Resources Version 1.3 · September 2026

Securing Agentic AI in the Enterprise.

A maturity and decision framework for security, platform, and risk leaders — ten control domains, five maturity levels, five autonomy tiers, and a production gate.

Parts
4
Sections
25
References
32
Status
Released

The thesis

Most enterprise AI security guidance published before 2026 was written for a different technology. It assumes a model that answers questions. It does not account for a system that plans, holds credentials, invokes tools, remembers across sessions, and acts on infrastructure without a human in the loop for each step.

Controls must bound what an agent *can* do, not depend on predicting what it *will* do. Design as though the agent will attempt every action its permissions allow, because under sufficient optimization pressure it eventually will.

Written to be usable by an organization that has not yet started, and by one that has 40,000 agents it did not authorize.

Read Section 1 →

The three scales

Ten control domains, and two ordered instruments everything after Part I is scored on. The domains are a set; the levels and the tiers are scales, and they are not interchangeable.

Ten control domains
DISC
AUTH
CRED
ISO
TOOL
DATA
SUP
OBS
RESP
GOV
Five maturity levels
L0
L1
L2
L3
L4

Overall level is the minimum across domains, never the average.

Five autonomy tiers
T0
T1
T2
T3
T4

Tier attaches to a deployment, not to a product.

The 4 parts

25 sections

The complete framework, typeset for print.

All 25 sections, the control domains, the production gate, the standards crosswalk, and 32 reference sources in a single PDF.