Cerberus blocks the lethal trifecta at the tool boundary — see the 525-run evidence set.

Warden · Agentic Assurance

Before you scale agents, find out what the ones you already have can reach

A structured assessment of the agents running in your organization — the tools they hold, the data those tools expose, and the actions nobody scoped when the integration was added.

Most estates cannot answer the first question

Agents arrive through developer tooling, SaaS features and copilots rather than through procurement, so the inventory is usually incomplete and the permissions are usually inherited from whoever built the first prototype.

  1. The agents are not in the CMDBAn assistant wired into a ticketing system through an API key is a production integration that no asset register knows about.
  2. Permissions were set for convenienceTool credentials are typically scoped to what made the demo work, not to what the task requires.
  3. Nobody owns the blast radiusThe team that built the agent owns the feature; no one owns the question of what it could do if it were manipulated.

How the assessment runs

Two to four weeks, depending on estate size, run alongside your teams rather than over them.

1

Discovery

Interviews plus telemetry and code review to enumerate agents, frameworks, models, tools and the credentials each one holds.

2

Reachability analysis

For each agent, the set of actions it can take and the data it can read — including transitively, through the tools it can call.

3

Exposure rating

Where the lethal trifecta of private data access, untrusted input and an outbound channel co-occurs in a single agent.

4

Prioritized roadmap

What to constrain first, what to instrument, and what is safe to leave alone for now.

What you hold at the end

  • An inventory of agents, models, frameworks and tool integrations in use
  • A reachability map per agent: data readable, actions available, credentials held
  • Exposure findings rated by blast radius, with the specific tool call that creates each one
  • A remediation roadmap sequenced by risk reduction per unit of engineering effort
  • A read-out for the risk or board audience, in their language rather than ours

What we deploy against the findings

The assessment is product-neutral. These are what we use when you want the findings enforced rather than filed.

Start with the estate you have, not the one on the roadmap

Most organizations discover in week one that the agents already in production are the ones worth worrying about.