{"schema_version":"0.1","generated_at":"2026-07-26T06:08:46.699834+00:00","report_type":"fleet_agent_access_audit","scope":{"agents":30,"tools":34,"delegation_edges":3,"what_was_analyzed":"Agent configuration metadata: grants, declared purpose, ownership, usage, and delegation. No agent payload data was analyzed."},"executive_summary":{"findings":10,"severity_counts":{"critical":6,"high":4,"medium":0,"low":0},"critical_agents":6,"review_status":30,"top_risks":[{"rank":1,"agent_id":"support_bot","title":"Critical data-exfiltration path","severity":"critical","risk_score":64,"check_type":"sod"},{"rank":2,"agent_id":"report_bot","title":"Unused standing access: 2 direct grants","severity":"high","risk_score":58,"check_type":"over_privilege"},{"rank":3,"agent_id":"invoice_bot","title":"Critical fraud path: create vendor and approve payment","severity":"critical","risk_score":54,"check_type":"sod"},{"rank":4,"agent_id":"payroll_bot","title":"Critical ghost-employee fraud path","severity":"critical","risk_score":54,"check_type":"sod"},{"rank":5,"agent_id":"sales_bot","title":"AI-generalized toxic capability combination: Read CRM account context + Send email outside the company","severity":"high","risk_score":54,"check_type":"sod"}],"framework_coverage":{"frameworks":5,"controls":15},"review_status_counts":{"pending":30},"peer_outliers":1},"certification_campaigns":null,"peer_analytics":{"method":"Jaccard similarity of effective access sets; an agent isolated from every peer (max similarity at or below the threshold) while holding enough access is flagged. Heuristic, not a policy finding.","similarity_threshold":0.3,"min_tools":3,"agents_considered":30,"applicable":true,"note":"1 agent(s) hold access unlike any peer. Indicative on a small fleet, not statistical: a legitimately unique role looks the same as a mistake.","outliers":[{"agent_id":"report_bot","effective_tool_count":3,"high_impact_count":2,"max_similarity":0.25,"nearest_peer":"bi_bot","reason":"Holds 3 effective tools (2 high-impact: delete_records, export_data), but overlaps at most 25% with any peer (closest: bi_bot) — an access profile unlike the rest of the fleet, worth a look for over-grant."}]},"control_mapping":[{"check_type":"escalation","label":"Delegation escalation","control_mapping":"Delegated authority — confused-deputy control","findings":3,"highest_severity":"critical"},{"check_type":"orphan","label":"Orphaned agent","control_mapping":"Accountability — named ownership","findings":1,"highest_severity":"high"},{"check_type":"over_privilege","label":"Over-privilege","control_mapping":"Least privilege — periodic access certification","findings":1,"highest_severity":"high"},{"check_type":"sod","label":"Segregation of duties","control_mapping":"SOX ITGC — segregation of duties","findings":5,"highest_severity":"critical"}],"control_framework_coverage":[{"framework":"EU AI Act (Regulation (EU) 2024/1689)","controls":[{"framework":"EU AI Act (Regulation (EU) 2024/1689)","control_id":"Art. 14","control_name":"Human oversight","findings":5,"check_types":["sod"]}]},{"framework":"ISO/IEC 27001:2022","controls":[{"framework":"ISO/IEC 27001:2022","control_id":"A.5.15","control_name":"Access control","findings":5,"check_types":["sod"]},{"framework":"ISO/IEC 27001:2022","control_id":"A.5.16","control_name":"Identity management","findings":1,"check_types":["orphan"]},{"framework":"ISO/IEC 27001:2022","control_id":"A.5.18","control_name":"Access rights","findings":6,"check_types":["over_privilege","sod"]},{"framework":"ISO/IEC 27001:2022","control_id":"A.8.2","control_name":"Privileged access rights","findings":4,"check_types":["escalation","over_privilege"]}]},{"framework":"NIST SP 800-53 Rev. 5","controls":[{"framework":"NIST SP 800-53 Rev. 5","control_id":"AC-2","control_name":"Account Management","findings":1,"check_types":["orphan"]},{"framework":"NIST SP 800-53 Rev. 5","control_id":"AC-5","control_name":"Separation of Duties","findings":8,"check_types":["escalation","sod"]},{"framework":"NIST SP 800-53 Rev. 5","control_id":"AC-6","control_name":"Least Privilege","findings":3,"check_types":["escalation"]},{"framework":"NIST SP 800-53 Rev. 5","control_id":"AC-6 / AC-6(1)","control_name":"Least Privilege / Authorize Access to Security Functions","findings":1,"check_types":["over_privilege"]}]},{"framework":"SOC 2 Trust Services Criteria (2017)","controls":[{"framework":"SOC 2 Trust Services Criteria (2017)","control_id":"CC6.1","control_name":"Logical access security","findings":4,"check_types":["escalation","over_privilege"]},{"framework":"SOC 2 Trust Services Criteria (2017)","control_id":"CC6.2","control_name":"User registration and authorization","findings":1,"check_types":["orphan"]},{"framework":"SOC 2 Trust Services Criteria (2017)","control_id":"CC6.3","control_name":"Access modification and segregation of duties","findings":6,"check_types":["over_privilege","sod"]}]},{"framework":"SOX ITGC","controls":[{"framework":"SOX ITGC","control_id":"Access accountability","control_name":"Accountable ownership of access","findings":1,"check_types":["orphan"]},{"framework":"SOX ITGC","control_id":"Least privilege","control_name":"Least-privilege provisioning","findings":1,"check_types":["over_privilege"]},{"framework":"SOX ITGC","control_id":"SoD","control_name":"Segregation of duties over financial processes","findings":5,"check_types":["sod"]}]}],"governance_process_controls":[{"framework":"EU AI Act (Regulation (EU) 2024/1689)","control_id":"Art. 12","control_name":"Record-keeping","relevance":"Findings and certification decisions are recorded in a tamper-evident, verifiable log."},{"framework":"NIST SP 800-53 Rev. 5","control_id":"AU-2","control_name":"Event Logging","relevance":"Analysis and review events are captured as signed, append-only audit records."},{"framework":"NIST SP 800-53 Rev. 5","control_id":"AU-6","control_name":"Audit Record Review, Analysis, and Reporting","relevance":"The ledger supports independent offline verification and review of recorded events."},{"framework":"NIST SP 800-53 Rev. 5","control_id":"AC-2","control_name":"Account Management (review)","relevance":"The certification queue implements periodic review of agent-identity access."},{"framework":"ISO/IEC 27001:2022","control_id":"A.8.15","control_name":"Logging","relevance":"Governance events are logged in a form protected against tampering."}],"findings":[{"id":"sod:support_bot:sensitive_data_external_egress","rule_id":"sensitive_data_external_egress","agent_id":"support_bot","check_type":"sod","check_label":"Segregation of duties","source":"deterministic","source_label":"Deterministic check","source_description":"Rule-based detection from Steward's deterministic safety floor. The deterministic tier is covered by the labeled synthetic-fleet regression and precision gate.","source_css_class":"source-deterministic","severity":"critical","title":"Critical data-exfiltration path","business_risk":"SupportBot can read customer PII and directly send external email, creating a direct path for confidential customer data to be exfiltrated outside the organization, exposing the firm to regulatory violations, financial penalties, and reputational harm.","evidence":[{"entity_type":"agent","entity_id":"support_bot","detail":"holds this effective-access combination"},{"entity_type":"tool","entity_id":"read_customer_pii","detail":"SupportBot has a direct grant of read_customer_pii."},{"entity_type":"tool","entity_id":"send_external_email","detail":"SupportBot has a direct grant of send_external_email."}],"recommended_action":"Revoke the direct read_customer_pii and send_external_email grants from SupportBot; implement least‑privilege controls, require mediated approval for external egress, and add monitoring/auditing of any PII access and outbound email activity.","control_mapping":"Data protection — least privilege and controlled external egress","owasp_mcp":[{"title":"Tool Poisoning","url":"https://owasp.org/www-project-mcp-top-10/2025/MCP03-2025%E2%80%93Tool-Poisoning","relevance":"A compromised or misleading tool can steer an agent toward unintended data handling or external actions.","id":"MCP03:2025"},{"title":"Software Supply Chain Attacks & Dependency Tampering","url":"https://owasp.org/www-project-mcp-top-10/2025/MCP04-2025%E2%80%93Software-Supply-Chain-Attacks%26Dependency-Tampering","relevance":"A compromised MCP dependency can add covert external egress to an otherwise trusted workflow.","id":"MCP04:2025"}],"real_world_incident":[{"title":"Supabase MCP stored prompt-injection scenario","url":"https://supabase.com/blog/defense-in-depth-mcp","relevance":"Supabase documented a scenario where stored instructions led an MCP-connected agent to read private database data and write it into an attacker-visible field. It illustrates this read-to-egress risk class; it is not evidence that this fleet uses Supabase.","date":"Documented 16 Sep 2025"},{"title":"Malicious postmark-mcp package backdoor (v1.0.16)","url":"https://postmarkapp.com/blog/information-regarding-malicious-postmark-mcp-package","relevance":"Postmark reported that an impersonating npm package silently BCC'd email to an external server. It is an analogous tool-poisoning and supply-chain incident, not evidence that this fleet installed the package.","date":"Postmark advisory, 25 Sep 2025"}],"control_frameworks":[{"framework":"NIST SP 800-53 Rev. 5","control_id":"AC-5","control_name":"Separation of Duties","relevance":"One agent identity holds both sides of a duty that the control requires to be separated."},{"framework":"SOC 2 Trust Services Criteria (2017)","control_id":"CC6.3","control_name":"Access modification and segregation of duties","relevance":"Toxic capability combinations in one identity undermine segregation-of-duties objectives."},{"framework":"ISO/IEC 27001:2022","control_id":"A.5.15","control_name":"Access control","relevance":"Access rules should prevent a single identity from combining conflicting capabilities."},{"framework":"ISO/IEC 27001:2022","control_id":"A.5.18","control_name":"Access rights","relevance":"Provisioned rights should be reviewed so conflicting entitlements are not co-held."},{"framework":"SOX ITGC","control_id":"SoD","control_name":"Segregation of duties over financial processes","relevance":"An agent that can initiate and approve the same transaction defeats independent review."},{"framework":"EU AI Act (Regulation (EU) 2024/1689)","control_id":"Art. 14","control_name":"Human oversight","relevance":"A toxic combination lets an AI agent complete a consequential action without an independent human checkpoint."