SECENG WORKBENCH
Authority, Paths & Defense Breakpoints
Map what agents can do before they do it.
SecEng Authority Graph maps agent authority first, then enables abuse testing and hardening. Import workflows, MCP servers, and tool schemas to see what agents can read, write, send, execute, and administer — then turn that authority map into least-privilege controls, approval gates, hardening tasks, and APC evidence for larger chains. MADE stage: Map + Defend, with Attack validation.
Authority Mapping
Classify every tool: read, write, send, execute, admin — with scopes.
Workflow Graphs
Visual authority graph from user input through agents to external effects.
Risk Detection
Detect dangerous compositions: read sensitive data + send externally.
Approval Control
Verify approval gates and flag missing, bypassed, or optional controls.
Agent Workflow & Authority Analyzer
ACME Corp fixture · graph preview driven by the real analysis bundle
High-risk workflows
7
Composition report scorecard
Tools across demo dataset
38
Authority-register tools across the demo dataset
Approval coverage
68%
Approval boundary coverage
Approval bypassed
3
Bypass boundaries
Webhook
User Request
Agent
Assistant Agent
Retriever
Retrieve Documents
Crm
Read CRM
Llm
Draft Email with LLM
Core capabilities
What SecEng Authority Graph does.
Tool & MCP Server Inventory
Inventory every agent tool, MCP server, plugin, workflow node, browser action, and API capability. Build a complete authority register before the first abuse case reaches production.
Authority Classification
Classify each tool by capability: Read, Write, Send, Execute, Admin, External, Irreversible. Analyze what the integration actually enables — not just what the label claims.
Dangerous Composition Detection
Detect combinations that create real risk: Read CRM Data + Send Email Externally, Retrieve Documents + Update Records, Filesystem Access + External API Call, Code Execution + Network Access, Admin API + LLM-controlled Arguments.
Workflow Authority Graph
Build a visual authority graph showing how user input flows through agents, prompts, tools, retrievers, APIs, approval gates, and external effects.
Blast Radius Scoring
Score blast radius per workflow: Low, Medium, High, Critical. Highlight irreversible actions, external sends, admin scope, and cross-system reach.
Approval Gate Verification
Verify approval boundaries: Enforced, Missing, Bypassed, Optional. Identify where human approval can be skipped through instruction injection or workflow manipulation.
Evidence & signals
What you get out of the box.
Tool Authority Breakdown
- Read: 18
- Write: 12
- Send: 7
- Execute: 4
- Admin: 2
Approval Boundaries
- Enforced: 14
- Missing: 5
- Bypassed: 3
- Optional: 4
Dangerous Compositions
- Read CRM Data + Send Email Externally — High
- Retrieve Documents + Update Records — High
- Access Files + External API Call — Medium
Red team + Blue team
Built for both sides of the security equation.
Red Team Use
- Discover abuse chains created by individually reasonable tools composed dangerously
- Simulate misuse paths: user prompt → retrieve CRM → draft email → send externally
- Find approval gates that can be bypassed through alternate workflow branches or prompt injection
- Identify high-blast-radius tools exposed to LLM-controlled arguments
Blue Team Use
- Export workflow reports, authority maps, risk registers, and evidence packs
- Generate least-privilege recommendations and approval-gate requirements per workflow
- Map agent authority findings to ISO 42001, NIST AI RMF, OWASP LLM, and internal governance controls
- Build regression checks for workflow changes and newly added tools
SECENG WORKBENCH
Ready to put SecEng Authority Graph to work?
Scope a Workbench-backed review — we’ll import a workflow, map agent authority, identify dangerous compositions, and give you a concrete approval-boundary plan.
Also in the Workbench
WHAT AI DO WE HAVE?
SecEng Surface Scanner
Browser, repo & IDE discovery for AI assets, vendors, and risky patterns.
WHERE CAN AI CODE BECOME AN ATTACK PATH?
SecEng Code Scanner
AI-native SAST and marketplace readiness for AI-enabled apps, agents, integrations, and managed packages.
WHAT DID IT ACTUALLY DO?
SecEng Runtime Proxy
MITM capture, replay & runtime evidence reconstruction.
HOW CAN IT FAIL UNDER ATTACK?
SecEng Adversarial Range
Scenario-driven AI red-team testing for prompts, agents, tools, RAG, and multimodal systems.
WAS RETRIEVAL AUTHORIZED?
SecEng RAG Test Harness
Test retrieval security & context authorization.
