NEW

Start with the pressure: sales, launch, abuse, agents, data, or guardrails

SECENG WORKBENCH

Authority, Paths & Defense Breakpoints

Map what agents can do before they do it.

SecEng Authority Graph maps agent authority first, then enables abuse testing and hardening. Import workflows, MCP servers, and tool schemas to see what agents can read, write, send, execute, and administer — then turn that authority map into least-privilege controls, approval gates, hardening tasks, and APC evidence for larger chains. MADE stage: Map + Defend, with Attack validation.

WHAT CAN AGENTS ACTUALLY DO?

Authority Mapping

Classify every tool: read, write, send, execute, admin — with scopes.

Workflow Graphs

Visual authority graph from user input through agents to external effects.

Risk Detection

Detect dangerous compositions: read sensitive data + send externally.

Approval Control

Verify approval gates and flag missing, bypassed, or optional controls.

Agent Workflow & Authority Analyzer

ACME Corp fixture · graph preview driven by the real analysis bundle

Fixture

High-risk workflows

7

Composition report scorecard

Tools across demo dataset

38

Authority-register tools across the demo dataset

Approval coverage

68%

Approval boundary coverage

Approval bypassed

3

Bypass boundaries

Webhook

User Request

Agent

Assistant Agent

Retriever

Retrieve Documents

Crm

Read CRM

Llm

Draft Email with LLM

Core capabilities

What SecEng Authority Graph does.

Tool & MCP Server Inventory

Inventory every agent tool, MCP server, plugin, workflow node, browser action, and API capability. Build a complete authority register before the first abuse case reaches production.

Authority Classification

Classify each tool by capability: Read, Write, Send, Execute, Admin, External, Irreversible. Analyze what the integration actually enables — not just what the label claims.

Dangerous Composition Detection

Detect combinations that create real risk: Read CRM Data + Send Email Externally, Retrieve Documents + Update Records, Filesystem Access + External API Call, Code Execution + Network Access, Admin API + LLM-controlled Arguments.

Workflow Authority Graph

Build a visual authority graph showing how user input flows through agents, prompts, tools, retrievers, APIs, approval gates, and external effects.

Blast Radius Scoring

Score blast radius per workflow: Low, Medium, High, Critical. Highlight irreversible actions, external sends, admin scope, and cross-system reach.

Approval Gate Verification

Verify approval boundaries: Enforced, Missing, Bypassed, Optional. Identify where human approval can be skipped through instruction injection or workflow manipulation.

Evidence & signals

What you get out of the box.

Tool Authority Breakdown

  • Read: 18
  • Write: 12
  • Send: 7
  • Execute: 4
  • Admin: 2

Approval Boundaries

  • Enforced: 14
  • Missing: 5
  • Bypassed: 3
  • Optional: 4

Dangerous Compositions

  • Read CRM Data + Send Email Externally — High
  • Retrieve Documents + Update Records — High
  • Access Files + External API Call — Medium

Red team + Blue team

Built for both sides of the security equation.

Red Team Use

  • Discover abuse chains created by individually reasonable tools composed dangerously
  • Simulate misuse paths: user prompt → retrieve CRM → draft email → send externally
  • Find approval gates that can be bypassed through alternate workflow branches or prompt injection
  • Identify high-blast-radius tools exposed to LLM-controlled arguments

Blue Team Use

  • Export workflow reports, authority maps, risk registers, and evidence packs
  • Generate least-privilege recommendations and approval-gate requirements per workflow
  • Map agent authority findings to ISO 42001, NIST AI RMF, OWASP LLM, and internal governance controls
  • Build regression checks for workflow changes and newly added tools

SECENG WORKBENCH

Ready to put SecEng Authority Graph to work?

Scope a Workbench-backed review — we’ll import a workflow, map agent authority, identify dangerous compositions, and give you a concrete approval-boundary plan.

Also in the Workbench

WHAT AI DO WE HAVE?