}],"risk_score":64,"risk_factors":{"base_severity":40,"blast_radius":4,"data_sensitivity":10,"exploitability":10,"untrusted_exposure":0}},{"id":"over_privilege:report_bot:unused_granted_tools","rule_id":"unused_granted_tools","agent_id":"report_bot","check_type":"over_privilege","check_label":"Over-privilege","source":"deterministic","source_label":"Deterministic check","source_description":"Rule-based detection from Steward's deterministic safety floor. The deterministic tier is covered by the labeled synthetic-fleet regression and precision gate.","source_css_class":"source-deterministic","severity":"high","title":"Unused standing access: 2 direct grants","business_risk":"ReportBot holds standing privileges to delete records and export data that are never exercised. If the agent were compromised or misused, an attacker could invoke these unused grants to irreversibly remove critical data or exfiltrate sensitive information, exposing the organization to data loss, regulatory non‑compliance, and reputational damage.","evidence":[{"entity_type":"agent","entity_id":"report_bot","detail":"usage log contains no invocation of these direct grants: delete_records, export_data"},{"entity_type":"tool","entity_id":"delete_records","detail":"ReportBot has a direct grant of delete_records."},{"entity_type":"tool","entity_id":"export_data","detail":"ReportBot has a direct grant of export_data."}],"recommended_action":"Revoke the unnecessary delete_records and export_data grants from ReportBot and re‑certify its access against the principle of least privilege. Implement periodic review of granted versus used permissions for all agents.","control_mapping":"Least privilege — access certification using granted versus used access","owasp_mcp":[],"real_world_incident":[],"control_frameworks":[{"framework":"NIST SP 800-53 Rev. 5","control_id":"AC-6 / AC-6(1)","control_name":"Least Privilege / Authorize Access to Security Functions","relevance":"Standing grants with no observed use exceed the minimum access the agent's function requires."},{"framework":"SOC 2 Trust Services Criteria (2017)","control_id":"CC6.1","control_name":"Logical access security","relevance":"Unused standing entitlements enlarge the logical-access attack surface without business need."},{"framework":"SOC 2 Trust Services Criteria (2017)","control_id":"CC6.3","control_name":"Access modification and segregation of duties","relevance":"Granted-but-unused access should be removed through the access-modification process."},{"framework":"ISO/IEC 27001:2022","control_id":"A.8.2","control_name":"Privileged access rights","relevance":"High-risk unused entitlements are privileged rights that should be restricted and reviewed."},{"framework":"ISO/IEC 27001:2022","control_id":"A.5.18","control_name":"Access rights","relevance":"Access rights should be adjusted when observed use does not support the grant."},{"framework":"SOX ITGC","control_id":"Least privilege","control_name":"Least-privilege provisioning","relevance":"Unused financially-relevant entitlements weaken ITGC access assertions."}],"risk_score":58,"risk_factors":{"base_severity":30,"blast_radius":8,"data_sensitivity":10,"exploitability":10,"untrusted_exposure":0}},{"id":"sod:invoice_bot:finance_create_vendor_approve_payment","rule_id":"finance_create_vendor_approve_payment","agent_id":"invoice_bot","check_type":"sod","check_label":"Segregation of duties","source":"deterministic","source_label":"Deterministic check","source_description":"Rule-based detection from Steward's deterministic safety floor. The deterministic tier is covered by the labeled synthetic-fleet regression and precision gate.","source_css_class":"source-deterministic","severity":"critical","title":"Critical fraud path: create vendor and approve payment","business_risk":"InvoiceBot possesses both the create_vendor and approve_payment tool grants, giving a single automated agent the ability to add new vendors and subsequently authorize payments to those vendors. This concentration of authority creates a direct fraud pathway that could be exploited to generate fictitious vendors and approve unauthorized disbursements, potentially resulting in material financial loss and SOX compliance violations across the entire accounts‑payable function.","evidence":[{"entity_type":"agent","entity_id":"invoice_bot","detail":"holds this effective-access combination"},{"entity_type":"tool","entity_id":"approve_payment","detail":"InvoiceBot has a direct grant of approve_payment."},{"entity_type":"tool","entity_id":"create_vendor","detail":"InvoiceBot has a direct grant of create_vendor."}],"recommended_action":"Implement segregation of duties by revoking either the create_vendor or approve_payment grant from InvoiceBot, enforce dual‑approval controls for vendor creation and payment authorization, and add continuous monitoring to detect any instance where a single entity performs both actions.","control_mapping":"SOX ITGC — segregation of duties (vendor creation versus payment approval)","owasp_mcp":[],"real_world_incident":[],"control_frameworks":[{"framework":"NIST SP 800-53 Rev. 5","control_id":"AC-5","control_name":"Separation of Duties","relevance":"One agent identity holds both sides of a duty that the control requires to be separated."},{"framework":"SOC 2 Trust Services Criteria (2017)","control_id":"CC6.3","control_name":"Access modification and segregation of duties","relevance":"Toxic capability combinations in one identity undermine segregation-of-duties objectives."},{"framework":"ISO/IEC 27001:2022","control_id":"A.5.15","control_name":"Access control","relevance":"Access rules should prevent a single identity from combining conflicting capabilities."},{"framework":"ISO/IEC 27001:2022","control_id":"A.5.18","control_name":"Access rights","relevance":"Provisioned rights should be reviewed so conflicting entitlements are not co-held."},{"framework":"SOX ITGC","control_id":"SoD","control_name":"Segregation of duties over financial processes","relevance":"An agent that can initiate and approve the same transaction defeats independent review."},{"framework":"EU AI Act (Regulation (EU) 2024/1689)","control_id":"Art. 14","control_name":"Human oversight","relevance":"A toxic combination lets an AI agent complete a consequential action without an independent human checkpoint."}],"risk_score":54,"risk_factors":{"base_severity":40,"blast_radius":4,"data_sensitivity":0,"exploitability":10,"untrusted_exposure":0}},{"id":"sod:payroll_bot:hr_add_employee_run_payroll","rule_id":"hr_add_employee_run_payroll","agent_id":"payroll_bot","check_type":"sod","check_label":"Segregation of duties","source":"deterministic","source_label":"Deterministic check","source_description":"Rule-based detection from Steward's deterministic safety floor. The deterministic tier is covered by the labeled synthetic-fleet regression and precision gate.","source_css_class":"source-deterministic","severity":"critical","title":"Critical ghost-employee fraud path","business_risk":"PayrollBot holds direct authority to both add_employee (employee creation) and run_payroll (payroll execution). This conflation of employee setup and payroll processing creates a critical segregation‑of‑duties violation, enabling a malicious or compromised bot to create ghost employees and issue unauthorized payroll payments, potentially resulting in financial loss, regulatory non‑compliance, and reputational harm across the entire payroll function.","evidence":[{"entity_type":"agent","entity_id":"payroll_bot","detail":"holds this effective-access combination"},{"entity_type":"tool","entity_id":"add_employee","detail":"PayrollBot has a direct grant of add_employee."},{"entity_type":"tool","entity_id":"run_payroll","detail":"PayrollBot has a direct grant of run_payroll."}],"recommended_action":"Re‑engineer the permission model to enforce segregation of duties: remove the direct add_employee grant from PayrollBot, require an independent approval workflow for employee creation, and limit payroll execution to a separate, controlled role. Implement least‑privilege access, periodic access reviews, and monitoring of employee‑creation and payroll‑run activities.","control_mapping":"SOX ITGC — segregation of duties (employee setup versus payroll execution)","owasp_mcp":[],"real_world_incident":[],"control_frameworks":[{"framework":"NIST SP 800-53 Rev. 5","control_id":"AC-5","control_name":"Separation of Duties","relevance":"One agent identity holds both sides of a duty that the control requires to be separated."},{"framework":"SOC 2 Trust Services Criteria (2017)","control_id":"CC6.3","control_name":"Access modification and segregation of duties","relevance":"Toxic capability combinations in one identity undermine segregation-of-duties objectives."},{"framework":"ISO/IEC 27001:2022","control_id":"A.5.15","control_name":"Access control","relevance":"Access rules should prevent a single identity from combining conflicting capabilities."},{"framework":"ISO/IEC 27001:2022","control_id":"A.5.18","control_name":"Access rights","relevance":"Provisioned rights should be reviewed so conflicting entitlements are not co-held."},{"framework":"SOX ITGC","control_id":"SoD","control_name":"Segregation of duties over financial processes","relevance":"An agent that can initiate and approve the same transaction defeats independent review."},{"framework":"EU AI Act (Regulation (EU) 2024/1689)","control_id":"Art. 14","control_name":"Human oversight","relevance":"A toxic combination lets an AI agent complete a consequential action without an independent human checkpoint."}],"risk_score":54,"risk_factors":{"base_severity":40,"blast_radius":4,"data_sensitivity":0,"exploitability":10,"untrusted_exposure":0}},{"id":"sod:sales_bot:llm_toxic_read_crm_send_external_email","rule_id":"llm_toxic_read_crm_send_external_email","agent_id":"sales_bot","check_type":"sod","check_label":"Segregation of duties","source":"llm_generalized","source_label":"LLM-generalized","source_description":"The configured model proposed this additional combination; Steward verified its graph citations before showing it. It is evaluated separately from the deterministic golden-set gate.","source_css_class":"source-llm-generalized","severity":"high","title":"AI-generalized toxic capability combination: Read CRM account context + Send email outside the company","business_risk":"The SalesBot agent can both read CRM account context and send email outside the company, creating a direct path to expose customer information to external recipients. This combination can lead to unauthorized data disclosure, regulatory non‑compliance, reputational damage, and potential financial loss.","evidence":[{"entity_type":"agent","entity_id":"sales_bot","detail":"holds the cited effective-access combination."},{"entity_type":"tool","entity_id":"read_crm","detail":"SalesBot has a direct grant of read_crm."},{"entity_type":"tool","entity_id":"send_external_email","detail":"SalesBot has a direct grant of send_external_email."