PARTNERS

Add selected Workbench capabilities through bounded OEM and partner integrations

M.A.D.E. · DEFEND

Agent Authority Review & Hardening

Compare intended authority with what the workflow can actually do.

Compare declared permissions, intended workflow boundaries, tool schemas, API scopes, runtime identities, approval requirements, side effects, and available execution evidence. Agent Authority Review identifies excessive or poorly controlled authority and turns it into a concrete hardening backlog.

WHAT CAN YOUR AGENTS ACTUALLY DO?

Compare

Compare intended authority, declared permissions, tool definitions, API scopes, runtime identities, approvals, and available evidence.

Detect

Identify excessive read, write, delete, send, execute, administer, secret, filesystem, browser, network, and external-action authority.

Harden

Split tools, reduce scopes, constrain identities, add approval gates, improve argument controls, and create audit trails.

Review

Produce a human-reviewable decision record without replacing security or system-owner judgment.

Core capabilities

What Agent Authority Review does.

Declared vs Observed Permissions

Compare declared and intended authority against capabilities visible in schemas, API grants, runtime identities, implementation evidence, and approved observations.

Excessive authority analysis

Identify workflows whose combined permissions, tools, identities, or side effects exceed the intended business purpose.

OAuth and API Scope Review

Identify broad or hidden grants, administrator access, cross-tenant scope, external-action permissions, and credentials that should be reduced or isolated.

Approval Gate Analysis

Identify missing, optional, weak, or bypassable approvals around irreversible, external, administrative, high-value, or high-blast-radius actions.

Tool Hardening Plan

Recommend smaller tools, narrower scopes, constrained identities, explicit approvals, argument validation, audit trails, rollback controls, and release-blocking changes.

Connected model and evidence handoff

Carry approved authority findings into Threat Canvas, Authority Graph, engineering backlog, release decisions, retest requirements, and evidence outputs.

Evidence & signals

What you get out of the box.

Capability Classes

  • Read
  • Write
  • Delete
  • Send
  • Execute
  • Admin
  • Secret
  • Filesystem
  • Browser
  • Network

Findings

  • Declared-versus-effective authority comparison
  • Excessive-authority findings
  • Identity and scope review
  • Missing or bypassable approvals
  • Dangerous side-effect combinations
  • Release-blocking risks
  • Evidence and observation gaps

Hardening Outputs

  • Tool split recommendations
  • Reduced scopes
  • Constrained runtime identities
  • Approval requirements
  • Argument and action controls
  • Audit and rollback gaps
  • Engineering backlog
  • Retest conditions

Authority Graph models the system. Agent Authority Review changes it.

Authority Graph shows how identities, credentials, tools, permissions, approvals, data, and actions compose. Agent Authority Review uses that context to compare intended and effective authority, assign remediation, define retest conditions, and preserve the decision.

AI SECURITY WORKBENCH

Ready to reduce effective agent authority?

Use Agent Authority Review to compare intended and effective capability, identify the smallest useful control changes, assign the hardening work, and define how the workflow will be retested.