Agentic Security Explorer (ASE)

Learn Agentic Attack Surfaces, Risks, and Business Impact

Business Guide - Components

Component Guide

Each card explains what the component is, why it matters, what can go wrong, and the business impacts to consider.

Central Planner

Orchestrator

Breaks the top-level goal into subtasks and decides which agent or tool handles each one.

Why it matters: Orchestrator helps the organization use agentic AI capabilities while preserving continuity, control, and accountability.

Business value

  • Faster workflows
  • Reduced manual effort
  • Improved continuity
  • Scalable decision support

Business impact

Control weaknessData exposureFinancial lossOperational disruptionOperational impactRegulatory exposureReputation damage

What could go wrong

  • Goal manipulation via prompt injection
  • Single point of failure
  • Insecure delegation logic
Task Workers

Sub-Agents

Specialized agents that carry out the subtasks the orchestrator assigns.

Why it matters: Sub-Agents helps the organization use agentic AI capabilities while preserving continuity, control, and accountability.

Business value

  • Faster workflows
  • Reduced manual effort
  • Improved continuity
  • Scalable decision support

Business impact

Control weaknessData exposureFinancial lossOperational disruptionOperational impactRegulatory exposureReputation damage

What could go wrong

  • Excessive agency
  • Role confusion / impersonation
  • Insecure inter-agent trust
Function Execution

Tool-Calling Layer

The interface agents use to call external functions, APIs, and code.

Why it matters: Tool-Calling Layer helps the organization use agentic AI capabilities while preserving continuity, control, and accountability.

Business value

  • Faster workflows
  • Reduced manual effort
  • Improved continuity
  • Scalable decision support

Business impact

Control weaknessData exposureFinancial lossOperational disruptionOperational impactRegulatory exposureReputation damage

What could go wrong

  • Tool poisoning
  • Arbitrary code execution
  • Unvalidated trust in tool output
State & Recall

Memory / Context Store

Persists conversation history, long-term memory, and embeddings across turns and sessions.

Why it matters: Memory / Context Store helps the organization use agentic AI capabilities while preserving continuity, control, and accountability.

Business value

  • Faster workflows
  • Reduced manual effort
  • Improved continuity
  • Scalable decision support

Business impact

Control weaknessData exposureFinancial lossOperational disruptionOperational impactRegulatory exposureReputation damage

What could go wrong

  • Memory poisoning
  • Cross-session data leakage
  • Persistent prompt injection
Message Bus

Inter-Agent Comms

The channel agents use to pass messages, requests, and results to one another.

Why it matters: Inter-Agent Comms helps the organization use agentic AI capabilities while preserving continuity, control, and accountability.

Business value

  • Faster workflows
  • Reduced manual effort
  • Improved continuity
  • Scalable decision support

Business impact

Control weaknessData exposureFinancial lossLimited business impactMonitoring gapOperational disruptionOperational impactProcess inefficiencyRegulatory exposureReputation damage

What could go wrong

  • Man-in-the-middle injection
  • Message spoofing
  • Lack of message integrity checks
Knowledge Grounding

Retrieval / RAG

Fetches external documents or data to ground agent responses in current information.

Why it matters: Retrieval / RAG helps the organization use agentic AI capabilities while preserving continuity, control, and accountability.

Business value

  • Faster workflows
  • Reduced manual effort
  • Improved continuity
  • Scalable decision support

Business impact

Control weaknessData exposureFinancial lossLimited business impactMonitoring gapOperational disruptionOperational impactProcess inefficiencyRegulatory exposureReputation damage

What could go wrong

  • Indirect prompt injection via retrieved content
  • Data poisoning of the knowledge base
  • Source spoofing
Runtime Isolation

Execution Sandbox

Isolates code execution, browsing, and file operations from the host and from other agents.

Why it matters: Execution Sandbox helps the organization use agentic AI capabilities while preserving continuity, control, and accountability.

Business value

  • Faster workflows
  • Reduced manual effort
  • Improved continuity
  • Scalable decision support

Business impact

Control weaknessData exposureFinancial lossOperational disruptionOperational impactRegulatory exposureReputation damage

What could go wrong

  • Sandbox escape
  • Privilege escalation
  • Insufficient isolation between agents
Third-Party APIs

External Integrations

Connections to outside services — email, calendars, payments, ticketing, and more.

Why it matters: External Integrations helps the organization use agentic AI capabilities while preserving continuity, control, and accountability.

Business value

  • Faster workflows
  • Reduced manual effort
  • Improved continuity
  • Scalable decision support

Business impact

Control weaknessData exposureFinancial lossOperational disruptionOperational impactRegulatory exposureReputation damage

What could go wrong

  • Data exfiltration via a legitimate channel
  • Over-permissioned API scopes
  • Third-party supply chain compromise
Auth Material

Credentials & Secrets

API keys, tokens, and service credentials that let agents authenticate to tools and integrations.

Why it matters: Credentials & Secrets helps the organization use agentic AI capabilities while preserving continuity, control, and accountability.

Business value

  • Faster workflows
  • Reduced manual effort
  • Improved continuity
  • Scalable decision support

Business impact

Control weaknessData exposureFinancial lossOperational disruptionOperational impactRegulatory exposureReputation damage

What could go wrong

  • Secret leakage via logs or output
  • Long-lived static credentials
  • Credential reuse across agents
Approval Gate

Human-in-the-Loop

Checkpoints where a person reviews or approves an agent's proposed action before it executes.