}],"recommended_action":"Separate the read_crm and send_external_email permissions, enforce a dual‑approval workflow for any external email that includes CRM data, and implement continuous monitoring and audit of combined usage.","control_mapping":"Identity governance — Model-identified segregation-of-duties candidate","owasp_mcp":[{"title":"Tool Poisoning","url":"https://owasp.org/www-project-mcp-top-10/2025/MCP03-2025%E2%80%93Tool-Poisoning","relevance":"A compromised or misleading tool can steer an agent toward unintended data handling or external actions.","id":"MCP03:2025"},{"title":"Software Supply Chain Attacks & Dependency Tampering","url":"https://owasp.org/www-project-mcp-top-10/2025/MCP04-2025%E2%80%93Software-Supply-Chain-Attacks%26Dependency-Tampering","relevance":"A compromised MCP dependency can add covert external egress to an otherwise trusted workflow.","id":"MCP04:2025"}],"real_world_incident":[{"title":"Supabase MCP stored prompt-injection scenario","url":"https://supabase.com/blog/defense-in-depth-mcp","relevance":"Supabase documented a scenario where stored instructions led an MCP-connected agent to read private database data and write it into an attacker-visible field. It illustrates this read-to-egress risk class; it is not evidence that this fleet uses Supabase.","date":"Documented 16 Sep 2025"},{"title":"Malicious postmark-mcp package backdoor (v1.0.16)","url":"https://postmarkapp.com/blog/information-regarding-malicious-postmark-mcp-package","relevance":"Postmark reported that an impersonating npm package silently BCC'd email to an external server. It is an analogous tool-poisoning and supply-chain incident, not evidence that this fleet installed the package.","date":"Postmark advisory, 25 Sep 2025"}],"control_frameworks":[{"framework":"NIST SP 800-53 Rev. 5","control_id":"AC-5","control_name":"Separation of Duties","relevance":"One agent identity holds both sides of a duty that the control requires to be separated."},{"framework":"SOC 2 Trust Services Criteria (2017)","control_id":"CC6.3","control_name":"Access modification and segregation of duties","relevance":"Toxic capability combinations in one identity undermine segregation-of-duties objectives."},{"framework":"ISO/IEC 27001:2022","control_id":"A.5.15","control_name":"Access control","relevance":"Access rules should prevent a single identity from combining conflicting capabilities."},{"framework":"ISO/IEC 27001:2022","control_id":"A.5.18","control_name":"Access rights","relevance":"Provisioned rights should be reviewed so conflicting entitlements are not co-held."},{"framework":"SOX ITGC","control_id":"SoD","control_name":"Segregation of duties over financial processes","relevance":"An agent that can initiate and approve the same transaction defeats independent review."},{"framework":"EU AI Act (Regulation (EU) 2024/1689)","control_id":"Art. 14","control_name":"Human oversight","relevance":"A toxic combination lets an AI agent complete a consequential action without an independent human checkpoint."}],"risk_score":54,"risk_factors":{"base_severity":30,"blast_radius":4,"data_sensitivity":10,"exploitability":10,"untrusted_exposure":0}},{"id":"escalation:chief_of_staff_bot:delegated_high_risk_payment_approval","rule_id":"delegated_high_risk_payment_approval","agent_id":"chief_of_staff_bot","check_type":"escalation","check_label":"Delegation escalation","source":"deterministic","source_label":"Deterministic check","source_description":"Rule-based detection from Steward's deterministic safety floor. The deterministic tier is covered by the labeled synthetic-fleet regression and precision gate.","source_css_class":"source-deterministic","severity":"critical","title":"Delegated payment-approval blast radius","business_risk":"Through the delegation edge, ChiefOfStaffBot can reach the finance_bot, which directly holds the approve_payment tool. Consequently, any user or process that can invoke ChiefOfStaffBot inherits the ability to trigger payment approvals via finance_bot. The practical blast radius therefore extends to all payment transactions that finance_bot is authorized to approve, creating a critical risk of unauthorized or fraudulent payments if the delegation is not tightly controlled.","evidence":[{"entity_type":"agent","entity_id":"chief_of_staff_bot","detail":"reaches approve_payment only through delegation to finance_bot"},{"entity_type":"delegation_edge","entity_id":"chief_of_staff_bot->finance_bot","detail":"chief_of_staff_bot can delegate to finance_bot."},{"entity_type":"agent","entity_id":"finance_bot","detail":"finance_bot is the direct grant holder reached through chief_of_staff_bot -> finance_bot."},{"entity_type":"tool","entity_id":"approve_payment","detail":"ChiefOfStaffBot effectively reaches approve_payment through chief_of_staff_bot -> finance_bot."}],"recommended_action":"Conduct an immediate access review of the delegation relationship between ChiefOfStaffBot and finance_bot. Restrict delegation to only verified, least‑privilege identities, enforce multi‑factor approval for payment actions, and implement monitoring/auditing of all approve_payment invocations originating from ChiefOfStaffBot.","control_mapping":"Identity governance — effective access review and least privilege","owasp_mcp":[],"real_world_incident":[],"control_frameworks":[{"framework":"NIST SP 800-53 Rev. 5","control_id":"AC-6","control_name":"Least Privilege","relevance":"Delegation extends the agent's effective privilege beyond its direct provisioning."},{"framework":"NIST SP 800-53 Rev. 5","control_id":"AC-5","control_name":"Separation of Duties","relevance":"Authority reachable through delegation recombines duties the direct grants kept separate."},{"framework":"SOC 2 Trust Services Criteria (2017)","control_id":"CC6.1","control_name":"Logical access security","relevance":"Effective access through delegation is logical access and must be evaluated as such."},{"framework":"ISO/IEC 27001:2022","control_id":"A.8.2","control_name":"Privileged access rights","relevance":"A privileged capability reachable only through delegation is still a privileged right of that identity."}],"risk_score":49,"risk_factors":{"base_severity":40,"blast_radius":4,"data_sensitivity":0,"exploitability":5,"untrusted_exposure":0}},{"id":"escalation:exec_briefing_bot:delegated_high_risk_payment_approval","rule_id":"delegated_high_risk_payment_approval","agent_id":"exec_briefing_bot","check_type":"escalation","check_label":"Delegation escalation","source":"deterministic","source_label":"Deterministic check","source_description":"Rule-based detection from Steward's deterministic safety floor. The deterministic tier is covered by the labeled synthetic-fleet regression and precision gate.","source_css_class":"source-deterministic","severity":"critical","title":"Delegated payment-approval blast radius","business_risk":"Compromise of ExecBriefingBot grants indirect access to the approve_payment tool via the delegation chain (ExecBriefingBot → chief_of_staff_bot → finance_bot). An attacker who gains control of ExecBriefingBot could approve payments without direct authorization, exposing the organization to unauthorized disbursements and potential financial loss.","evidence":[{"entity_type":"agent","entity_id":"exec_briefing_bot","detail":"reaches approve_payment only through delegation to finance_bot"},{"entity_type":"delegation_edge","entity_id":"exec_briefing_bot->chief_of_staff_bot","detail":"exec_briefing_bot can delegate to chief_of_staff_bot."},{"entity_type":"delegation_edge","entity_id":"chief_of_staff_bot->finance_bot","detail":"chief_of_staff_bot can delegate to finance_bot."},{"entity_type":"agent","entity_id":"finance_bot","detail":"finance_bot is the direct grant holder reached through exec_briefing_bot -> chief_of_staff_bot -> finance_bot."},{"entity_type":"tool","entity_id":"approve_payment","detail":"ExecBriefingBot effectively reaches approve_payment through exec_briefing_bot -> chief_of_staff_bot -> finance_bot."}],"recommended_action":"Restrict delegation paths so that ExecBriefingBot cannot reach payment‑approval capabilities, enforce least‑privilege principles on delegation edges, conduct an immediate access review of all delegated relationships, and implement monitoring/alerting for any use of approve_payment originating from indirect agents.","control_mapping":"Identity governance — effective access review and least privilege","owasp_mcp":[],"real_world_incident":[],"control_frameworks":[{"framework":"NIST SP 800-53 Rev. 5","control_id":"AC-6","control_name":"Least Privilege","relevance":"Delegation extends the agent's effective privilege beyond its direct provisioning."},{"framework":"NIST SP 800-53 Rev. 5","control_id":"AC-5","control_name":"Separation of Duties","relevance":"Authority reachable through delegation recombines duties the direct grants kept separate."},{"framework":"SOC 2 Trust Services Criteria (2017)","control_id":"CC6.1","control_name":"Logical access security","relevance":"Effective access through delegation is logical access and must be evaluated as such."},{"framework":"ISO/IEC 27001:2022","control_id":"A.8.2","control_name":"Privileged access rights","relevance":"A privileged capability reachable only through delegation is still a privileged right of that identity."}],"risk_score":49,"risk_factors":{"base_severity":40,"blast_radius":4,"data_sensitivity":0,"exploitability":5,"untrusted_exposure":0}},{"id":"escalation:summary_bot:delegated_high_risk_payment_approval","rule_id":"delegated_high_risk_payment_approval","agent_id":"summary_bot","check_type":"escalation","check_label":"Delegation escalation","source":"deterministic","source_label":"Deterministic check","source_description":"Rule-based detection from Steward's deterministic safety floor. The deterministic tier is covered by the labeled synthetic-fleet regression and precision gate.","source_css_class":"source-deterministic","severity":"critical","title":"Delegated payment-approval blast radius","business_risk":"This agent does not hold payment approval directly, but it can reach an agent that does through delegation. Its effective access therefore includes authority to authorize disbursements, creating a confused-deputy path.","evidence":[{"entity_type":"agent","entity_id":"summary_bot","detail":"reaches approve_payment only through delegation to finance_bot"},{"entity_type":"delegation_edge","entity_id":"summary_bot->finance_bot","detail":"summary_bot can delegate to finance_bot."},{"entity_type":"agent","entity_id":"finance_bot","detail":"finance_bot is the direct grant holder reached through summary_bot -> finance_bot."},{"entity_type":"tool","entity_id":"approve_payment","detail":"SummaryBot effectively reaches approve_payment through summary_bot -> finance_bot."}],"recommended_action":"Remove or constrain the delegation link to the payment-approving agent. If delegation is necessary, expose a narrowly scoped workflow action rather than the delegate's general approval authority.","control_mapping":"Identity governance — effective access review and least privilege","owasp_mcp":[{"title":"Privilege Escalation via Scope Creep","url":"https://owasp.org/www-project-mcp-top-10/2025/MCP02-2025%E2%80%93Privilege-Escalation-via-Scope-Creep","relevance":"Delegated authority can turn a narrowly scoped agent into a higher-impact actor through effective access.","id":"MCP02:2025"}],"real_world_incident":[{"title":"Invariant Labs GitHub MCP toxic agent flow","url":"https://invariantlabs.ai/blog/mcp-github-vulnerability","relevance":"Invariant demonstrated an untrusted GitHub issue coercing an MCP-connected agent to move private repository data into a public pull request. It illustrates how composed authority paths can exceed an agent's apparent role.","date":"26 May 2025"}],"control_frameworks":[{"framework":"NIST SP 800-53 Rev. 5","control_id":"AC-6","control_name":"Least Privilege","relevance":"Delegation extends the agent's effective privilege beyond its direct provisioning."