Securing Agentic AI in the Enterprise.
A maturity and decision framework for security, platform, and risk leaders — ten control domains, five maturity levels, five autonomy tiers, and a production gate.
The thesis
Most enterprise AI security guidance published before 2026 was written for a different technology. It assumes a model that answers questions. It does not account for a system that plans, holds credentials, invokes tools, remembers across sessions, and acts on infrastructure without a human in the loop for each step.
Controls must bound what an agent *can* do, not depend on predicting what it *will* do. Design as though the agent will attempt every action its permissions allow, because under sufficient optimization pressure it eventually will.
Written to be usable by an organization that has not yet started, and by one that has 40,000 agents it did not authorize.
Read Section 1 →The three scales
Ten control domains, and two ordered instruments everything after Part I is scored on. The domains are a set; the levels and the tiers are scales, and they are not interchangeable.
Overall level is the minimum across domains, never the average.
Tier attaches to a deployment, not to a product.
The 4 parts
25 sectionsScope and Models
Scope, definitions, the threat model, autonomy tiering, and the five maturity levels.
The Control Domains
The eleven control domains in detail, from discovery and identity through to retirement, oversight, and assurance.
Assurance and Adoption
The production gate, incident response, metrics, procurement, the standards crosswalk, and a sequenced roadmap.
Appendices and References
Glossary, executive summary, and reference sources.
Contents · Securing Agentic AI in the Enterprise
v1.3The complete framework, typeset for print.
All 25 sections, the control domains, the production gate, the standards crosswalk, and 32 reference sources in a single PDF.