The Defender’s Guide to AI Agents·Chapter 7

AI Agent Security Controls, in Order of Leverage

What to prevent

Detection tells you afterwards. These change what is possible in the first place, and they are listed in order of leverage - how much risk each one removes for the effort it costs.

Control one, and it is not close: the identity that reads untrusted content must not be the identity that acts on consequential systems.

Split them. One agent reads the email, the web, the tickets, the documents - and can do nothing but produce a proposal. A separate agent, which never touches outside content, carries the permissions that matter and acts only on proposals that have passed whatever gate you set.

Every other control on this page makes a compromised agent less powerful. This one makes it structurally unable to do the thing you are afraid of. Under this split, a perfect prompt injection - one your filters would never catch, written by someone better than you - produces a suggestion. That is the whole difference between a bad afternoon and a breach.

It is also the one nobody does, because it is an architecture decision rather than a setting, and it has to be made before the thing is built.

#ControlWhat it means in practiceWhat it buys you
2 Its own identity, with an expiry date Every agent gets its own account. Never a shared service account, never a human's credentials, always a named human owner, always an expiry that forces someone to re-justify it. Makes every other control possible. You cannot scope, monitor or revoke what you cannot name.
3 Narrow keys, short lives, short destination lists The credential reaches only what the job needs, expires in hours rather than never, and can connect only to an explicitly written list of places. Caps the damage of a stolen key and gives detection three something to compare against.
4 A fixed list of tools, pinned to a version Tools and plug-ins are approved individually, pinned to a specific version, and cannot update themselves. Adding one is a change, with a person's name on it. Closes the case in Chapter 3, where something benign for fifteen versions turns hostile at the sixteenth.
5 Rules about what may be remembered Every memory carries where it came from. Memories expire. An agent that reads outside content may not write to any store a more privileged agent reads. Removes the delayed attack and the privilege jump in Chapter 3, neither of which you can currently detect.
6 An authority ladder for consequential actions Low-impact, low-reach actions are pre-authorized and happen instantly. Larger ones need one named approver. The largest need two. Written down before the incident, not during it. Speed where it is safe and friction only where it is earned - instead of the usual choice between approving everything and approving nothing.
7 Deploy in order of reversibility Start read-only. Then let it write to things that can be undone in one step - drafts, tickets, branches, staging. Only then, consequential systems under the ladder above. Turns a large irreversible bet into a series of small reversible ones. See Chapter 10.

If you only do three things.

Split the identity that reads from the identity that acts. Everything else is damage limitation; this is the one that changes the outcome.

Write down where each agent may connect, and enforce it. One list, per agent, shorter than you expect.

Collect the six events from Chapter 5. Not because they detect anything on their own, but because every future option depends on having them, and the day you need them is not the day you can start.

Say this on Monday

"Which of our agents both reads outside content and holds real permissions? Those are the ones to split first - everything else can wait."

About the author

Jessen Kurien is a cybersecurity leader and the author of The Defender’s Guide to AI Agents. His 18+ years in cybersecurity include nearly 15 years at Microsoft, work as part of the founding team of the Microsoft Threat Intelligence Center, and detection engineering leadership in Microsoft Defender XDR. His work connects investigations, detection engineering and security operations with the evidence and accountability needed for AI security and governance.

Meet Jessen

Connect with Jessen Speaking, workshops and training

This guide will go out of date.

Providers change how their logs work, models get retired, and new cases get disclosed. Ask to be told when this changes — no newsletter, just the updates.

Get told when it changes

Download the complete guide (PDF)

The telemetry contract, detection specifications, framework mappings and checklists are also published as files — the defender pack, CC BY 4.0, free to reuse.