},{"framework":"NIST SP 800-53 Rev. 5","control_id":"AC-5","control_name":"Separation of Duties","relevance":"Authority reachable through delegation recombines duties the direct grants kept separate."},{"framework":"SOC 2 Trust Services Criteria (2017)","control_id":"CC6.1","control_name":"Logical access security","relevance":"Effective access through delegation is logical access and must be evaluated as such."},{"framework":"ISO/IEC 27001:2022","control_id":"A.8.2","control_name":"Privileged access rights","relevance":"A privileged capability reachable only through delegation is still a privileged right of that identity."}],"risk_score":49,"risk_factors":{"base_severity":40,"blast_radius":4,"data_sensitivity":0,"exploitability":5,"untrusted_exposure":0}},{"id":"sod:access_bot:it_request_access_grant_access","rule_id":"it_request_access_grant_access","agent_id":"access_bot","check_type":"sod","check_label":"Segregation of duties","source":"deterministic","source_label":"Deterministic check","source_description":"Rule-based detection from Steward's deterministic safety floor. The deterministic tier is covered by the labeled synthetic-fleet regression and precision gate.","source_css_class":"source-deterministic","severity":"high","title":"Self-granting privilege path","business_risk":"AccessBot possesses both the request_access and grant_access capabilities, creating a self‑granting privilege path. This enables the agent to request and immediately approve access to applications without independent review, allowing unauthorized privilege escalation across the organization’s systems. The blast radius includes potential exposure of sensitive data, violation of compliance requirements, and the ability for an attacker who compromises the bot to obtain unrestricted access to any application the bot can request.","evidence":[{"entity_type":"agent","entity_id":"access_bot","detail":"holds this effective-access combination"},{"entity_type":"tool","entity_id":"grant_access","detail":"AccessBot has a direct grant of grant_access."},{"entity_type":"tool","entity_id":"request_access","detail":"AccessBot has a direct grant of request_access."}],"recommended_action":"Segregate duties by removing the direct grant of the grant_access tool from AccessBot. Implement an approval workflow that requires a separate, privileged role to approve access requests. Apply least‑privilege principles to the agent, enforce monitoring of any grant actions, and conduct periodic reviews of agent permissions.","control_mapping":"Identity governance — segregation of duties (access request versus access grant)","owasp_mcp":[],"real_world_incident":[],"control_frameworks":[{"framework":"NIST SP 800-53 Rev. 5","control_id":"AC-5","control_name":"Separation of Duties","relevance":"One agent identity holds both sides of a duty that the control requires to be separated."},{"framework":"SOC 2 Trust Services Criteria (2017)","control_id":"CC6.3","control_name":"Access modification and segregation of duties","relevance":"Toxic capability combinations in one identity undermine segregation-of-duties objectives."},{"framework":"ISO/IEC 27001:2022","control_id":"A.5.15","control_name":"Access control","relevance":"Access rules should prevent a single identity from combining conflicting capabilities."},{"framework":"ISO/IEC 27001:2022","control_id":"A.5.18","control_name":"Access rights","relevance":"Provisioned rights should be reviewed so conflicting entitlements are not co-held."},{"framework":"SOX ITGC","control_id":"SoD","control_name":"Segregation of duties over financial processes","relevance":"An agent that can initiate and approve the same transaction defeats independent review."},{"framework":"EU AI Act (Regulation (EU) 2024/1689)","control_id":"Art. 14","control_name":"Human oversight","relevance":"A toxic combination lets an AI agent complete a consequential action without an independent human checkpoint."}],"risk_score":44,"risk_factors":{"base_severity":30,"blast_radius":4,"data_sensitivity":0,"exploitability":10,"untrusted_exposure":0}},{"id":"orphan:legacy_bot:missing_owner","rule_id":"missing_owner","agent_id":"legacy_bot","check_type":"orphan","check_label":"Orphaned agent","source":"deterministic","source_label":"Deterministic check","source_description":"Rule-based detection from Steward's deterministic safety floor. The deterministic tier is covered by the labeled synthetic-fleet regression and precision gate.","source_css_class":"source-deterministic","severity":"high","title":"Ownerless agent has no accountable reviewer","business_risk":"The LegacyBot agent lacks an assigned owner, so no individual is accountable for its access rights or activity. This creates a compliance gap (missing reviewer for access certification) and increases the risk of undetected misuse or unauthorized data exposure through the agent's operations.","evidence":[{"entity_type":"agent","entity_id":"legacy_bot","detail":"owner is null in the fleet inventory"}],"recommended_action":"Assign a named owner in the fleet inventory, update the agent's governance record, and include the agent in the regular access certification process to ensure accountability.","control_mapping":"Accountability — named owner required for agent access certification","owasp_mcp":[],"real_world_incident":[],"control_frameworks":[{"framework":"NIST SP 800-53 Rev. 5","control_id":"AC-2","control_name":"Account Management","relevance":"An agent identity with no accountable owner cannot be certified, reviewed, or deprovisioned on schedule."},{"framework":"SOC 2 Trust Services Criteria (2017)","control_id":"CC6.2","control_name":"User registration and authorization","relevance":"Identities must be traceable to an accountable party throughout their lifecycle."},{"framework":"ISO/IEC 27001:2022","control_id":"A.5.16","control_name":"Identity management","relevance":"The full life cycle of an identity — including this non-human one — requires a responsible owner."},{"framework":"SOX ITGC","control_id":"Access accountability","control_name":"Accountable ownership of access","relevance":"Ownerless identities break the accountability chain ITGC access reviews depend on."}],"risk_score":30,"risk_factors":{"base_severity":30,"blast_radius":0,"data_sensitivity":0,"exploitability":0,"untrusted_exposure":0}}],"delegation_edges":[{"source":"summary_bot","target":"finance_bot"},{"source":"chief_of_staff_bot","target":"finance_bot"},{"source":"exec_briefing_bot","target":"chief_of_staff_bot"}],"certification_packet":{"schema_version":"0.1","generated_at":"2026-07-26T06:08:46.699834+00:00","packet_type":"agent_access_certification","summary":{"agents":30,"findings":10,"critical_agents":6,"pending_reviews":30},"risk_cards":[{"agent":{"id":"support_bot","name":"SupportBot","owner":"Elena Rodriguez, Customer Support","description":"Investigates customer support cases and sends resolution updates to customers.","granted_tools":["read_customer_pii","send_external_email"],"effective_access":["read_customer_pii","send_external_email"],"can_delegate_to":[],"usage_log":["read_customer_pii","send_external_email"],"usage_log_available":true},"risk_tier":"critical","top_risk_score":64,"findings":[{"id":"sod:support_bot:sensitive_data_external_egress","rule_id":"sensitive_data_external_egress","agent_id":"support_bot","check_type":"sod","check_label":"Segregation of duties","source":"deterministic","source_label":"Deterministic check","source_description":"Rule-based detection from Steward's deterministic safety floor. The deterministic tier is covered by the labeled synthetic-fleet regression and precision gate.","source_css_class":"source-deterministic","severity":"critical","title":"Critical data-exfiltration path","business_risk":"SupportBot can read customer PII and directly send external email, creating a direct path for confidential customer data to be exfiltrated outside the organization, exposing the firm to regulatory violations, financial penalties, and reputational harm.","evidence":[{"entity_type":"agent","entity_id":"support_bot","detail":"holds this effective-access combination"},{"entity_type":"tool","entity_id":"read_customer_pii","detail":"SupportBot has a direct grant of read_customer_pii."},{"entity_type":"tool","entity_id":"send_external_email","detail":"SupportBot has a direct grant of send_external_email."}],"recommended_action":"Revoke the direct read_customer_pii and send_external_email grants from SupportBot; implement least‑privilege controls, require mediated approval for external egress, and add monitoring/auditing of any PII access and outbound email activity.","control_mapping":"Data protection — least privilege and controlled external egress","owasp_mcp":[{"title":"Tool Poisoning","url":"https://owasp.org/www-project-mcp-top-10/2025/MCP03-2025%E2%80%93Tool-Poisoning","relevance":"A compromised or misleading tool can steer an agent toward unintended data handling or external actions.","id":"MCP03:2025"},{"title":"Software Supply Chain Attacks & Dependency Tampering","url":"https://owasp.org/www-project-mcp-top-10/2025/MCP04-2025%E2%80%93Software-Supply-Chain-Attacks%26Dependency-Tampering","relevance":"A compromised MCP dependency can add covert external egress to an otherwise trusted workflow.","id":"MCP04:2025"}],"real_world_incident":[{"title":"Supabase MCP stored prompt-injection scenario","url":"https://supabase.com/blog/defense-in-depth-mcp","relevance":"Supabase documented a scenario where stored instructions led an MCP-connected agent to read private database data and write it into an attacker-visible field. It illustrates this read-to-egress risk class; it is not evidence that this fleet uses Supabase.","date":"Documented 16 Sep 2025"},{"title":"Malicious postmark-mcp package backdoor (v1.0.16)","url":"https://postmarkapp.com/blog/information-regarding-malicious-postmark-mcp-package","relevance":"Postmark reported that an impersonating npm package silently BCC'd email to an external server. It is an analogous tool-poisoning and supply-chain incident, not evidence that this fleet installed the package.","date":"Postmark advisory, 25 Sep 2025"}],"control_frameworks":[{"framework":"NIST SP 800-53 Rev. 5","control_id":"AC-5","control_name":"Separation of Duties","relevance":"One agent identity holds both sides of a duty that the control requires to be separated."},{"framework":"SOC 2 Trust Services Criteria (2017)","control_id":"CC6.3","control_name":"Access modification and segregation of duties","relevance":"Toxic capability combinations in one identity undermine segregation-of-duties objectives."},{"framework":"ISO/IEC 27001:2022","control_id":"A.5.15","control_name":"Access control","relevance":"Access rules should prevent a single identity from combining conflicting capabilities."},{"framework":"ISO/IEC 27001:2022","control_id":"A.5.18","control_name":"Access rights","relevance":"Provisioned rights should be reviewed so conflicting entitlements are not co-held."},{"framework":"SOX ITGC","control_id":"SoD","control_name":"Segregation of duties over financial processes","relevance":"An agent that can initiate and approve the same transaction defeats independent review."},{"framework":"EU AI Act (Regulation (EU) 2024/1689)","control_id":"Art. 14","control_name":"Human oversight","relevance":"A toxic combination lets an AI agent complete a consequential action without an independent human checkpoint."