WHERE ARE THE TRUST BOUNDARIES?
SecEng Threat Canvas
Structured AI threat modeling, trust-boundary mapping, and abuse-path planning.
WHAT DO OUR PUBLIC AI CLAIMS REVEAL?
SecEng Trust Scanner
Public trust surface scoring across six AI governance dimensions.
WHERE DO TRUST BOUNDARIES LIVE IN JIRA?
Atlassian Threat Canvas
AI threat models that ship to Jira and Confluence.
DO YOUR AGENTS HAVE TOO MUCH PERMISSION?
SecEng Agent Permission Analyzer
Deterministic permission security analysis for AI agent tool configs.
WHAT'S INSIDE YOUR AI ARTIFACTS?
SecEng Artifact Analyzer
Static artifact intelligence for AI security and evidence packaging.
HOW RESILIENT IS YOUR SYSTEM TO INJECTION?
SecEng Injection Harness
Structured prompt injection probes with evidence session export.
ARE YOUR PROMPTS SECURE?
SecEng Prompt Reviewer
Deterministic rule-based scanner for system prompts and RAG corpus documents.
WHO CONTROLS WHAT MODELS CAN DO?
SecEng Model Gateway
Governed AI routing, policy enforcement, and spend control.
WHAT DOES YOUR AI SECURITY PROGRAM LOOK LIKE?
SecEng Program Blueprint Kit
Complete AI security program structure for Jira, Confluence, and Linear.
IS YOUR MODEL OUTPUT SAFE TO RENDER?
SecEng Output Safety Tester
Deterministic AI output safety analysis across 8 sink types.
WHERE DOES YOUR PROGRAM STAND?
AI Security Program Scorecard
14-domain AI product security baseline with evidence pack generation.
WHAT CAN YOUR AI TOOLS REALLY DO?
SecEng Tool Capsule Analyzer
Analyze MCP servers, OpenAPI specifications, and AI tool definitions to understand capabilities, permissions, and attack surface.
WHERE ARE YOUR PRODUCTION PROMPTS?
SecEng Prompt Asset Scanner
Inventory and review system prompts, developer prompts, agent instructions, and prompt templates for security risks.
WHAT CAN YOUR AGENTS ACTUALLY DO?
SecEng Agent Authority Diff
Compare declared permissions with observed capabilities to identify excessive agent privileges and unsafe tool access.
WHICH AI DEPENDENCIES CHANGE RELEASE RISK?
SecEng Supply Chain Scanner
Identify AI-specific dependency, model loader, framework, and supply-chain security risks.
CAN YOU PROVE WHAT YOUR EVALS COVER?
SecEng Eval Coverage Auditor
Measure whether AI security evaluations adequately cover prompt injection, tool abuse, RAG, memory, and other critical attack classes.
ARE YOUR AI CONFIGS SAFE TO DEPLOY?
SecEng AI Config Linter
Identify AI-specific dependency, model loader, framework, and supply-chain security risks.
CAN YOU PROVE WHAT YOU'VE DONE?
SecEng Evidence Packs
Buyer-ready evidence artifacts from AI security assessment and testing.
Progressive proof
Product story first. Fixture detail second.
The workbench below is a deterministic ACME workflow fixture. Metrics are labeled by scope: tools across the demo dataset, graph nodes and edges in this fixture, and attack paths derived from the normalized evidence graph. The fixture remains visible for proof, but it is not the primary product claim.
Model effective authority, not just assigned permissions.
The graph connects identities, agents, tools, data, credentials, policies, approval gates, and consequential actions so reviewers can see who or what can reach each sensitive outcome.
Authority Graph Overview
The authority graph models which identities and agents can invoke which tools, data, approvals, and consequential actions.
Graph showing users, agents, service identities, permissions, tools, approval gates, data, and external effects.
This turns fragmented IAM, application, agent, and workflow configuration into a reviewable topology of read, write, send, execute, approve, administer, and delegate authority.
SecEng Map + Defend · instrument
Workflow authority result — ACME Corp fixture.
The fixture below stands in for an ACME Corp workflow import and shows how the Tauri sidecar surface operates with shared components, consistent theming, and release-ready evidence language.
SecEng Authority Graph / Dashboard
Agent Workflow & Authority Analyzer
Analysis bundleMap what your agents can actually do. Find dangerous compositions. Enforce approval boundaries.
