The Maturity Model
Five levels across ten domains, scored as the minimum rather than the average, with Level 2 as the minimum defensible bar.
Five levels across ten control domains. An organization’s overall level is the minimum across domains, not the average—a deliberate design choice, because agent security fails at its weakest boundary and an arithmetic mean conceals exactly the gap that matters.
5.1 Level Definitions #
The starting position is low almost everywhere. In a 2026 survey of 235 large-enterprise CISOs and CIOs, 92 percent reported lacking full visibility into their AI agent identities and 95 percent doubted they could detect or contain a compromised agent.7 Only 13 percent of organizations consider their agent governance adequate, against a projection that the average Fortune 500 firm will operate more than 150,000 agents by 2028, up from fewer than 15 in 2025.8 Nearly two-thirds apply weaker controls to agents than to human employees.9 Forrester now ranks AI agent threats as the top CISO risk for 2026, framing several of the new categories as self-inflicted—introduced by organizations deploying agents without governance controls.10
Realistic targets: Level 2 is the minimum defensible bar for any production agent touching enterprise data. Level 3 is the target for organizations at scale or in regulated sectors. Level 4 is appropriate where agents operate at T3–T4 autonomy on critical systems.
5.2 Maturity Grid #
| Domain | L0 | L1 | L2 | L3 | L4 |
|---|---|---|---|---|---|
| DISC — Discovery & Inventory | None | Manual list of known agents | Complete registry of managed agents with owners | Automated discovery incl. unmanaged/shadow agents | Continuous discovery with drift alerting |
| AUTH — Identity & Authorization | Shared service accounts | Distinct accounts, manual | Unique agent principal per deployment; lifecycle defined | Task-scoped delegation; automated deprovisioning | Continuous authorization; risk-adaptive access |
| CRED — Credentials & Secrets | Static keys in config | Vaulted but long-lived | Vaulted, rotated, scoped | Ephemeral, task-scoped, no standing secrets in runtime | Just-in-time issuance with per-action attestation |
| ISO — Isolation & Egress | Shared runtime, open egress | Containerized; egress partly restricted | Per-agent isolation; default-deny egress with allowlist | Egress domains segmented by trust tier; no shared network path | Micro-segmented, ephemeral, attested runtimes |
| TOOL — Tool & Action Authorization | Prompt-based restriction only | Static tool list per agent | Enforced tool allowlist outside the model | Deterministic per-call policy engine; velocity + blast-radius ceilings | Context-aware authorization with automated escalation |
| DATA — Data, Memory & Context | Unscoped retrieval; unbounded memory | Data classification applied manually | Retrieval scoped to invoking principal; memory TTL | Provenance labeling; memory write authorization; session isolation | Continuous context integrity verification |
| SUP — Supply Chain | Unvetted tools and models | Inventory of models and tools | Approved registry; pinned versions; MCP servers reviewed | Signed artifacts; provenance verified; automated drift detection | Continuous attestation across model, tool, and MCP surface |
| OBS — Observability & Detection | Prompt logs only, if any | Action logs collected, unread | Centralized action telemetry with alerting | Automated anomaly detection on action streams; halting controls | Behavioral baselining per agent; predictive containment |
| RESP — IR & Forensics | No agent-specific plan | Plan drafted, untested | Agent scenarios in IR plan; kill switch exists and is tested | Self-hosted forensic capability staged; tested on real artifacts | Rehearsed at scale; automated evidence preservation |
| GOV — Oversight & Governance | None | Policy exists | Tiering applied; review board operating | Independent assurance; metrics reported to executive | Continuous assurance; autonomy decisions data-driven |
| RET — Decommissioning & Retirement | Agents abandoned, never removed | Ad hoc teardown on request | Decommission criteria recorded; retirement executed and evidenced | Automated teardown of credentials, data, and integrations | Continuous detection of orphaned agents, grants, and stores |
References cited in this section
4 of 32 · numbering matches the PDF
- 7"The AI Agent Governance Gap: What CISOs Need Now," Cloud Security Alliance Lab Space, April 2026, reporting the 2026 CISO AI Risk Report survey of 235 large-enterprise CISOs and CIOs.labs.cloudsecurityalliance.org/research/csa-research-note-ai-agent-governance-framework-gap-20260403 ↗
- 8"Top Cybersecurity Trends 2026," Gartner, April 28, 2026, as reported by the Cloud Security Alliance. †www.gartner.com/en/topics/cybersecurity ↗
- 9"AI Agents at Work 2026: Securing the Agentic Enterprise," Okta, June 2, 2026. †www.okta.com/resources ↗
- 10"Top Cybersecurity Threats 2026," Forrester Research, as reported in Cybersecurity Insiders, July 2026. †www.forrester.com/technology/security-risk ↗