PARTNERS

Add selected Workbench capabilities through bounded OEM and partner integrations

Practitioner field guide · 2026

Published

Practical playbooks for AI security work in the field.

Map the system, inspect the boundary, test the abuse path, choose the control, collect the evidence, and turn the result into owned engineering work.

14

Domains

12+

Artifact types

Field

Practitioner use

Free

Open access

Free PDF · No signup required

Positioning

Field Guide vs Handbook

Practitioner-first

Use the guide to inspect systems, map boundaries, test abuse paths, choose controls, collect evidence, and write remediation work.

Domain-based

The 14-domain spine covers LLM apps, RAG, agents, model supply chain, MLOps, governance evidence, procurement, and architecture.

Artifact-producing

Each domain points to questions, checks, controls, evidence, Workbench instruments, service paths, and Handbook background.

Field Guide

Applied, practitioner-first, domain-based, checklist-heavy, evidence-oriented, and built to support assessment delivery.

Handbook

Educational, chapter-based, concept-first, and built for study, training, discipline vocabulary, and operating-model background.

Visual playbooks

See the system, the authority, and the evidence chain.

Practitioner workflow from the AI Security Engineering Field Guide

Practitioner workflow

Move from inventory and boundary mapping through testing, controls, evidence, remediation, and retest.

Agent authority graph from the AI Security Engineering Field Guide

Agent authority graph

Make delegated action, tool scope, approvals, identities, side effects, and rollback visible.

Governance evidence chain from the AI Security Engineering Field Guide

Governance evidence chain

Trace executive intent into controls, telemetry, decisions, backlog work, and reviewable proof.

Domain index

The 14 applied AI security domains

01

AI Security Foundations

02

LLM Application Security

03

Prompt Injection and Context Security

04

RAG Security

05

Agent Security

06

Model Supply Chain Security

07

MLOps Platform Security

08

AI-Aware Secure SDLC

09

Privacy and Data Protection in AI Systems

10

AI Governance, Risk, and Compliance

11

Red Teaming and Adversarial Evaluations

12

Incident Response and AI Observability

13

Vendor Risk and AI Procurement

14

Secure AI Architecture Design

Practitioner checklist

Use it to produce review evidence

01

Map the AI system surface before testing behavior.

02

Mark trust boundaries for prompts, retrieval, tools, memory, providers, and logs.

03

Run checks against data access, delegated action, provider boundaries, and fallback paths.

04

Collect evidence that shows controls ran.

05

Turn findings into backlog items with owner, test, evidence, and retest date.