High-risk workflows
7
Derived from composition risks
Tools across demo dataset
38
Authority-register tools across the demo dataset
Approval coverage
68%
Approval boundary coverage
Approval bypassed
3
Blocked or bypassed steps
Dangerous compositions
4
Risk-report compositions
External effects
5
Send / write / external sinks
Workflow Authority Graph
The graph is organized around approval control, bypass detection, and the points where safe components become dangerous together.
Focus path: Reviewed outbound path
User Request
Webhook
apps/web/app/api/assistant/outbound/route.ts
Assistant Agent
Agent
packages/ai/agents/outbound-assistant.ts
Retrieve Documents
Retriever
packages/rag/retrieve-context.ts
Read CRM
Crm
packages/ai/tools/read-crm.ts
Draft Email with LLM
Llm
packages/ai/prompts/outbound-email.md
Policy Check
Policy Check
packages/governance/policies/workflow-policy.ts
Human Approval Gate
Approval Gate
packages/governance/approvals/review.ts
Send Email via Outlook
packages/ai/tools/send-outlook.ts
Update CRM Record
Api
packages/ai/tools/update-crm.ts
Bypass Send Branch
External Sink
packages/ai/flows/bypass-send.ts
Nodes
10
Edges
12
Platform
n8n
Importer
explicit_graph
Focus path
Reviewed outbound path
The branch from the draft step reaches the CRM update without passing through the human approval gate.
Connected control map
RAG Boundary Lens for workflow authority
The same lens now shows how approval coverage, bypass paths, and external effects line up inside the workflow graph.
SecEng Authority Graph
RAG Boundary Lens
Approval boundaries, bypass paths, and external effects rendered against the agent workflow graph.
AuthZ pass
Approval coverage still needs hardening.
Context leaks
External effect nodes stand in for potential leakage surfaces.
Policy violations
Bypassed approvals need follow-up.
Pipeline snapshot
5Suggested tests
3Controls found
3Affected paths
2Missing boundaries
Priority gaps
Top tests
Harness checks
The lens is public-safe and directional. It uses job-description intelligence and trace fixture signals to show where RAG boundaries need reinforcement, without exposing raw documents or private payloads.
Workflow Authority Register
Capabilities are derived from the actual authority booleans on each node.
Update CRM Record
Api · enforced
Bypass Send Branch
External Sink · bypassed
Read CRM
Crm · optional
Send Email via Outlook
Email · enforced
Assistant Agent
Agent · optional
Retrieve Documents
Retriever · not_required
Draft Email with LLM
Llm · not_required
User Request
Webhook · not_required
Policy Check
Policy Check · enforced
Human Approval Gate
Approval Gate · enforced
Composition Risk Stack
Abuse paths
Scorecard
High risk workflows
7
Dangerous compositions
4
External effects
5
Approval bypasses
3
Approval Coverage
Coverage
68%
17 enforced · 5 missing · 3 bypassed · 0 optional
Outbound send requires human review
The primary send path is gated by a human approval step.
Bypass branch skips human approval
A secondary branch can route from the draft directly to the CRM update.
Policy check is enforced before the review gate
Policy evaluation exists and is wired into the reviewed path.
CRM lookup remains unaudited in the draft path
The lookup step contributes context but does not have its own approval event.
Blast Radius
Overall: high · Score 84
Bypass Send Branch
node_bypass
Update CRM Record
node_api
Send Email via Outlook
node_email
Draft Email with LLM
node_llm
Read CRM
node_crm
Retrieve Documents
node_retriever
Assistant Agent
node_agent
Policy Check
node_policy
Human Approval Gate
node_approval
User Request
node_webhook
Grounded Attack Paths (APC) — from this authority graph
Evidence from this surface, normalized and joined into the shared SecEng evidence graph. Every step traces to a specific tool’s output; grounded steps were observed or deterministically derived.
Adding a mandatory approval/control at wf:acme-outbound-assistant-graph-v1:node_agent blocks 16 of 16 analyzed paths.
