CERTIV FIELD GUIDE · AUGUST 2026

AI agent security,
organized for action.

The useful guidance is scattered across standards bodies, security teams, cloud vendors, and research papers. This guide turns it into a practical reading path and a control plan you can use.

Explore the field guide ↓ 9 selected resources · 4 control layers · 8 min read
THE SIGNAL

Agents change the unit of risk

Traditional software waits for inputs. Agents interpret context, choose tools, and take sequences of actions. The security question is no longer only “is the model safe?” It is “what can this identity see, decide, and do, and can we intervene?”

01

Untrusted context

Web pages, tickets, documents, code, and messages can become instructions through indirect prompt injection.

02

Compounding privilege

Individually safe tools can form an unsafe chain when an agent combines access across systems.

03

Machine-speed action

Errors propagate faster when agents can write files, change infrastructure, send data, or approve workflows.

04

Invisible execution

Endpoint controls see processes. SaaS logs see API calls. Neither alone explains the agent’s intent and full action path.

CURATED READING PATH

Read less. Apply more.

Selected for authority and practical value, not volume. Start with the first three, then choose the material closest to your role.

01
Start here Security leaders

NIST: Security considerations for AI agents

The clearest current view of the agent-security problem space: identity, authorization, data, monitoring, and human oversight.

GovernanceIdentity
NIST CAISI
02
Start here Security engineers

OWASP Agentic AI threats and mitigations

A practical threat model for planning reviews, controls, and red-team exercises around autonomous systems.

Threat modelControls
OWASP GenAI Security Project
03
Start here Platform teams

MCP security design considerations

Implementation guidance for the protocol layer connecting agents to tools, data, and privileged actions.

MCPArchitecture
NSA AI Security Center
04
Build safely Developers

Agent safety engineering guidance

Concrete development patterns: constrain tool arguments, isolate execution, validate outputs, and design explicit approvals.

EngineeringPrompt injection
Microsoft
05
Build safely Web teams

Security considerations for WebMCP

A useful browser-agent model covering untrusted page content, tool exposure, confirmations, and data boundaries.

Browser agentsMCP
Chrome for Developers
06
Build safely Cloud teams

AI security and safety for MCP servers

Operational guidance for permissions, irreversible actions, tool chaining, and treating agent behavior as part of the trust boundary.

CloudLeast privilege
Google Cloud
07
Test & validate Red teams

MITRE ATLAS

A shared language for adversary tactics and techniques against AI-enabled systems, useful for test plans and incident mapping.

Adversary emulationDetection
MITRE
08
Test & validate Researchers

Breaking the Protocol: security analysis of MCP

Research on capability attestation, origin authentication, and trust propagation in multi-server agent environments.

ResearchMCP
arXiv
09
Test & validate AppSec teams

Prompt injection in agentic coding assistants

A systematic analysis spanning skills, tools, and protocol ecosystems, with implications for architectural defenses.

Coding agentsPrompt injection
arXiv
FROM READING TO READINESS

A four-layer operating model

A resource list is only useful if it changes the system. These are the control layers we think every organization deploying agents needs.

01

Know what exists

Inventory agents, models, MCP servers, tools, credentials, owners, and the environments where each can act.

02

Constrain the blast radius

Use task-scoped identity, least privilege, short-lived secrets, sandboxing, egress controls, and explicit action boundaries.

03

Observe decisions and actions

Capture prompts, tool calls, policy decisions, approvals, data movement, and outcomes in one reviewable timeline.

04

Respond at runtime

Block unsafe behavior in the moment, preserve evidence, revoke access, and turn incidents into stronger policy.

30-MINUTE BASELINE

Six questions to ask this week

If any answer is “we don’t know,” you have found the next piece of work.

  1. 01Can we name every agent running in our environment?
  2. 02Do we know which tools, data, and credentials each agent can access?
  3. 03Can untrusted content influence a privileged action?
  4. 04Are approvals bound to the exact action, arguments, and destination?
  5. 05Can we reconstruct an agent session from intent through outcome?
  6. 06Can we stop a risky action before it executes?
CERTIV RUNTIME ASSURANCE

See what your agents do.
Control what happens next.

Discover agent activity, understand intent, and enforce policy across the full automation lifecycle.

Request a demo →