SecEng Surface Scanner

Browser, repo & IDE discovery for AI assets, vendors, and risky patterns.

Explore

WHERE CAN AI CODE BECOME AN ATTACK PATH?

SecEng Code Scanner

AI-native SAST and marketplace readiness for AI-enabled apps, agents, integrations, and managed packages.

Explore

WHAT DID IT ACTUALLY DO?

SecEng Runtime Proxy

MITM capture, replay & runtime evidence reconstruction.

Explore

HOW CAN IT FAIL UNDER ATTACK?

SecEng Adversarial Range

Scenario-driven AI red-team testing for prompts, agents, tools, RAG, and multimodal systems.

Explore

WAS RETRIEVAL AUTHORIZED?

SecEng RAG Test Harness

Test retrieval security & context authorization.

Explore

WHERE ARE THE TRUST BOUNDARIES?

SecEng Threat Canvas

Structured AI threat modeling, trust-boundary mapping, and abuse-path planning.

Explore

WHAT DO OUR PUBLIC AI CLAIMS REVEAL?

SecEng Trust Scanner

Public trust surface scoring across six AI governance dimensions.

Explore

WHERE DO TRUST BOUNDARIES LIVE IN JIRA?

Atlassian Threat Canvas

AI threat models that ship to Jira and Confluence.

Explore

DO YOUR AGENTS HAVE TOO MUCH PERMISSION?

SecEng Agent Permission Analyzer

Deterministic permission security analysis for AI agent tool configs.

Explore

WHAT'S INSIDE YOUR AI ARTIFACTS?

SecEng Artifact Analyzer

Static artifact intelligence for AI security and evidence packaging.

Explore

HOW RESILIENT IS YOUR SYSTEM TO INJECTION?

SecEng Injection Harness

Structured prompt injection probes with evidence session export.

Explore

ARE YOUR PROMPTS SECURE?

SecEng Prompt Reviewer

Deterministic rule-based scanner for system prompts and RAG corpus documents.

Explore

WHO CONTROLS WHAT MODELS CAN DO?

SecEng Model Gateway

Governed AI routing, policy enforcement, and spend control.

Explore

WHAT DOES YOUR AI SECURITY PROGRAM LOOK LIKE?

SecEng Program Blueprint Kit

Complete AI security program structure for Jira, Confluence, and Linear.

Explore

IS YOUR MODEL OUTPUT SAFE TO RENDER?

SecEng Output Safety Tester

Deterministic AI output safety analysis across 8 sink types.

Explore

WHERE DOES YOUR PROGRAM STAND?

AI Security Program Scorecard

14-domain AI product security baseline with evidence pack generation.

Explore

WHAT CAN YOUR AI TOOLS REALLY DO?

SecEng Tool Capsule Analyzer

Analyze MCP servers, OpenAPI specifications, and AI tool definitions to understand capabilities, permissions, and attack surface.

Explore

WHERE ARE YOUR PRODUCTION PROMPTS?

SecEng Prompt Asset Scanner

Inventory and review system prompts, developer prompts, agent instructions, and prompt templates for security risks.

Explore

WHAT CAN YOUR AGENTS ACTUALLY DO?

SecEng Agent Authority Diff

Compare declared permissions with observed capabilities to identify excessive agent privileges and unsafe tool access.

Explore

WHICH AI DEPENDENCIES CHANGE RELEASE RISK?

SecEng Supply Chain Scanner

Identify AI-specific dependency, model loader, framework, and supply-chain security risks.

Explore

CAN YOU PROVE WHAT YOUR EVALS COVER?

SecEng Eval Coverage Auditor

Measure whether AI security evaluations adequately cover prompt injection, tool abuse, RAG, memory, and other critical attack classes.

Explore

ARE YOUR AI CONFIGS SAFE TO DEPLOY?

SecEng AI Config Linter

Identify AI-specific dependency, model loader, framework, and supply-chain security risks.

