Skip to main content

Securing Agentic Systems

by David Matousek

Book 1 covers building agentic systems. This one covers securing them: the threat model, the posture framework, and the governance that holds under real production load. Chapters publish weekly in The Agentic Shift and land here as they go live.

Introduction

Part 1 Map

Part 2 Measure

  • AI Reasoning as a Security Mechanism

    One Capability, Three Altitudes

    Coming soon
  • The Seven Agentic Posture Domains

    Seven Posture Domains for Securing AI Agents

    Coming soon
  • Agent Identity Posture

    Who Is This Agent?

    Coming soon
  • Agent Input Posture

    What Can Influence This Agent?

    Coming soon
  • Agent Data & Context Posture

    What Does This Agent Remember and Trust?

    Coming soon
  • Agent Tool & API Posture

    What Can This Agent Touch?

    Coming soon
  • Agent Communication Posture

    How Do Agents Talk to Each Other?

    Coming soon
  • Agent Runtime Posture

    Where Does This Agent Run?

    Coming soon
  • Agent Governance Posture

    Can You See What This Agent Is Doing?

    Coming soon

Part 3 Rank

  • Rank by Value and Exposure

    One Slide, Two Axes, and Who Scores Which

    Coming soon
  • Beyond Coding Agents - Governance Across Domains

    When "Commit" Means Something Different

    Coming soon

Part 4 Govern

  • Governance as Security

    Governing the Agentic Stack, Layer by Layer

    Coming soon
  • Securing the Inheritance Chain

    How Unsafe Patterns Propagate Through Spawn Trees

    Coming soon
  • Shift Left, To the Agent

    Security as Agent Orchestration, Not Pipeline

    Coming soon
  • When the Pipeline Loses Its Authority

    The Governance Crisis of Shifting Security Left

    Coming soon
  • Rebuilding Governance for the Agentic Era

    Attestation, Compliance Evidence, and the New Trust Model

    Coming soon
  • The AI-Native Pipeline

    The Reference Architecture

    Coming soon
  • Securing Discover

    Risk Classification and the Attack-Surface Map

    Coming soon
  • Securing Define

    Intent Is a Security Artifact

    Coming soon
  • Securing Plan

    Threat-Model the Design

    Coming soon
  • Securing Build

    The Reasoning Scan Joins the Floor

    Coming soon
  • Securing Deliver

    Evidence at the Gate, Not a Review Board

    Coming soon
  • Securing Document

    The Evidence Every Turn Leaves Behind

    Coming soon
  • The Execution Layer

    Governed at the Edge, Outside the Loop

    Coming soon

Part 5 Prove

  • Prove It with Numbers

    Two Signals per Finding, One Rule per Metric

    Coming soon
  • Agent Security Posture in the Enterprise

    From Framework to Practice

    Coming soon
  • Conclusion - Security Is Not a Feature

    TBD

    Coming soon
Book One

Agentic-Oriented Development

The first living book, on building agentic AI systems. Complete, start to finish.

Start reading