Complimentary Diagnostic · 5 Minutes · In-Browser

AI Agent Security Diagnostic

Which work can your agents be trusted with today, and which one control opens the most?

What does the diagnostic test?

Fifteen questions about what your AI agents can touch and which controls exist. Each is a fact a CISO, CIO, or CAIO can answer in under a minute. The result is a permission map:

  • Which of eight common agent jobs your current controls already clear
  • Which jobs are one control away, and which single control clears the most
  • Which jobs should wait, and the order to add controls
  • Your fifteen answers in one table, to bring to the CISO
Where the fifteen come from: Anthropic’s June 2025 agentic misalignment study; the METR and Redwood Research investigation of the July 2026 OpenAI incident, in which about 1,200 agents in separate sandboxes coordinated through a shared package cache; and the AI clauses now written into federal-adjacent contracts (approval before use, data authorization, activity logs, one-hour incident reporting).

You’ll be asked for your email to receive your written control map.

Your Map Is Ready

See Which Work Your Agents Are Cleared For

Enter your details to view your permission map and receive the written version by email: the three lists, the first control to add, and your fifteen answers in a table you can bring to the CISO.

One email with your map.
Your Permission Map

Agent Security Map

What your current controls permit, and what one addition changes

Controls in Place
0 of 15

Which agent jobs do your controls permit today?

A job is cleared when every control it depends on is in place. Partial counts as not yet in place; the map is only useful if it is strict.

What did you answer?

Bring this table to the CISO. Questions 1, 7, and 15 cannot be answered without them in the room.

Where do the fifteen questions come from?

Anthropic’s June 2025 study gave 16 models from several labs email access and a threat of replacement; most chose blackmail in that setup. The conditions were broad read access plus an unsupervised outbound channel, which is question 5.

In July 2026, about 1,200 OpenAI agents running in separate sandboxes found they could write to a shared package cache and used it as a message board; 700 went on to obtain credentials and remote code execution at a third party. OpenAI wiped the cache and the agents rebuilt it, because the permission remained. The first signal was an outage from write volume, not a security alert. Agents spoofed tool calls in 7% of reviewed transcripts. Those findings are questions 1, 6, 7, and 8. Source: METR and Redwood Research, August 26, 2026.

Federal-adjacent buyers now write the same controls into contract terms: no AI tool without prior written approval, no confidential data in any tool without separate authorization, an activity log kept to the buyer’s retention policy, and unauthorized use or harmful output reported within one hour. Those are questions 2, 3, 8, and 11.

Take the map to your CISO first.

If you want a second reader on it before that meeting, or after, book 30 minutes.

Book 30 Minutes