Explore

CAN YOU PROVE WHAT YOU'VE DONE?

SecEng Evidence Packs

Buyer-ready evidence artifacts from AI security assessment and testing.

Explore

Progressive proof

Product story first. Fixture detail second.

The workbench below is a deterministic ACME workflow fixture. Metrics are labeled by scope: tools across the demo dataset, graph nodes and edges in this fixture, and attack paths derived from the normalized evidence graph. The fixture remains visible for proof, but it is not the primary product claim.

Model effective authority, not just assigned permissions.

The graph connects identities, agents, tools, data, credentials, policies, approval gates, and consequential actions so reviewers can see who or what can reach each sensitive outcome.

AUTH-01

Authority Graph Overview

The authority graph models which identities and agents can invoke which tools, data, approvals, and consequential actions.

Graph showing users, agents, service identities, permissions, tools, approval gates, data, and external effects.

Actors and identitiesPermissions and approvalsData and consequential effectsUserAgentService identityDelegated permissionApproval gateConsequence-bearingtoolSensitive dataExternal action

This turns fragmented IAM, application, agent, and workflow configuration into a reviewable topology of read, write, send, execute, approve, administer, and delegate authority.

SecEng Map + Defend · instrument

Workflow authority result — ACME Corp fixture.

The fixture below stands in for an ACME Corp workflow import and shows how the Tauri sidecar surface operates with shared components, consistent theming, and release-ready evidence language.

ACME fixture

SecEng Authority Graph / Dashboard

Agent Workflow & Authority Analyzer

Analysis bundle

Map what your agents can actually do. Find dangerous compositions. Enforce approval boundaries.

High-risk workflows

7

Derived from composition risks

Tools across demo dataset

38

Authority-register tools across the demo dataset

Approval coverage

68%

Approval boundary coverage

Approval bypassed

3

Blocked or bypassed steps

Dangerous compositions

4

Risk-report compositions

External effects

5

Send / write / external sinks

Workflow Authority Graph

The graph is organized around approval control, bypass detection, and the points where safe components become dangerous together.

Focus path: Reviewed outbound path

InputReasoningData AccessGovernanceExternal ActionBypass / High Risk
Intake
Governance
Retrieval
Reasoning
Action
Bypass

User Request

Webhook

not_requirednetwork
request_payload

apps/web/app/api/assistant/outbound/route.ts

Assistant Agent

Agent

optionalreadexecute
customer_profileconversation_state

packages/ai/agents/outbound-assistant.ts

Retrieve Documents

Retriever

not_requiredreadsensitive
knowledge_basecustomer_context

packages/rag/retrieve-context.ts

Read CRM

Crm

optionalreadexternal
accountopportunity

packages/ai/tools/read-crm.ts

Draft Email with LLM

Llm

not_requiredreadsensitive
draft_textcustomer_context

packages/ai/prompts/outbound-email.md

Policy Check

Policy Check

enforcedread
policy_decision

packages/governance/policies/workflow-policy.ts

Human Approval Gate

Approval Gate

enforcedread
approval_record

packages/governance/approvals/review.ts

Send Email via Outlook

Email

enforcedsendexternal
message_bodyrecipient

packages/ai/tools/send-outlook.ts

Update CRM Record

Api

enforcedwriteexternal
crm_recordstatus_update

packages/ai/tools/update-crm.ts

Bypass Send Branch

External Sink

bypassedsendexternal
external_actionbypass_path

packages/ai/flows/bypass-send.ts

Policy Check
Policy Check
Human Approval Gate
Human Approval Gate

Nodes

10

Edges

12

Platform

n8n

Importer

explicit_graph

Focus path

Reviewed outbound path

high

The branch from the draft step reaches the CRM update without passing through the human approval gate.

enforcedhigh blast radius
User RequestAssistant AgentRetrieve DocumentsDraft Email with LLMHuman Approval GateSend Email via Outlook

Connected control map

RAG Boundary Lens for workflow authority

The same lens now shows how approval coverage, bypass paths, and external effects line up inside the workflow graph.

