Securing Agentic Systems
by David Matousek
Book 1 covers building agentic systems. This one covers securing them: the threat model, the posture framework, and the governance that holds under real production load. Chapters publish weekly in The Agentic Shift and land here as they go live.
Part 1 The Threat Model
- Coming soon
Defense-in-Depth for Agentic Systems
Layered Security for AI That Actually Works
- Coming soon
Know Your Agent - The Type Taxonomy
Why \"Agent\" Is Doing Too Much Work as a Category
- Coming soon
Context as Attack Surface
Injection, Pollution, and Exfiltration
- Coming soon
Shift Left, To the Agent
Security as Agent Orchestration, Not Pipeline
- Coming soon
AI Reasoning as a Security Mechanism
One Capability, Three Altitudes
- Coming soon
Governance as Security
Governing the Agentic Stack, Layer by Layer
- Coming soon
Securing the Inheritance Chain
How Unsafe Patterns Propagate Through Spawn Trees
Part 2 The Agentic Security Posture
- Coming soon
The Agentic Security Posture Framework
Seven Posture Domains for Securing AI Agents
- Coming soon
Agent Identity Posture
Who Is This Agent?
- Coming soon
Agent Input Posture
What Can Influence This Agent?
- Coming soon
Agent Data & Context Posture
What Does This Agent Remember and Trust?
- Coming soon
Agent Tool & API Posture
What Can This Agent Touch?
- Coming soon
Agent Communication Posture
How Do Agents Talk to Each Other?
- Coming soon
Agent Runtime Posture
Where Does This Agent Run?
- Coming soon
Agent Governance Posture
Can You See What This Agent Is Doing?
Part 3 The DevSecOps Transformation
- Coming soon
When the Pipeline Loses Its Authority
The Governance Crisis of Shifting Security Left
- Coming soon
Rebuilding Governance for the Agentic Era
Attestation, Compliance Evidence, and the New Trust Model
Part 4 The AI-Native Pipeline
- Coming soon
The AI-Native Pipeline
The Reference Architecture
- Coming soon
Securing Discover
Risk Classification and the Attack-Surface Map
- Coming soon
Securing Define
Intent Is a Security Artifact
- Coming soon
Securing Plan
Threat-Model the Design
- Coming soon
Securing Build
The Reasoning Scan Joins the Floor
- Coming soon
Securing Deliver
Evidence at the Gate, Not a Review Board
- Coming soon
Securing Document
The Evidence Every Turn Leaves Behind
- Coming soon
The Execution Layer
Governed at the Edge, Outside the Loop
Part 5 Governance in Practice
- Coming soon
Beyond Coding Agents - Governance Across Domains
When \"Commit\" Means Something Different
- Coming soon
Agent Security Posture in the Enterprise
From Framework to Practice
- Coming soon
Conclusion - Security Is Not a Feature
TBD