Why it matters: Human-in-the-Loop helps the organization use agentic AI capabilities while preserving continuity, control, and accountability.

Business value

  • Faster workflows
  • Reduced manual effort
  • Improved continuity
  • Scalable decision support

Business impact

Control weaknessData exposureFinancial lossLimited business impactMonitoring gapOperational disruptionOperational impactProcess inefficiencyRegulatory exposureReputation damage

What could go wrong

  • Bypassable confirmation step
  • Approval fatigue / rubber-stamping
  • Unclear accountability
Authority Plane

Agent Identity & AuthZ

Issues, verifies, scopes, and revokes agent identities and delegated authority for actions.

Why it matters: Agent Identity & AuthZ helps the organization use agentic AI capabilities while preserving continuity, control, and accountability.

Business value

  • Faster workflows
  • Reduced manual effort
  • Improved continuity
  • Scalable decision support

Business impact

Control weaknessData exposureFinancial lossOperational disruptionOperational impactRegulatory exposureReputation damage

What could go wrong

  • Rogue agent registration
  • Broken delegated authorization
  • Stale or revoked token reuse
Behavior Packages

Agent Skills / MCP Registry

Reusable skills, MCP servers, manifests, and workflow packages that define what agents can do and how they do it.

Why it matters: Agent Skills / MCP Registry helps the organization use agentic AI capabilities while preserving continuity, control, and accountability.

Business value

  • Faster workflows
  • Reduced manual effort
  • Improved continuity
  • Scalable decision support

Business impact

Control weaknessData exposureFinancial lossOperational disruptionOperational impactRegulatory exposureReputation damage

What could go wrong

  • Malicious skill or MCP package installation
  • Skill typosquatting / brand impersonation
  • Unsigned or unpinned skill update
Instruction/Data Split

Context Boundary & Provenance

Separates instructions from data and preserves evidence, source, and trust level as context moves across agents and tools.

Why it matters: Context Boundary & Provenance helps the organization use agentic AI capabilities while preserving continuity, control, and accountability.

Business value

  • Faster workflows
  • Reduced manual effort
  • Improved continuity
  • Scalable decision support

Business impact

Control weaknessData exposureFinancial lossOperational disruptionOperational impactRegulatory exposureReputation damage

What could go wrong

  • Context boundary collapse
  • Provenance loss across hops
  • Evidence laundering through summaries
Reasoning Runtime

Model / Inference Routing

Selects model, prompt template, policy tier, context window, and fallback behavior for agent reasoning.

Why it matters: Model / Inference Routing helps the organization use agentic AI capabilities while preserving continuity, control, and accountability.

Business value

  • Faster workflows
  • Reduced manual effort
  • Improved continuity
  • Scalable decision support

Business impact

Control weaknessData exposureFinancial lossLimited business impactMonitoring gapOperational disruptionOperational impactProcess inefficiencyRegulatory exposureReputation damage

What could go wrong

  • Prompt template injection
  • Unsafe model fallback
  • Unbounded reasoning / denial of wallet
Outbound Surface

Output & Egress Channels

Represents every route through which the agent sends content, files, actions, records, or instructions outward.

Why it matters: Output & Egress Channels helps the organization use agentic AI capabilities while preserving continuity, control, and accountability.

Business value

  • Faster workflows
  • Reduced manual effort
  • Improved continuity
  • Scalable decision support

Business impact

Control weaknessData exposureFinancial lossOperational disruptionOperational impactRegulatory exposureReputation damage

What could go wrong

  • Covert exfiltration through normal output
  • Malicious generated artifact
  • Downstream automation abuse
TrustOps

Agent Lifecycle & Governance

Tracks agent inventory, owners, versions, approvals, deployment state, rollback paths, and emergency disablement.

Why it matters: Agent Lifecycle & Governance helps the organization use agentic AI capabilities while preserving continuity, control, and accountability.

Business value

  • Faster workflows
  • Reduced manual effort
  • Improved continuity
  • Scalable decision support

Business impact

Control weaknessData exposureFinancial lossLimited business impactMonitoring gapOperational disruptionOperational impactProcess inefficiencyRegulatory exposureReputation damage

What could go wrong

  • Missing kill switch or rollback path
  • Shadow agents outside governance
  • Untracked agent version drift
Forensic Plane

Telemetry Integrity & Evidence

Captures tamper-resistant evidence of plans, prompts, retrieved context, tool calls, approvals, outputs, and policy decisions.

Why it matters: Telemetry Integrity & Evidence helps the organization use agentic AI capabilities while preserving continuity, control, and accountability.

Business value

  • Faster workflows
  • Reduced manual effort
  • Improved continuity
  • Scalable decision support

Business impact

Control weaknessData exposureFinancial lossLimited business impactMonitoring gapOperational disruptionOperational impactProcess inefficiencyRegulatory exposureReputation damage

What could go wrong

  • Agent-generated telemetry tampering
  • Incomplete replayability
  • Non-repudiation failure
Policy & Observability

Guardrails & Monitoring

Policy enforcement, logging, and anomaly detection layered across the whole system.

Why it matters: Guardrails & Monitoring helps the organization use agentic AI capabilities while preserving continuity, control, and accountability.

Business value

  • Faster workflows
  • Reduced manual effort
  • Improved continuity
  • Scalable decision support

Business impact

Control weaknessData exposureFinancial lossOperational disruptionOperational impactRegulatory exposureReputation damage

What could go wrong

  • Guardrail bypass via obfuscation
  • Blind spots / incomplete logging
  • Telemetry tampering / false audit trail