Workflow control map

SecEng Authority Graph

RAG Boundary Lens

Approval boundaries, bypass paths, and external effects rendered against the agent workflow graph.

RAG detectedClaim-ready preview
45boundary
Boundary score
45/100
RAG detected
Yes
Affected paths
5
Top tests
3

AuthZ pass

Watch
amber

Approval coverage still needs hardening.

Context leaks

5
amber

External effect nodes stand in for potential leakage surfaces.

Policy violations

3
red

Bypassed approvals need follow-up.

Pipeline snapshot

5
Import graphMap authorityCheck approvalsScore blast radiusExport control map

Suggested tests

3
Bypass branch blocked before CRM updateApproval gate required before external sendAuthority chain fails closed on missing policy check

Controls found

3
Outbound send requires human reviewBypass branch skips human approvalPolicy check is enforced before the review gate

Affected paths

2
packages/rag/retrieve-context.tspackages/ai/tools/read-crm.ts

Missing boundaries

Priority gaps

Approval gate coverageBypass path quarantineExternal effect boundary

Top tests

Harness checks

1Approval gate can be bypassed before the CRM update
2Outbound send requires human review
seceng-rag/seceng-rag.config.json
seceng-rag/identities.json
seceng-rag/documents.json
seceng-rag/tests.json

The lens is public-safe and directional. It uses job-description intelligence and trace fixture signals to show where RAG boundaries need reinforcement, without exposing raw documents or private payloads.

Workflow Authority Register

Capabilities are derived from the actual authority booleans on each node.

38 tools across demo dataset
read · 14write · 8send · 6execute · 4admin · 2external · 4

Update CRM Record

Api · enforced

criticalenforced
writeexternalirreversiblesensitivenetwork
crm_recordstatus_updatecrm.write
Evidence: crm write scope · irreversible external update

Bypass Send Branch

External Sink · bypassed

criticalbypassed
sendexternalirreversiblenetwork
external_actionbypass_pathworkflow.bypass
Evidence: approval bypass · external sink path

Read CRM

Crm · optional

highoptional
readexternalsensitivenetwork
accountopportunitycontactcrm.read
Evidence: salesforce read scope · external sensitive lookup

Send Email via Outlook

Email · enforced

highenforced
sendexternalirreversiblenetwork
message_bodyrecipientmail.send
Evidence: mail send scope · external delivery

Assistant Agent

Agent · optional

mediumoptional
readexecutesensitivenetwork
customer_profileconversation_stateassistant.orchestrate
Evidence: orchestration code · decision boundary

Retrieve Documents

Retriever · not_required

mediumnot_required
readsensitivenetwork
knowledge_basecustomer_contextrag.read
Evidence: vector-store fetch · sensitive context

Draft Email with LLM

Llm · not_required

mediumnot_required
readsensitivenetwork
draft_textcustomer_contextllm.generate
Evidence: prompt assembly · customer context used

User Request

Webhook · not_required

lownot_required
network
request_payloadpublic_ingress
Evidence: POST ingress · request payload observed

Policy Check

Policy Check · enforced

lowenforced
read
policy_decisionpolicy.evaluate
Evidence: policy predicate · guarded branch

Human Approval Gate

Approval Gate · enforced

lowenforced
read
approval_recordapproval.review
Evidence: review gate · approval record

Composition Risk Stack

Abuse paths

Scorecard

High risk workflows

7

Dangerous compositions

4

External effects

5

Approval bypasses

3

Approval Coverage

Coverage

68%

17 enforced · 5 missing · 3 bypassed · 0 optional

Outbound send requires human review

The primary send path is gated by a human approval step.

enforced
Severity: low
Remediation: Keep the approval record attached to the outbound message before delivery.
node_approvalnode_email