}],"risk_score":64,"risk_factors":{"base_severity":40,"blast_radius":4,"data_sensitivity":10,"exploitability":10,"untrusted_exposure":0}}],"needed_capabilities":["reads customer contact and account information for support cases","sends email messages to external recipients"],"granted_vs_needed_gap":[],"recommended_actions":["Revoke the direct read_customer_pii and send_external_email grants from SupportBot; implement least‑privilege controls, require mediated approval for external egress, and add monitoring/auditing of any PII access and outbound email activity."],"review":{"status":"pending","note":"","updated_at":null}},{"agent":{"id":"report_bot","name":"ReportBot","owner":"Noah Williams, Analytics","description":"Reads analytics data and prepares the weekly operating report.","granted_tools":["delete_records","export_data","read_db"],"effective_access":["delete_records","export_data","read_db"],"can_delegate_to":[],"usage_log":["read_db"],"usage_log_available":true},"risk_tier":"high","top_risk_score":58,"findings":[{"id":"over_privilege:report_bot:unused_granted_tools","rule_id":"unused_granted_tools","agent_id":"report_bot","check_type":"over_privilege","check_label":"Over-privilege","source":"deterministic","source_label":"Deterministic check","source_description":"Rule-based detection from Steward's deterministic safety floor. The deterministic tier is covered by the labeled synthetic-fleet regression and precision gate.","source_css_class":"source-deterministic","severity":"high","title":"Unused standing access: 2 direct grants","business_risk":"ReportBot holds standing privileges to delete records and export data that are never exercised. If the agent were compromised or misused, an attacker could invoke these unused grants to irreversibly remove critical data or exfiltrate sensitive information, exposing the organization to data loss, regulatory non‑compliance, and reputational damage.","evidence":[{"entity_type":"agent","entity_id":"report_bot","detail":"usage log contains no invocation of these direct grants: delete_records, export_data"},{"entity_type":"tool","entity_id":"delete_records","detail":"ReportBot has a direct grant of delete_records."},{"entity_type":"tool","entity_id":"export_data","detail":"ReportBot has a direct grant of export_data."}],"recommended_action":"Revoke the unnecessary delete_records and export_data grants from ReportBot and re‑certify its access against the principle of least privilege. Implement periodic review of granted versus used permissions for all agents.","control_mapping":"Least privilege — access certification using granted versus used access","owasp_mcp":[],"real_world_incident":[],"control_frameworks":[{"framework":"NIST SP 800-53 Rev. 5","control_id":"AC-6 / AC-6(1)","control_name":"Least Privilege / Authorize Access to Security Functions","relevance":"Standing grants with no observed use exceed the minimum access the agent's function requires."},{"framework":"SOC 2 Trust Services Criteria (2017)","control_id":"CC6.1","control_name":"Logical access security","relevance":"Unused standing entitlements enlarge the logical-access attack surface without business need."},{"framework":"SOC 2 Trust Services Criteria (2017)","control_id":"CC6.3","control_name":"Access modification and segregation of duties","relevance":"Granted-but-unused access should be removed through the access-modification process."},{"framework":"ISO/IEC 27001:2022","control_id":"A.8.2","control_name":"Privileged access rights","relevance":"High-risk unused entitlements are privileged rights that should be restricted and reviewed."},{"framework":"ISO/IEC 27001:2022","control_id":"A.5.18","control_name":"Access rights","relevance":"Access rights should be adjusted when observed use does not support the grant."},{"framework":"SOX ITGC","control_id":"Least privilege","control_name":"Least-privilege provisioning","relevance":"Unused financially-relevant entitlements weaken ITGC access assertions."}],"risk_score":58,"risk_factors":{"base_severity":30,"blast_radius":8,"data_sensitivity":10,"exploitability":10,"untrusted_exposure":0}}],"needed_capabilities":["executes read-only queries on analytics database","exports analytics data to a file"],"granted_vs_needed_gap":["delete_records"],"recommended_actions":["Revoke the unnecessary delete_records and export_data grants from ReportBot and re‑certify its access against the principle of least privilege. Implement periodic review of granted versus used permissions for all agents."],"review":{"status":"pending","note":"","updated_at":null}},{"agent":{"id":"invoice_bot","name":"InvoiceBot","owner":"Maya Chen, Finance Operations","description":"Creates vendor records and routes supplier invoices for payment processing.","granted_tools":["approve_payment","create_vendor"],"effective_access":["approve_payment","create_vendor"],"can_delegate_to":[],"usage_log":["create_vendor","approve_payment"],"usage_log_available":true},"risk_tier":"critical","top_risk_score":54,"findings":[{"id":"sod:invoice_bot:finance_create_vendor_approve_payment","rule_id":"finance_create_vendor_approve_payment","agent_id":"invoice_bot","check_type":"sod","check_label":"Segregation of duties","source":"deterministic","source_label":"Deterministic check","source_description":"Rule-based detection from Steward's deterministic safety floor. The deterministic tier is covered by the labeled synthetic-fleet regression and precision gate.","source_css_class":"source-deterministic","severity":"critical","title":"Critical fraud path: create vendor and approve payment","business_risk":"InvoiceBot possesses both the create_vendor and approve_payment tool grants, giving a single automated agent the ability to add new vendors and subsequently authorize payments to those vendors. This concentration of authority creates a direct fraud pathway that could be exploited to generate fictitious vendors and approve unauthorized disbursements, potentially resulting in material financial loss and SOX compliance violations across the entire accounts‑payable function.","evidence":[{"entity_type":"agent","entity_id":"invoice_bot","detail":"holds this effective-access combination"},{"entity_type":"tool","entity_id":"approve_payment","detail":"InvoiceBot has a direct grant of approve_payment."},{"entity_type":"tool","entity_id":"create_vendor","detail":"InvoiceBot has a direct grant of create_vendor."}],"recommended_action":"Implement segregation of duties by revoking either the create_vendor or approve_payment grant from InvoiceBot, enforce dual‑approval controls for vendor creation and payment authorization, and add continuous monitoring to detect any instance where a single entity performs both actions.","control_mapping":"SOX ITGC — segregation of duties (vendor creation versus payment approval)","owasp_mcp":[],"real_world_incident":[],"control_frameworks":[{"framework":"NIST SP 800-53 Rev. 5","control_id":"AC-5","control_name":"Separation of Duties","relevance":"One agent identity holds both sides of a duty that the control requires to be separated."},{"framework":"SOC 2 Trust Services Criteria (2017)","control_id":"CC6.3","control_name":"Access modification and segregation of duties","relevance":"Toxic capability combinations in one identity undermine segregation-of-duties objectives."},{"framework":"ISO/IEC 27001:2022","control_id":"A.5.15","control_name":"Access control","relevance":"Access rules should prevent a single identity from combining conflicting capabilities."},{"framework":"ISO/IEC 27001:2022","control_id":"A.5.18","control_name":"Access rights","relevance":"Provisioned rights should be reviewed so conflicting entitlements are not co-held."},{"framework":"SOX ITGC","control_id":"SoD","control_name":"Segregation of duties over financial processes","relevance":"An agent that can initiate and approve the same transaction defeats independent review."},{"framework":"EU AI Act (Regulation (EU) 2024/1689)","control_id":"Art. 14","control_name":"Human oversight","relevance":"A toxic combination lets an AI agent complete a consequential action without an independent human checkpoint."}],"risk_score":54,"risk_factors":{"base_severity":40,"blast_radius":4,"data_sensitivity":0,"exploitability":10,"untrusted_exposure":0}}],"needed_capabilities":["adds supplier or payee to vendor master","authorizes queued payments for release"],"granted_vs_needed_gap":[],"recommended_actions":["Implement segregation of duties by revoking either the create_vendor or approve_payment grant from InvoiceBot, enforce dual‑approval controls for vendor creation and payment authorization, and add continuous monitoring to detect any instance where a single entity performs both actions."],"review":{"status":"pending","note":"","updated_at":null}},{"agent":{"id":"payroll_bot","name":"PayrollBot","owner":"Jordan Ellis, People Operations","description":"Maintains employee records and prepares the biweekly payroll run.","granted_tools":["add_employee","run_payroll"],"effective_access":["add_employee","run_payroll"],"can_delegate_to":[],"usage_log":["add_employee","run_payroll"],"usage_log_available":true},"risk_tier":"critical","top_risk_score":54,"findings":[{"id":"sod:payroll_bot:hr_add_employee_run_payroll","rule_id":"hr_add_employee_run_payroll","agent_id":"payroll_bot","check_type":"sod","check_label":"Segregation of duties","source":"deterministic","source_label":"Deterministic check","source_description":"Rule-based detection from Steward's deterministic safety floor. The deterministic tier is covered by the labeled synthetic-fleet regression and precision gate.","source_css_class":"source-deterministic","severity":"critical","title":"Critical ghost-employee fraud path","business_risk":"PayrollBot holds direct authority to both add_employee (employee creation) and run_payroll (payroll execution). This conflation of employee setup and payroll processing creates a critical segregation‑of‑duties violation, enabling a malicious or compromised bot to create ghost employees and issue unauthorized payroll payments, potentially resulting in financial loss, regulatory non‑compliance, and reputational harm across the entire payroll function.","evidence":[{"entity_type":"agent","entity_id":"payroll_bot","detail":"holds this effective-access combination"},{"entity_type":"tool","entity_id":"add_employee","detail":"PayrollBot has a direct grant of add_employee."},{"entity_type":"tool","entity_id":"run_payroll","detail":"PayrollBot has a direct grant of run_payroll."}],"recommended_action":"Re‑engineer the permission model to enforce segregation of duties: remove the direct add_employee grant from PayrollBot, require an independent approval workflow for employee creation, and limit payroll execution to a separate, controlled role. Implement least‑privilege access, periodic access reviews, and monitoring of employee‑creation and payroll‑run activities.","control_mapping":"SOX ITGC — segregation of duties (employee setup versus payroll execution)","owasp_mcp":[],"real_world_incident":[],"control_frameworks":[{"framework":"NIST SP 800-53 Rev. 5","control_id":"AC-5","control_name":"Separation of Duties","relevance":"One agent identity holds both sides of a duty that the control requires to be separated."