CASE STUDY Β· AI SECURITY
AI agent security & governance: securing AI agents before they become business risks.
Illustrative scenario Β· Sector: Enterprise AI and cybersecurity Β· Solution partner: Brandsmashers Tech
- 120Internal AI agents across support, finance, HR and engineering
- 34 β <10Target for agents with broader permissions than they need
01 Β· PROJECT OVERVIEW
A new kind of security problem.
Traditional software generally performs actions according to predefined permissions. Autonomous or semi-autonomous agents can interpret instructions, call tools, access information and potentially trigger actions across multiple systems.
As organisations deploy more agents, the goal is to make AI adoption scalable without allowing autonomy to outpace governance.
- Building a continuous inventory of agents, owners, tools and data sources
- Giving every agent an identity and least-privilege permissions
- Governing tool calls and defending against prompt injection
- Making agent actions auditable, with human approval for sensitive operations
- 1Which agents exist, and what systems can they access?
- 2What actions can they perform, and who authorised them?
- 3Can every action be audited, including when an agent behaves unexpectedly?
02 Β· THE CHALLENGE
Deployment outpaced governance.
Consider an enterprise operating 120 internal AI agents across support, finance, HR and engineering. A governance assessment identifies four gaps.
- FINDING 0134 over-permissioned agents
34 agents hold broader permissions than their workflows require, widening the damage a mistake or a malicious instruction could cause.
- FINDING 0218 agents with high-risk actions
18 agents can perform high-risk actions without a person approving them first.
- FINDING 03Partial production logging
Not every agent action and tool call is logged, so incidents are slow to investigate.
- FINDING 04Ad-hoc access reviews
Permissions are reviewed when someone remembers, not on a schedule, so drift goes unnoticed.
Before an AI agent gets more autonomy, give it better controls.
03 Β· THE APPROACH
Seven controls for governed autonomy.
A structured AI security programme that treats agents as accountable identities rather than anonymous automation.
- 01Agent inventory
A continuously updated inventory of deployed agents, owners, environments, tools and data sources.
- 02Identity and access management
Every agent gets a defined identity rather than being treated as anonymous automation.
- 03Least privilege
An agent receives only the permissions necessary for its assigned workflow.
- 04Tool authorisation
Every external tool or API call is governed by explicit authorisation policies.
- 05Prompt-injection protection
Defences against malicious instructions embedded in documents, websites, emails or other inputs.
- 06Auditability and human approval
Agent actions, tool calls and high-risk decisions are traceable, and sensitive operations need explicit human authorisation.
- 1βInventory
- 2βIdentity
- 3βLeast privilege
- 4βTool authorisation
- 5βInjection defence
- 6βAudit
- 7Human approval
04 Β· RESULTS
The target state.
Better visibility, stronger access control and controlled autonomy, so new agents can be added without adding unmanaged risk.
| CONTROL | CURRENT | TARGET |
|---|---|---|
| Agents inventoried | 120 | 120 plus continuous inventory |
| Broad permissions | 34 agents | Fewer than 10 |
| High-risk actions | 18 agents, unapproved | Human approval required |
| Production logs | Partial | 100% |
| Access reviews | Ad hoc | Quarterly |
Scenario figures are illustrative governance targets, not measured Brandsmashers results. The underlying market context comes from Gartnerβs 2026 AI-agent governance research.
- <10Agents with broad permissionsFrom 34 in the assessment.
- ApprovedHigh-risk actionsAll 18 behind human approval.
- 100%Production loggingFrom partial coverage.
- QuarterlyAccess reviewsFrom ad hoc.
- ContinuousAgent inventoryAll 120 agents, kept up to date.
- Visibility
Every agent, owner, tool and data source is known.
- Stronger access control
Fewer excessive permissions and explicit tool authorisation.
- Faster investigations
Complete logs make incidents traceable.
- Controlled autonomy
Sensitive actions wait for a person; routine ones run.
05 Β· DELIVERABLES
How Brandsmashers would build it.
- Agent inventoryA continuously updated register of agents, owners, environments, tools and data sources.
- Identity and accessAgent identities, least-privilege roles and scheduled access reviews.
- Tool authorisationExplicit policies governing every external tool and API call.
- Prompt-injection defencesInput handling and checks for instructions hidden in external content.
- Audit and approvalTraceable actions and tool calls, with human sign-off for sensitive operations.
- Security
- Identity and access managementLeast privilegeAccess reviews
- AI
- Agent frameworksTool authorisationPrompt-injection defences
- Cloud
- Cloud IAMSecrets managementNetwork controls
- Operations
- Audit loggingMonitoringIncident investigation
TAKEAWAYS
Why Brandsmashers.
- 01Inventory every agent before adding more.
- 02Give each agent an identity and only the permissions it needs.
- 03Authorise tools explicitly and defend against injected instructions.
- 04Log everything, and keep a human on high-risk actions.
- Enterprise AI programmes
- Financial services
- Healthcare
- SaaS
- Shared services
YOUR TURN
Scaling AI agents safely?
Brandsmashers brings together AI engineers, cloud engineers, security specialists and software developers to build AI systems with security controls designed into the architecture.