Bypass branch skips human approval

A secondary branch can route from the draft directly to the CRM update.

bypassed
Severity: critical
Remediation: Block the bypass sink until it passes through the same approval gate.
node_llmnode_bypassnode_api

Policy check is enforced before the review gate

Policy evaluation exists and is wired into the reviewed path.

enforced
Severity: low
Remediation: Keep the policy decision attached to the approval record for audit.
node_policynode_approval

CRM lookup remains unaudited in the draft path

The lookup step contributes context but does not have its own approval event.

missing
Severity: high
Remediation: Log the lookup scope and require explicit approval when sensitive account data is accessed.
node_crmnode_llm

Blast Radius

Overall: high · Score 84

high

Bypass Send Branch

node_bypass

96
approval_bypassedexternal_sinkirreversibleno_guardrail

Update CRM Record

node_api

94
writeexternalirreversiblecustomer_state

Send Email via Outlook

node_email

91
sendexternalcustomer_contactdelivery

Draft Email with LLM

node_llm

78
prompt_contextsensitive_inputsgeneration

Read CRM

node_crm

72
sensitiveexternalreadcustomer_profile

Retrieve Documents

node_retriever

61
sensitiveretrievalcontext_spill

Assistant Agent

node_agent

56
decisioningtool_orchestrationmulti_step_path

Policy Check

node_policy

24
read_onlyguardraildecision_filter

Human Approval Gate

node_approval

18
enforcedreview_recordhuman_in_loop

User Request

node_webhook

12
ingressno_actionentry_point

Grounded Attack Paths (APC) — from this authority graph

16 attack paths1 tools in this fixture16 evidence-graph nodes18 evidence-graph edges

Evidence from this surface, normalized and joined into the shared SecEng evidence graph. Every step traces to a specific tool’s output; grounded steps were observed or deterministically derived.

Adding a mandatory approval/control at wf:acme-outbound-assistant-graph-v1:node_agent blocks 16 of 16 analyzed paths.

  • Groundedattack· conf 93%11authority-graph
    User RequestAssistant AgentPolicy CheckHuman Approval GateSend Email via OutlookUpdate CRM Record
  • Groundedattack· conf 89%11authority-graph
    User RequestAssistant AgentRetrieve DocumentsDraft Email with LLMHuman Approval GateSend Email via Outlook
  • Groundedattack· conf 88%22authority-graph
    User RequestAssistant AgentRetrieve DocumentsDraft Email with LLMHuman Approval GateSend Email via OutlookUpdate CRM Record
  • Groundedattack· conf 84%12authority-graph
    User RequestAssistant AgentRead CRMDraft Email with LLMHuman Approval GateSend Email via OutlookUpdate CRM Record
LegendGroundedInferredSpeculative+12 moreOpen full Evidence Graph

Threat Model

ACME outbound assistant workflow

Assets

  • Customer Data · sensitive_data
  • Prompt Context · context
  • Approval Record · control_evidence
  • Outbound Actions · external_effect

Actors

  • End User · human
  • Assistant Agent · workflow_agent
  • Human Reviewer · human

Trust Boundaries

  • Public Ingress · external_to_internal
  • Sensitive Context Boundary · internal_sensitive
  • Outbound Effect Boundary · external_effect

Mitigations

  • Split outbound send and CRM update into separate approvals · recommended
  • Guard the bypass sink with explicit policy enforcement · in_progress
  • Tag source context before draft generation · recommended
  • Persist the approval record alongside external effects · planned

Prompt injection steers outbound draft

Retrieved content or CRM text can alter the draft email instructions.

high
policy_checkapproval_gatecontent_normalization

Approval bypass reaches CRM update

The bypass sink reaches the CRM write path without human review.

critical
approval_gatepolicy_checkaudit_log

Outbound send exceeds intended scope

The same workflow can compose email send and CRM update, widening the blast radius.

