Securing Agents – New Challenge for Security Teams

Agents are rapidly moving from developer-led experimentation to business-user adoption. With agent-building platforms making it easier to create and deploy agents, organizations are likely to see agents being developed at increasing scale and through different channels. Agents, more of a small application or performing a particular task can pose same risk as small marketplace applications. This creates a fundamental question - How should an organization review an agent when the way it is built, deployed, and managed can be very different? 

The answer starts with understanding the type of agents and the platforms through which it is created or distributed.

Agent Platforms

 

No-Code Agent Building Platforms

These platforms allow business users to create agents through visual interfaces, with little or no traditional coding. The security of these agents is closely tied to the security controls and configuration of the underlying platform. The focus therefore extends beyond the individual agent to how users, tools, data sources and integrations are governed by the platform. User’s who are writing agents are business users so expecting them to write it securely is a biggest mistake. 

Low-Code Agent Building Platforms

Low-code platforms provide pre-built capabilities while allowing additional customization. Usually developed by developer or even project managers but there is little code writing capability involved. The review can go deeper into both the platform configuration and the agent implementation, depending on the level of source code and configuration visibility available.

Third-Party Marketplace Agents

Organizations consume pre-built agents or integrations developed outside the organization. In this case, there is limited visibility into the underlying implementation which makes it very important to review. The review focuses more heavily on the agent's exposed behaviour, permissions, integrations and trust boundaries, along with any artifacts that are available for analysis.


The way an agent is built therefore determines how much visibility is available and consequently how it should be reviewed.

From Agent Type to Security Review

A practical Agent Security Review approach should not apply the same assessment to every agent. Instead, the review should consider:

This leads to three complementary review approaches:

  • Platform Review — for the environment in which agents are being created
  • Continuous Agent Scanning — for large-scale agent creation and frequent changes
  • Individual Agent Security Testing — for ad-hoc, business-specific and third-party agents requiring deeper validation

1. Before Platform Rollout: Review the Agent-Building Platform

When an agent-building platform is being introduced to business users, the first security consideration should be the platform itself. The platform effectively becomes the foundation on which potentially hundreds or thousands of agents will be created. A security review at this stage should therefore combine - Configuration Review + AI-Focused Threat Simulation. The configuration review validates whether the platform's security controls, permissions, integrations, data access and governance mechanisms are appropriately configured. Threat simulation validates controls from an attack perspective - assessing whether the platform can be manipulated to cross intended security boundaries or cause unintended behavior.  The objective is to establish a secure baseline before the platform is made widely available to users.

2. After Rollout: Continuous Scanning at Scale

Once the platform is rolled out, the security challenge changes. Business users may continuously create new agents, modify existing agents, and introduce new tools or integrations. At this scale, manually reviewing every agent is not practical. This is where continuous agent scanning becomes relevant.

 


3. Ad-Hoc and Third-Party Agents: Deeper Individual Review

Not all agents will necessarily be created through the organization's centrally managed platform. Business teams may develop agents independently for specific use cases, while other agents may be sourced from third-party marketplaces. For these agents, a deeper individual security review may be appropriate.


As organizations move toward widespread business-user adoption of AI agents, security needs to move with that lifecycle - secure the platform before rollout, continuously scan agents at scale, and perform deeper testing where individual agents warrant it. That provides a practical path from platform security to agent-level security without creating a manual security bottleneck for every agent.

Article by Hemil Shah and Rishita Anubhai