- Groundedattack· conf 93%11authority-graphUser RequestAssistant AgentPolicy CheckHuman Approval GateSend Email via OutlookUpdate CRM Record
- Groundedattack· conf 89%11authority-graphUser RequestAssistant AgentRetrieve DocumentsDraft Email with LLMHuman Approval GateSend Email via Outlook
- Groundedattack· conf 88%22authority-graphUser RequestAssistant AgentRetrieve DocumentsDraft Email with LLMHuman Approval GateSend Email via OutlookUpdate CRM Record
- Groundedattack· conf 84%12authority-graphUser RequestAssistant AgentRead CRMDraft Email with LLMHuman Approval GateSend Email via OutlookUpdate CRM Record
Threat Model
ACME outbound assistant workflow
Assets
- • Customer Data · sensitive_data
- • Prompt Context · context
- • Approval Record · control_evidence
- • Outbound Actions · external_effect
Actors
- • End User · human
- • Assistant Agent · workflow_agent
- • Human Reviewer · human
Trust Boundaries
- • Public Ingress · external_to_internal
- • Sensitive Context Boundary · internal_sensitive
- • Outbound Effect Boundary · external_effect
Mitigations
- • Split outbound send and CRM update into separate approvals · recommended
- • Guard the bypass sink with explicit policy enforcement · in_progress
- • Tag source context before draft generation · recommended
- • Persist the approval record alongside external effects · planned
Prompt injection steers outbound draft
Retrieved content or CRM text can alter the draft email instructions.
Approval bypass reaches CRM update
The bypass sink reaches the CRM write path without human review.
Outbound send exceeds intended scope
The same workflow can compose email send and CRM update, widening the blast radius.
Policy check does not cover the bypass branch
The policy gate protects the reviewed path but does not currently stop the bypass sink.
Evidence
graph_snapshot
Normalized graph snapshot for ACME outbound assistant workflow.
sha256:cc9a6b6e0a9f3c8f4baf1a2b90c1b1c7d8f3f0f8c83c8f70b06d8fef2c28a1f4
approval_record
Human review attached to the primary send path.
sha256:5f7b4f3f0a7dbeed5d68e0d3f8b9d6b4de2ccaf6f6c0c1f3f5a7c5b6d8e2c1a9
abuse_path
Bypass branch observed from draft step to CRM update.
sha256:9b1e0d4cf8d2cde2c1d0f3f0a7b1e5d7c2f8c0e1d6b5a8c9f4e3d2c1b0a9f8e7
Export Artifacts
Copy or download the bundle outputs without leaving the page.
graph_json
acme-outbound-assistant-graph.json
application/json
{
"graph": {
"graph_id": "acme-outbound-assistant-graph-v1",
"name": "ACME outbound assistant workflow",
"source": {
"platform": "n8n",
"source_uri": "https://n8n.acme.local/workflows/outbound-assistant",
"importer": "workflow-import-normalizer"
}
},
"scorecard": {
"high_risk_workflows": 7,
"dangerous_compositions": 4,
"external_effects": 5,
"irreversible_actions": 3,
"approval_bypasses": 3
}
}authority_register_json
acme-workflow-authority-register.json
application/json
{
"graph_id": "acme-outbound-assistant-graph-v1",
"tools_discovered": 38
}threat_model_json
acme-workflow-threat-model.json
application/json
{
"graph_id": "acme-outbound-assistant-graph-v1",
"title": "ACME outbound assistant workflow"
}export_manifest_md
acme-workflow-analysis.md
text/markdown
# ACME outbound assistant workflow - High-risk workflows: 7 - Tools discovered: 38 - Approval coverage: 68% - Approval bypasses: 3
Individually reasonable permissions can compose into unsafe authority.
A system may appear constrained when each permission is reviewed separately. Risk emerges when an agent can combine retrieval, credentials, tools, delegated identity, and downstream actions into an end-to-end path.
Unsafe Authority Composition
Individually reasonable permissions can combine into a dangerous end-to-end authority path.
Graph showing separate read, plan, tool, and approval permissions combining into one consequential authority path.
The graph exposes these composed paths before they become an incident, allowing reviewers to distinguish ordinary access from authority that can cross trust boundaries or create irreversible effects.
Recommendations preserve evidence and ownership.
Least-privilege, approval, credential-scope, and separation-of-duties recommendations record their configuration basis, confidence, inferred reachability, and responsible remediation owner before they become control decisions.
Break several authority paths with one well-placed control.
The highest-value remediation is often not another detector. It is the approval gate, permission boundary, credential scope, action limit, or separation-of-duties control shared by several dangerous paths.
Authority to Control Chokepoint
A small change to permission, approval, or action scope can break several unsafe authority paths.
Several authority paths converging on overbroad permission, followed by a constrained policy and approval gate that blocks or reduces the paths.
Chokepoint analysis helps product, platform, identity, and security teams prioritize controls that materially reduce reachable impact rather than merely shrinking isolated permission lists.