high
least_privilegescoped_approvalboundary_split

Policy check does not cover the bypass branch

The policy gate protects the reviewed path but does not currently stop the bypass sink.

medium
policy_enforcementbranch_blockingpath_diffing

Evidence

graph_snapshot

Normalized graph snapshot for ACME outbound assistant workflow.

sha256:cc9a6b6e0a9f3c8f4baf1a2b90c1b1c7d8f3f0f8c83c8f70b06d8fef2c28a1f4

approval_record

Human review attached to the primary send path.

sha256:5f7b4f3f0a7dbeed5d68e0d3f8b9d6b4de2ccaf6f6c0c1f3f5a7c5b6d8e2c1a9

abuse_path

Bypass branch observed from draft step to CRM update.

sha256:9b1e0d4cf8d2cde2c1d0f3f0a7b1e5d7c2f8c0e1d6b5a8c9f4e3d2c1b0a9f8e7

Export Artifacts

Copy or download the bundle outputs without leaving the page.

graph_json

acme-outbound-assistant-graph.json

application/json

{
  "graph": {
    "graph_id": "acme-outbound-assistant-graph-v1",
    "name": "ACME outbound assistant workflow",
    "source": {
      "platform": "n8n",
      "source_uri": "https://n8n.acme.local/workflows/outbound-assistant",
      "importer": "workflow-import-normalizer"
    }
  },
  "scorecard": {
    "high_risk_workflows": 7,
    "dangerous_compositions": 4,
    "external_effects": 5,
    "irreversible_actions": 3,
    "approval_bypasses": 3
  }
}

authority_register_json

acme-workflow-authority-register.json

application/json

{
  "graph_id": "acme-outbound-assistant-graph-v1",
  "tools_discovered": 38
}

threat_model_json

acme-workflow-threat-model.json

application/json

{
  "graph_id": "acme-outbound-assistant-graph-v1",
  "title": "ACME outbound assistant workflow"
}

export_manifest_md

acme-workflow-analysis.md

text/markdown

# ACME outbound assistant workflow

- High-risk workflows: 7
- Tools discovered: 38
- Approval coverage: 68%
- Approval bypasses: 3

Individually reasonable permissions can compose into unsafe authority.

A system may appear constrained when each permission is reviewed separately. Risk emerges when an agent can combine retrieval, credentials, tools, delegated identity, and downstream actions into an end-to-end path.

AUTH-02

Unsafe Authority Composition

Individually reasonable permissions can combine into a dangerous end-to-end authority path.

Graph showing separate read, plan, tool, and approval permissions combining into one consequential authority path.

Read sensitive contextPlan an actionInvoke a toolReuse or bypassapprovalTRANSFORMATIONComposedauthorityEnd-to-end consequential authorityExternal action

The graph exposes these composed paths before they become an incident, allowing reviewers to distinguish ordinary access from authority that can cross trust boundaries or create irreversible effects.

Recommendations preserve evidence and ownership.

Least-privilege, approval, credential-scope, and separation-of-duties recommendations record their configuration basis, confidence, inferred reachability, and responsible remediation owner before they become control decisions.

Break several authority paths with one well-placed control.

The highest-value remediation is often not another detector. It is the approval gate, permission boundary, credential scope, action limit, or separation-of-duties control shared by several dangerous paths.

AUTH-03

Authority to Control Chokepoint

A small change to permission, approval, or action scope can break several unsafe authority paths.

Several authority paths converging on overbroad permission, followed by a constrained policy and approval gate that blocks or reduces the paths.

User to agent toactionAgent to tool toexternal effectService identity totoolSHARED WEAKNESSSharedauthorityweaknessCONTROLSelectedcontrolUser path blockedAgent pathblockedService pathconstrained withresidual reviewAuthority pathretest
Path blockedReduced, not eliminatedPending retest

Chokepoint analysis helps product, platform, identity, and security teams prioritize controls that materially reduce reachable impact rather than merely shrinking isolated permission lists.