},{"framework":"SOC 2 Trust Services Criteria (2017)","control_id":"CC6.3","control_name":"Access modification and segregation of duties","relevance":"Toxic capability combinations in one identity undermine segregation-of-duties objectives."},{"framework":"ISO/IEC 27001:2022","control_id":"A.5.15","control_name":"Access control","relevance":"Access rules should prevent a single identity from combining conflicting capabilities."},{"framework":"ISO/IEC 27001:2022","control_id":"A.5.18","control_name":"Access rights","relevance":"Provisioned rights should be reviewed so conflicting entitlements are not co-held."},{"framework":"SOX ITGC","control_id":"SoD","control_name":"Segregation of duties over financial processes","relevance":"An agent that can initiate and approve the same transaction defeats independent review."},{"framework":"EU AI Act (Regulation (EU) 2024/1689)","control_id":"Art. 14","control_name":"Human oversight","relevance":"A toxic combination lets an AI agent complete a consequential action without an independent human checkpoint."}],"risk_score":54,"risk_factors":{"base_severity":40,"blast_radius":4,"data_sensitivity":0,"exploitability":10,"untrusted_exposure":0}}],"needed_capabilities":["creates employee records in the HR system","starts payroll calculation and payment run for employees"],"granted_vs_needed_gap":[],"recommended_actions":["Re‑engineer the permission model to enforce segregation of duties: remove the direct add_employee grant from PayrollBot, require an independent approval workflow for employee creation, and limit payroll execution to a separate, controlled role. Implement least‑privilege access, periodic access reviews, and monitoring of employee‑creation and payroll‑run activities."],"review":{"status":"pending","note":"","updated_at":null}},{"agent":{"id":"sales_bot","name":"SalesBot","owner":"Talia Brooks, Revenue Operations","description":"Looks up CRM account context and sends personalized sales outreach to prospective customers.","granted_tools":["read_crm","send_external_email"],"effective_access":["read_crm","send_external_email"],"can_delegate_to":[],"usage_log":["read_crm","send_external_email"],"usage_log_available":true},"risk_tier":"high","top_risk_score":54,"findings":[{"id":"sod:sales_bot:llm_toxic_read_crm_send_external_email","rule_id":"llm_toxic_read_crm_send_external_email","agent_id":"sales_bot","check_type":"sod","check_label":"Segregation of duties","source":"llm_generalized","source_label":"LLM-generalized","source_description":"The configured model proposed this additional combination; Steward verified its graph citations before showing it. It is evaluated separately from the deterministic golden-set gate.","source_css_class":"source-llm-generalized","severity":"high","title":"AI-generalized toxic capability combination: Read CRM account context + Send email outside the company","business_risk":"The SalesBot agent can both read CRM account context and send email outside the company, creating a direct path to expose customer information to external recipients. This combination can lead to unauthorized data disclosure, regulatory non‑compliance, reputational damage, and potential financial loss.","evidence":[{"entity_type":"agent","entity_id":"sales_bot","detail":"holds the cited effective-access combination."},{"entity_type":"tool","entity_id":"read_crm","detail":"SalesBot has a direct grant of read_crm."},{"entity_type":"tool","entity_id":"send_external_email","detail":"SalesBot has a direct grant of send_external_email."}],"recommended_action":"Separate the read_crm and send_external_email permissions, enforce a dual‑approval workflow for any external email that includes CRM data, and implement continuous monitoring and audit of combined usage.","control_mapping":"Identity governance — Model-identified segregation-of-duties candidate","owasp_mcp":[{"title":"Tool Poisoning","url":"https://owasp.org/www-project-mcp-top-10/2025/MCP03-2025%E2%80%93Tool-Poisoning","relevance":"A compromised or misleading tool can steer an agent toward unintended data handling or external actions.","id":"MCP03:2025"},{"title":"Software Supply Chain Attacks & Dependency Tampering","url":"https://owasp.org/www-project-mcp-top-10/2025/MCP04-2025%E2%80%93Software-Supply-Chain-Attacks%26Dependency-Tampering","relevance":"A compromised MCP dependency can add covert external egress to an otherwise trusted workflow.","id":"MCP04:2025"}],"real_world_incident":[{"title":"Supabase MCP stored prompt-injection scenario","url":"https://supabase.com/blog/defense-in-depth-mcp","relevance":"Supabase documented a scenario where stored instructions led an MCP-connected agent to read private database data and write it into an attacker-visible field. It illustrates this read-to-egress risk class; it is not evidence that this fleet uses Supabase.","date":"Documented 16 Sep 2025"},{"title":"Malicious postmark-mcp package backdoor (v1.0.16)","url":"https://postmarkapp.com/blog/information-regarding-malicious-postmark-mcp-package","relevance":"Postmark reported that an impersonating npm package silently BCC'd email to an external server. It is an analogous tool-poisoning and supply-chain incident, not evidence that this fleet installed the package.","date":"Postmark advisory, 25 Sep 2025"}],"control_frameworks":[{"framework":"NIST SP 800-53 Rev. 5","control_id":"AC-5","control_name":"Separation of Duties","relevance":"One agent identity holds both sides of a duty that the control requires to be separated."},{"framework":"SOC 2 Trust Services Criteria (2017)","control_id":"CC6.3","control_name":"Access modification and segregation of duties","relevance":"Toxic capability combinations in one identity undermine segregation-of-duties objectives."},{"framework":"ISO/IEC 27001:2022","control_id":"A.5.15","control_name":"Access control","relevance":"Access rules should prevent a single identity from combining conflicting capabilities."},{"framework":"ISO/IEC 27001:2022","control_id":"A.5.18","control_name":"Access rights","relevance":"Provisioned rights should be reviewed so conflicting entitlements are not co-held."},{"framework":"SOX ITGC","control_id":"SoD","control_name":"Segregation of duties over financial processes","relevance":"An agent that can initiate and approve the same transaction defeats independent review."},{"framework":"EU AI Act (Regulation (EU) 2024/1689)","control_id":"Art. 14","control_name":"Human oversight","relevance":"A toxic combination lets an AI agent complete a consequential action without an independent human checkpoint."}],"risk_score":54,"risk_factors":{"base_severity":30,"blast_radius":4,"data_sensitivity":10,"exploitability":10,"untrusted_exposure":0}}],"needed_capabilities":["reads sales account notes and opportunity context from CRM","sends email messages to external recipients"],"granted_vs_needed_gap":[],"recommended_actions":["Separate the read_crm and send_external_email permissions, enforce a dual‑approval workflow for any external email that includes CRM data, and implement continuous monitoring and audit of combined usage."],"review":{"status":"pending","note":"","updated_at":null}},{"agent":{"id":"chief_of_staff_bot","name":"ChiefOfStaffBot","owner":"Avery Thompson, Executive Operations","description":"Prepares leadership briefings and can hand finance approvals to the finance agent.","granted_tools":["read_calendar","read_knowledge_base"],"effective_access":["approve_payment","read_calendar","read_knowledge_base"],"can_delegate_to":["finance_bot"],"usage_log":["read_calendar","read_knowledge_base"],"usage_log_available":true},"risk_tier":"critical","top_risk_score":49,"findings":[{"id":"escalation:chief_of_staff_bot:delegated_high_risk_payment_approval","rule_id":"delegated_high_risk_payment_approval","agent_id":"chief_of_staff_bot","check_type":"escalation","check_label":"Delegation escalation","source":"deterministic","source_label":"Deterministic check","source_description":"Rule-based detection from Steward's deterministic safety floor. The deterministic tier is covered by the labeled synthetic-fleet regression and precision gate.","source_css_class":"source-deterministic","severity":"critical","title":"Delegated payment-approval blast radius","business_risk":"Through the delegation edge, ChiefOfStaffBot can reach the finance_bot, which directly holds the approve_payment tool. Consequently, any user or process that can invoke ChiefOfStaffBot inherits the ability to trigger payment approvals via finance_bot. The practical blast radius therefore extends to all payment transactions that finance_bot is authorized to approve, creating a critical risk of unauthorized or fraudulent payments if the delegation is not tightly controlled.","evidence":[{"entity_type":"agent","entity_id":"chief_of_staff_bot","detail":"reaches approve_payment only through delegation to finance_bot"},{"entity_type":"delegation_edge","entity_id":"chief_of_staff_bot->finance_bot","detail":"chief_of_staff_bot can delegate to finance_bot."},{"entity_type":"agent","entity_id":"finance_bot","detail":"finance_bot is the direct grant holder reached through chief_of_staff_bot -> finance_bot."},{"entity_type":"tool","entity_id":"approve_payment","detail":"ChiefOfStaffBot effectively reaches approve_payment through chief_of_staff_bot -> finance_bot."}],"recommended_action":"Conduct an immediate access review of the delegation relationship between ChiefOfStaffBot and finance_bot. Restrict delegation to only verified, least‑privilege identities, enforce multi‑factor approval for payment actions, and implement monitoring/auditing of all approve_payment invocations originating from ChiefOfStaffBot.","control_mapping":"Identity governance — effective access review and least privilege","owasp_mcp":[],"real_world_incident":[],"control_frameworks":[{"framework":"NIST SP 800-53 Rev. 5","control_id":"AC-6","control_name":"Least Privilege","relevance":"Delegation extends the agent's effective privilege beyond its direct provisioning."},{"framework":"NIST SP 800-53 Rev. 5","control_id":"AC-5","control_name":"Separation of Duties","relevance":"Authority reachable through delegation recombines duties the direct grants kept separate."},{"framework":"SOC 2 Trust Services Criteria (2017)","control_id":"CC6.1","control_name":"Logical access security","relevance":"Effective access through delegation is logical access and must be evaluated as such."},{"framework":"ISO/IEC 27001:2022","control_id":"A.8.2","control_name":"Privileged access rights","relevance":"A privileged capability reachable only through delegation is still a privileged right of that identity."