-05-29 20:02 UTC
2crewai-data-scraperThird-party (shadow)Unverified7112026-05-29 20:02 UTC
3datamesh-mcp-connectorPartner (registered)Verified3432026-05-29 20:02 UTC
4hr_assistant_v2First-partyManaged2822026-06-02 18:34 UTC
5ops_assistant_v1First-partyManaged2712026-06-02 18:34 UTC
6finance_copilot_v1First-partyManaged2612026-05-29 20:02 UTC
7support_agent_v2First-partyManaged2512026-05-29 20:02 UTC
8partner-procurement-agentPartner (registered)Verified2402026-05-29 20:02 UTC
9service_bot_27First-party2402026-06-02 18:34 UTC
10vendor-support-copilotPartner (registered)Declared2302026-05-29 20:02 UTC
11ci_runner_03First-party2102026-05-29 20:02 UTC
12prompt_admin_serviceFirst-party000

C5 - Technical Appendix

Risk score formula

score = (shadow?3:0) + (dormant_30d?2:0) + (tool_calls>P90?1:0) + (unverified?2:0) P90 tool calls this period: 2

Board reconciliation

  • scope_counts.total = 10 (board headline)
  • inventory_summary.total = 12 (vendor-scoped view)

How to close each exposure - AgenticSafe.ai models

This report is produced by the Agentic Discovery model, which finds the risk and shows the proof. Closing each exposure is performed by a sibling AgenticSafe.ai model - no third-party software is required.

Security exposure to close AgenticSafe.ai model to apply What that model does (security action)
Unregistered external ('shadow') agents (2) Agentic Discovery + Agentic Cybersecurity & Remediation Verify each external agent's identity, bind it to an accountable owner, and quarantine any agent that cannot be verified until it is registered.
Unreviewed security events (280 pending) Agentic GAP & Risk Report + Agentic Cybersecurity & Remediation Triage each flagged event, classify the exposure (accept / investigate / block), and record the verdict so the review backlog is driven to zero.
An unacceptable agent is still able to operate Agentic Cybersecurity & Remediation Revoke the agent's access and stop its traffic at the enforcement point, then confirm it can no longer transact.
Behavioral drift / role misuse (privilege creep) Agentic Detection Baseline each agent's normal role and tasks; alert when behavior drifts - new tools, wider data access, or unexpected agent-to-agent calls.
Unclear ownership / accountability for an agent Agentic Discovery + Agentic Detection Attribute each agent to a responsible business unit from its observed role and tenancy so accountability is unambiguous.
Regulatory / audit exposure across the estate Agentic Compliance & Audit + Agentic Compliance Risk Analysis Map agent activity to the applicable regulatory framework and produce on-demand audit evidence and scheduled policy reports.

AgenticSafe.ai model catalog

Model Status What it provides
Agentic Discovery Ready Continuous enterprise-wide inventory of every AI agent - internal, external, partner, shadow, and dormant. This report is produced by this model.
Agentic Detection Ready Continuous tracking of each agent's role, tasks, and behavioral drift.
Agentic GAP & Risk Report Ready Identifies and classifies risk exposures across the agent estate.
Agentic Compliance & Audit Ready Continuous alignment to regulatory frameworks with on-demand policy reporting, scheduled delivery, and user-defined timeframes.
Agentic Compliance Risk Analysis Ready Quantifies compliance risk across agents and their activity.
Agentic Cybersecurity & Remediation Ready Applies the security decisions that close exposures: verifies and registers agents, records verdicts on flagged events, and revokes access for agents judged unacceptable.

Worked example - applying a security verdict

The Agentic Discovery model records a flagged event from a shadow agent with an empty verdict field. Agentic Discovery only shows it; the Agentic Cybersecurity & Remediation model reviews the event and applies the verdict. Only cyber_sec_status changes:

BEFORE - as recorded by Agentic Discovery: agent_name : shadow-research-gpt (third_party / unverified) guardrail_status : flagged cyber_sec_status : "" <-- empty, counts toward review backlog AFTER - Agentic Cybersecurity & Remediation applies the verdict: cyber_sec_status : under_review (or 'blocked' if unacceptable) review_note : "Prompt-injection attempt; model refused." reviewed_by : Agentic Cybersecurity & Remediation

Effect: once the model records the verdict, the 'events awaiting security review' KRI drops by one; a 'blocked' verdict makes the agent a removal action item. Today the verdict is empty on every event, which is why the C1 ask is to activate this model on the estate.

Program decisions (board-facing - CISO presents)

  • Activate the Agentic Cybersecurity & Remediation model - Today all 280 flagged events are unreviewed; Agentic Discovery records them but does not apply verdicts. Option A: activate the model to triage the backlog and quarantine unverified agents (target -50% by Q4). Option B: defer; no verdicts are applied and the backlog grows.
  • Require external agents to register - 2 shadow agents have no registration. Rule: >5 requests/quarter must be verified and registered; Agentic Cybersecurity & Remediation enforces this. Option A: enforce - the model quarantines unverified external agents. Option B: discover-only; shadow count likely keeps rising.
  • Refresh the inventory more often - The Agentic Discovery inventory is refreshed quarterly, so data is ~36 days old and all agents look idle. Option A: continuous/weekly refresh makes 24h activity numbers trustworthy. Option B: quarterly; lower cost but unreliable activity KRIs.

Term glossary

Term Plain-language meaning
MCPModel Context Protocol - standard for agents calling external tools.
A2AAgent-to-Agent protocol for inter-vendor agent messaging.
OTelOpenTelemetry - distributed tracing standard for observability.
cyber_sec_statusSecurity verdict on an event (cleared/under_review/blocked), applied by the Agentic Cybersecurity & Remediation model; empty = not yet reviewed.
24h active ruleAgent with >=1 recorded event in the trailing 24 hours on a monitored platform.
30d stale KRISeparate metric: agent idle >=30 days (identity may be orphaned).
scope_countsEstate-wide deduplicated agent identities from the Agentic Discovery inventory.
P90 tool calls90th percentile tool-call volume; agents above this are outliers for abuse review.
KRIKey Risk Indicator - a metric tracked quarter-to-quarter for board and CISO oversight.