Section 5 of 25 3 min read

The Maturity Model

Five levels across ten domains, scored as the minimum rather than the average, with Level 2 as the minimum defensible bar.

Five levels across ten control domains. An organization’s overall level is the minimum across domains, not the average—a deliberate design choice, because agent security fails at its weakest boundary and an arithmetic mean conceals exactly the gap that matters.

5.1 Level Definitions #

L0Unmanaged
Agents exist; nobody knows how many. No agent-specific controls. Governance is aspirational.
L1Aware
Partial inventory exists. Policy drafted. Controls are manual, inconsistent, and applied to known agents only.
L2Controlled
Complete inventory of managed agents. Identity, credential, and isolation baselines enforced at deployment. Detection is present but human-paced.
L3Enforced
Deterministic runtime enforcement at the action boundary. Ephemeral credentials standard. Automated detection with halting controls. Discovery covers unmanaged agents.
L4Adaptive
Continuous verification, behavioral baselining, automated response, tested forensic capability, and measured control efficacy. Autonomy expansion is data-driven.

The starting position is low almost everywhere. In a 2026 survey of 235 large-enterprise CISOs and CIOs, 92 percent reported lacking full visibility into their AI agent identities and 95 percent doubted they could detect or contain a compromised agent.7 Only 13 percent of organizations consider their agent governance adequate, against a projection that the average Fortune 500 firm will operate more than 150,000 agents by 2028, up from fewer than 15 in 2025.8 Nearly two-thirds apply weaker controls to agents than to human employees.9 Forrester now ranks AI agent threats as the top CISO risk for 2026, framing several of the new categories as self-inflicted—introduced by organizations deploying agents without governance controls.10

Realistic targets: Level 2 is the minimum defensible bar for any production agent touching enterprise data. Level 3 is the target for organizations at scale or in regulated sectors. Level 4 is appropriate where agents operate at T3–T4 autonomy on critical systems.

5.2 Maturity Grid #

DomainL0L1L2L3L4
DISC — Discovery & InventoryNoneManual list of known agentsComplete registry of managed agents with ownersAutomated discovery incl. unmanaged/shadow agentsContinuous discovery with drift alerting
AUTH — Identity & AuthorizationShared service accountsDistinct accounts, manualUnique agent principal per deployment; lifecycle definedTask-scoped delegation; automated deprovisioningContinuous authorization; risk-adaptive access
CRED — Credentials & SecretsStatic keys in configVaulted but long-livedVaulted, rotated, scopedEphemeral, task-scoped, no standing secrets in runtimeJust-in-time issuance with per-action attestation
ISO — Isolation & EgressShared runtime, open egressContainerized; egress partly restrictedPer-agent isolation; default-deny egress with allowlistEgress domains segmented by trust tier; no shared network pathMicro-segmented, ephemeral, attested runtimes
TOOL — Tool & Action AuthorizationPrompt-based restriction onlyStatic tool list per agentEnforced tool allowlist outside the modelDeterministic per-call policy engine; velocity + blast-radius ceilingsContext-aware authorization with automated escalation
DATA — Data, Memory & ContextUnscoped retrieval; unbounded memoryData classification applied manuallyRetrieval scoped to invoking principal; memory TTLProvenance labeling; memory write authorization; session isolationContinuous context integrity verification
SUP — Supply ChainUnvetted tools and modelsInventory of models and toolsApproved registry; pinned versions; MCP servers reviewedSigned artifacts; provenance verified; automated drift detectionContinuous attestation across model, tool, and MCP surface
OBS — Observability & DetectionPrompt logs only, if anyAction logs collected, unreadCentralized action telemetry with alertingAutomated anomaly detection on action streams; halting controlsBehavioral baselining per agent; predictive containment
RESP — IR & ForensicsNo agent-specific planPlan drafted, untestedAgent scenarios in IR plan; kill switch exists and is testedSelf-hosted forensic capability staged; tested on real artifactsRehearsed at scale; automated evidence preservation
GOV — Oversight & GovernanceNonePolicy existsTiering applied; review board operatingIndependent assurance; metrics reported to executiveContinuous assurance; autonomy decisions data-driven
RET — Decommissioning & RetirementAgents abandoned, never removedAd hoc teardown on requestDecommission criteria recorded; retirement executed and evidencedAutomated teardown of credentials, data, and integrationsContinuous detection of orphaned agents, grants, and stores

References cited in this section

4 of 32 · numbering matches the PDF

  1. 7"The AI Agent Governance Gap: What CISOs Need Now," Cloud Security Alliance Lab Space, April 2026, reporting the 2026 CISO AI Risk Report survey of 235 large-enterprise CISOs and CIOs.labs.cloudsecurityalliance.org/research/csa-research-note-ai-agent-governance-framework-gap-20260403 ↗
  2. 8"Top Cybersecurity Trends 2026," Gartner, April 28, 2026, as reported by the Cloud Security Alliance. †www.gartner.com/en/topics/cybersecurity ↗
  3. 9"AI Agents at Work 2026: Securing the Agentic Enterprise," Okta, June 2, 2026. †www.okta.com/resources ↗
  4. 10"Top Cybersecurity Threats 2026," Forrester Research, as reported in Cybersecurity Insiders, July 2026. †www.forrester.com/technology/security-risk ↗
PDF