}],"risk_score":49,"risk_factors":{"base_severity":40,"blast_radius":4,"data_sensitivity":0,"exploitability":5,"untrusted_exposure":0}}],"needed_capabilities":["creates concise summary of supplied document","sends reminder messages through the internal messaging system to employees"],"granted_vs_needed_gap":["approve_payment","read_calendar","read_knowledge_base"],"recommended_actions":["Conduct an immediate access review of the delegation relationship between ChiefOfStaffBot and finance_bot. Restrict delegation to only verified, least‑privilege identities, enforce multi‑factor approval for payment actions, and implement monitoring/auditing of all approve_payment invocations originating from ChiefOfStaffBot."],"review":{"status":"pending","note":"","updated_at":null}},{"agent":{"id":"exec_briefing_bot","name":"ExecBriefingBot","owner":"Avery Thompson, Executive Operations","description":"Compiles executive reading material and routes requests through the chief of staff agent.","granted_tools":["read_knowledge_base"],"effective_access":["approve_payment","read_calendar","read_knowledge_base"],"can_delegate_to":["chief_of_staff_bot"],"usage_log":["read_knowledge_base"],"usage_log_available":true},"risk_tier":"critical","top_risk_score":49,"findings":[{"id":"escalation:exec_briefing_bot:delegated_high_risk_payment_approval","rule_id":"delegated_high_risk_payment_approval","agent_id":"exec_briefing_bot","check_type":"escalation","check_label":"Delegation escalation","source":"deterministic","source_label":"Deterministic check","source_description":"Rule-based detection from Steward's deterministic safety floor. The deterministic tier is covered by the labeled synthetic-fleet regression and precision gate.","source_css_class":"source-deterministic","severity":"critical","title":"Delegated payment-approval blast radius","business_risk":"Compromise of ExecBriefingBot grants indirect access to the approve_payment tool via the delegation chain (ExecBriefingBot → chief_of_staff_bot → finance_bot). An attacker who gains control of ExecBriefingBot could approve payments without direct authorization, exposing the organization to unauthorized disbursements and potential financial loss.","evidence":[{"entity_type":"agent","entity_id":"exec_briefing_bot","detail":"reaches approve_payment only through delegation to finance_bot"},{"entity_type":"delegation_edge","entity_id":"exec_briefing_bot->chief_of_staff_bot","detail":"exec_briefing_bot can delegate to chief_of_staff_bot."},{"entity_type":"delegation_edge","entity_id":"chief_of_staff_bot->finance_bot","detail":"chief_of_staff_bot can delegate to finance_bot."},{"entity_type":"agent","entity_id":"finance_bot","detail":"finance_bot is the direct grant holder reached through exec_briefing_bot -> chief_of_staff_bot -> finance_bot."},{"entity_type":"tool","entity_id":"approve_payment","detail":"ExecBriefingBot effectively reaches approve_payment through exec_briefing_bot -> chief_of_staff_bot -> finance_bot."}],"recommended_action":"Restrict delegation paths so that ExecBriefingBot cannot reach payment‑approval capabilities, enforce least‑privilege principles on delegation edges, conduct an immediate access review of all delegated relationships, and implement monitoring/alerting for any use of approve_payment originating from indirect agents.","control_mapping":"Identity governance — effective access review and least privilege","owasp_mcp":[],"real_world_incident":[],"control_frameworks":[{"framework":"NIST SP 800-53 Rev. 5","control_id":"AC-6","control_name":"Least Privilege","relevance":"Delegation extends the agent's effective privilege beyond its direct provisioning."},{"framework":"NIST SP 800-53 Rev. 5","control_id":"AC-5","control_name":"Separation of Duties","relevance":"Authority reachable through delegation recombines duties the direct grants kept separate."},{"framework":"SOC 2 Trust Services Criteria (2017)","control_id":"CC6.1","control_name":"Logical access security","relevance":"Effective access through delegation is logical access and must be evaluated as such."},{"framework":"ISO/IEC 27001:2022","control_id":"A.8.2","control_name":"Privileged access rights","relevance":"A privileged capability reachable only through delegation is still a privileged right of that identity."}],"risk_score":49,"risk_factors":{"base_severity":40,"blast_radius":4,"data_sensitivity":0,"exploitability":5,"untrusted_exposure":0}}],"needed_capabilities":["creates concise summary of supplied document","searches and reads approved internal knowledge articles"],"granted_vs_needed_gap":["approve_payment","read_calendar"],"recommended_actions":["Restrict delegation paths so that ExecBriefingBot cannot reach payment‑approval capabilities, enforce least‑privilege principles on delegation edges, conduct an immediate access review of all delegated relationships, and implement monitoring/alerting for any use of approve_payment originating from indirect agents."],"review":{"status":"pending","note":"","updated_at":null}},{"agent":{"id":"summary_bot","name":"SummaryBot","owner":"Avery Thompson, Executive Operations","description":"Reads approved internal knowledge and produces concise leadership summaries.","granted_tools":["read_knowledge_base"],"effective_access":["approve_payment","read_knowledge_base"],"can_delegate_to":["finance_bot"],"usage_log":["read_knowledge_base"],"usage_log_available":true},"risk_tier":"critical","top_risk_score":49,"findings":[{"id":"escalation:summary_bot:delegated_high_risk_payment_approval","rule_id":"delegated_high_risk_payment_approval","agent_id":"summary_bot","check_type":"escalation","check_label":"Delegation escalation","source":"deterministic","source_label":"Deterministic check","source_description":"Rule-based detection from Steward's deterministic safety floor. The deterministic tier is covered by the labeled synthetic-fleet regression and precision gate.","source_css_class":"source-deterministic","severity":"critical","title":"Delegated payment-approval blast radius","business_risk":"This agent does not hold payment approval directly, but it can reach an agent that does through delegation. Its effective access therefore includes authority to authorize disbursements, creating a confused-deputy path.","evidence":[{"entity_type":"agent","entity_id":"summary_bot","detail":"reaches approve_payment only through delegation to finance_bot"},{"entity_type":"delegation_edge","entity_id":"summary_bot->finance_bot","detail":"summary_bot can delegate to finance_bot."},{"entity_type":"agent","entity_id":"finance_bot","detail":"finance_bot is the direct grant holder reached through summary_bot -> finance_bot."},{"entity_type":"tool","entity_id":"approve_payment","detail":"SummaryBot effectively reaches approve_payment through summary_bot -> finance_bot."}],"recommended_action":"Remove or constrain the delegation link to the payment-approving agent. If delegation is necessary, expose a narrowly scoped workflow action rather than the delegate's general approval authority.","control_mapping":"Identity governance — effective access review and least privilege","owasp_mcp":[{"title":"Privilege Escalation via Scope Creep","url":"https://owasp.org/www-project-mcp-top-10/2025/MCP02-2025%E2%80%93Privilege-Escalation-via-Scope-Creep","relevance":"Delegated authority can turn a narrowly scoped agent into a higher-impact actor through effective access.","id":"MCP02:2025"}],"real_world_incident":[{"title":"Invariant Labs GitHub MCP toxic agent flow","url":"https://invariantlabs.ai/blog/mcp-github-vulnerability","relevance":"Invariant demonstrated an untrusted GitHub issue coercing an MCP-connected agent to move private repository data into a public pull request. It illustrates how composed authority paths can exceed an agent's apparent role.","date":"26 May 2025"}],"control_frameworks":[{"framework":"NIST SP 800-53 Rev. 5","control_id":"AC-6","control_name":"Least Privilege","relevance":"Delegation extends the agent's effective privilege beyond its direct provisioning."},{"framework":"NIST SP 800-53 Rev. 5","control_id":"AC-5","control_name":"Separation of Duties","relevance":"Authority reachable through delegation recombines duties the direct grants kept separate."},{"framework":"SOC 2 Trust Services Criteria (2017)","control_id":"CC6.1","control_name":"Logical access security","relevance":"Effective access through delegation is logical access and must be evaluated as such."},{"framework":"ISO/IEC 27001:2022","control_id":"A.8.2","control_name":"Privileged access rights","relevance":"A privileged capability reachable only through delegation is still a privileged right of that identity."}],"risk_score":49,"risk_factors":{"base_severity":40,"blast_radius":4,"data_sensitivity":0,"exploitability":5,"untrusted_exposure":0}}],"needed_capabilities":["creates concise summary of supplied document","searches and reads approved internal knowledge articles"],"granted_vs_needed_gap":["approve_payment"],"recommended_actions":["Remove or constrain the delegation link to the payment-approving agent. If delegation is necessary, expose a narrowly scoped workflow action rather than the delegate's general approval authority."],"review":{"status":"pending","note":"","updated_at":null}},{"agent":{"id":"access_bot","name":"AccessBot","owner":"Priya Nair, IT Identity","description":"Helps employees request the application access they need for their work.","granted_tools":["grant_access","request_access"],"effective_access":["grant_access","request_access"],"can_delegate_to":[],"usage_log":["request_access","grant_access"],"usage_log_available":true},"risk_tier":"high","top_risk_score":44,"findings":[{"id":"sod:access_bot:it_request_access_grant_access","rule_id":"it_request_access_grant_access","agent_id":"access_bot","check_type":"sod","check_label":"Segregation of duties","source":"deterministic","source_label":"Deterministic check","source_description":"Rule-based detection from Steward's deterministic safety floor. The deterministic tier is covered by the labeled synthetic-fleet regression and precision gate.","source_css_class":"source-deterministic","severity":"high","title":"Self-granting privilege path","business_risk":"AccessBot possesses both the request_access and grant_access capabilities, creating a self‑granting privilege path. This enables the agent to request and immediately approve access to applications without independent review, allowing unauthorized privilege escalation across the organization’s systems. The blast radius includes potential exposure of sensitive data, violation of compliance requirements, and the ability for an attacker who compromises the bot to obtain unrestricted access to any application the bot can request.","evidence":[{"entity_type":"agent","entity_id":"access_bot","detail":"holds this effective-access combination"},{"entity_type":"tool","entity_id":"grant_access","detail":"AccessBot has a direct grant of grant_access."},{"entity_type":"tool","entity_id":"request_access","detail":"AccessBot has a direct grant of request_access."}],"recommended_action":"Segregate duties by removing the direct grant of the grant_access tool from AccessBot. Implement an approval workflow that requires a separate, privileged role to approve access requests. Apply least‑privilege principles to the agent, enforce monitoring of any grant actions, and conduct periodic reviews of agent permissions.","control_mapping":"Identity governance — segregation of duties (access request versus access grant)","owasp_mcp":[],"real_world_incident":[],"control_frameworks":[{"framework":"NIST SP 800-53 Rev. 5","control_id":"AC-5","control_name":"Separation of Duties","relevance":"One agent identity holds both sides of a duty that the control requires to be separated."},{"framework":"SOC 2 Trust Services Criteria (2017)","control_id":"CC6.3","control_name":"Access modification and segregation of duties","relevance":"Toxic capability combinations in one identity undermine segregation-of-duties objectives."},{"framework":"ISO/IEC 27001:2022","control_id":"A.5.15","control_name":"Access control","relevance":"Access rules should prevent a single identity from combining conflicting capabilities."},{"framework":"ISO/IEC 27001:2022","control_id":"A.5.18","control_name":"Access rights","relevance":"Provisioned rights should be reviewed so conflicting entitlements are not co-held."},{"framework":"SOX ITGC","control_id":"SoD","control_name":"Segregation of duties over financial processes","relevance":"An agent that can initiate and approve the same transaction defeats independent review."},{"framework":"EU AI Act (Regulation (EU) 2024/1689)","control_id":"Art. 14","control_name":"Human oversight","relevance":"A toxic combination lets an AI agent complete a consequential action without an independent human checkpoint."}],"risk_score":44,"risk_factors":{"base_severity":30,"blast_radius":4,"data_sensitivity":0,"exploitability":10,"untrusted_exposure":0}}],"needed_capabilities":["submits an application access request for an employee"],"granted_vs_needed_gap":["grant_access"],"recommended_actions":["Segregate duties by removing the direct grant of the grant_access tool from AccessBot. Implement an approval workflow that requires a separate, privileged role to approve access requests. Apply least‑privilege principles to the agent, enforce monitoring of any grant actions, and conduct periodic reviews of agent permissions."],"review":{"status":"pending","note":"","updated_at":null}},{"agent":{"id":"legacy_bot","name":"LegacyBot","owner":null,"description":"Answers questions from the retired product archive.","granted_tools":["read_archive"],"effective_access":["read_archive"],"can_delegate_to":[],"usage_log":["read_archive"],"usage_log_available":true},"risk_tier":"high","top_risk_score":30,"findings":[{"id":"orphan:legacy_bot:missing_owner","rule_id":"missing_owner","agent_id":"legacy_bot","check_type":"orphan","check_label":"Orphaned agent","source":"deterministic","source_label":"Deterministic check","source_description":"Rule-based detection from Steward's deterministic safety floor. The deterministic tier is covered by the labeled synthetic-fleet regression and precision gate.","source_css_class":"source-deterministic","severity":"high","title":"Ownerless agent has no accountable reviewer","business_risk":"The LegacyBot agent lacks an assigned owner, so no individual is accountable for its access rights or activity. This creates a compliance gap (missing reviewer for access certification) and increases the risk of undetected misuse or unauthorized data exposure through the agent's operations.","evidence":[{"entity_type":"agent","entity_id":"legacy_bot","detail":"owner is null in the fleet inventory"}],"recommended_action":"Assign a named owner in the fleet inventory, update the agent's governance record, and include the agent in the regular access certification process to ensure accountability.","control_mapping":"Accountability — named owner required for agent access certification","owasp_mcp":[],"real_world_incident":[],"control_frameworks":[{"framework":"NIST SP 800-53 Rev. 5","control_id":"AC-2","control_name":"Account Management","relevance":"An agent identity with no accountable owner cannot be certified, reviewed, or deprovisioned on schedule."},{"framework":"SOC 2 Trust Services Criteria (2017)","control_id":"CC6.2","control_name":"User registration and authorization","relevance":"Identities must be traceable to an accountable party throughout their lifecycle."},{"framework":"ISO/IEC 27001:2022","control_id":"A.5.16","control_name":"Identity management","relevance":"The full life cycle of an identity — including this non-human one — requires a responsible owner."},{"framework":"SOX ITGC","control_id":"Access accountability","control_name":"Accountable ownership of access","relevance":"Ownerless identities break the accountability chain ITGC access reviews depend on."}],"risk_score":30,"risk_factors":{"base_severity":30,"blast_radius":0,"data_sensitivity":0,"exploitability":0,"untrusted_exposure":0}}],"needed_capabilities":["retrieves documents from retired product archive"],"granted_vs_needed_gap":[],"recommended_actions":["Assign a named owner in the fleet inventory, update the agent's governance record, and include the agent in the regular access certification process to ensure accountability."],"review":{"status":"pending","note":"","updated_at":null}},{"agent":{"id":"bi_bot","name":"BusinessIntelligenceBot","owner":"Noah Williams, Analytics","description":"Runs read-only analytics queries and prepares metrics for the weekly review.","granted_tools":["read_analytics","read_db"],"effective_access":["read_analytics","read_db"],"can_delegate_to":[],"usage_log":["read_analytics","read_db"],"usage_log_available":true},"risk_tier":"clear","top_risk_score":0,"findings":[],"needed_capabilities":["executes read-only queries on analytics database","exports analytics data to a file"],"granted_vs_needed_gap":["read_analytics"],"recommended_actions":[],"review":{"status":"pending","note":"","updated_at":null}},{"agent":{"id":"compliance_bot","name":"ComplianceBot","owner":"Grace Kim, Risk and Compliance","description":"Reads policy material and opens audit follow-up tickets for reviewers.","granted_tools":["create_audit_ticket","read_policy_library"],"effective_access":["create_audit_ticket","read_policy_library"],"can_delegate_to":[],"usage_log":["read_policy_library","create_audit_ticket"],"usage_log_available":true},"risk_tier":"clear","top_risk_score":0,"findings":[],"needed_capabilities":["opens audit follow‑up tickets for reviewers","reads published company policy documents"],"granted_vs_needed_gap":[],"recommended_actions":[],"review":{"status":"pending","note":"","updated_at":null}},{"agent":{"id":"contract_bot","name":"ContractBot","owner":"Riley Foster, Legal Operations","description":"Finds prior agreements and drafts contract language for legal review.","granted_tools":["draft_contract","read_contract_repository"],"effective_access":["draft_contract","read_contract_repository"],"can_delegate_to":[],"usage_log":["read_contract_repository","draft_contract"],"usage_log_available":true},"risk_tier":"clear","top_risk_score":0,"findings":[],"needed_capabilities":["drafts contract language for legal review","retrieves approved contract templates and prior agreements from contract repository"],"granted_vs_needed_gap":[],"recommended_actions":[],"review":{"status":"pending","note":"","updated_at":null}},{"agent":{"id":"customer_success_bot","name":"CustomerSuccessBot","owner":"Nina Alvarez, Customer Success","description":"Looks up approved playbooks and posts internal account reminders to the success team.","granted_tools":["read_knowledge_base","send_internal_message"],"effective_access":["read_knowledge_base","send_internal_message"],"can_delegate_to":[],"usage_log":["read_knowledge_base","send_internal_message"],"usage_log_available":true},"risk_tier":"clear","top_risk_score":0,"findings":[],"needed_capabilities":["searches and reads approved internal knowledge articles","sends reminder messages through the internal messaging system to employees"],"granted_vs_needed_gap":[],"recommended_actions":[],"review":{"status":"pending","note":"","updated_at":null}},{"agent":{"id":"data_quality_bot","name":"DataQualityBot","owner":"Noah Williams, Analytics","description":"Reviews analytics extracts and validates data-quality rules.","granted_tools":["read_analytics","validate_data"],"effective_access":["read_analytics","validate_data"],"can_delegate_to":[],"usage_log":["read_analytics","validate_data"],"usage_log_available":true},"risk_tier":"clear","top_risk_score":0,"findings":[],"needed_capabilities":["checks analytics extract against data quality rules","retrieves approved analytics extract for review"],"granted_vs_needed_gap":[],"recommended_actions":[],"review":{"status":"pending","note":"","updated_at":null}},{"agent":{"id":"engineering_bot","name":"EngineeringBot","owner":"Ishan Kapoor, Engineering Productivity","description":"Reads source repositories and opens engineering work items for maintainers.","granted_tools":["create_issue","read_source_repository"],"effective_access":["create_issue","read_source_repository"],"can_delegate_to":[],"usage_log":["read_source_repository","create_issue"],"usage_log_available":true},"risk_tier":"clear","top_risk_score":0,"findings":[],"needed_capabilities":["opens engineering work items for maintainers","reads source code files and issue context from the engineering repository"],"granted_vs_needed_gap":[],"recommended_actions":[],"review":{"status":"pending","note":"","updated_at":null}},{"agent":{"id":"facilities_bot","name":"FacilitiesBot","owner":"Morgan Lee, Workplace Services","description":"Creates travel requests and checks workplace policy for on-site visits.","granted_tools":["create_travel_request","read_policy_library"],"effective_access":["create_travel_request","read_policy_library"],"can_delegate_to":[],"usage_log":["create_travel_request","read_policy_library"],"usage_log_available":true},"risk_tier":"clear","top_risk_score":0,"findings":[],"needed_capabilities":["creates travel request for manager review","reads published company policy documents"],"granted_vs_needed_gap":[],"recommended_actions":[],"review":{"status":"pending","note":"","updated_at":null}},{"agent":{"id":"finance_bot","name":"FinanceBot","owner":"Maya Chen, Finance Operations","description":"Approves payments that have completed the finance review workflow.","granted_tools":["approve_payment"],"effective_access":["approve_payment"],"can_delegate_to":[],"usage_log":["approve_payment"],"usage_log_available":true},"risk_tier":"clear","top_risk_score":0,"findings":[],"needed_capabilities":["authorizes queued payments for release"],"granted_vs_needed_gap":[],"recommended_actions":[],"review":{"status":"pending","note":"","updated_at":null}},{"agent":{"id":"inventory_bot","name":"InventoryBot","owner":"Diego Morales, Supply Chain","description":"Checks current inventory and updates stock counts after warehouse reconciliation.","granted_tools":["read_inventory","update_inventory"],"effective_access":["read_inventory","update_inventory"],"can_delegate_to":[],"usage_log":["read_inventory","update_inventory"],"usage_log_available":true},"risk_tier":"clear","top_risk_score":0,"findings":[],"needed_capabilities":["reads current warehouse inventory and stock counts","updates warehouse stock count records"],"granted_vs_needed_gap":[],"recommended_actions":[],"review":{"status":"pending","note":"","updated_at":null}},{"agent":{"id":"knowledge_bot","name":"KnowledgeBot","owner":"Samir Patel, Internal Enablement","description":"Finds approved answers in the internal knowledge base for employees.","granted_tools":["read_knowledge_base"],"effective_access":["read_knowledge_base"],"can_delegate_to":[],"usage_log":["read_knowledge_base"],"usage_log_available":true},"risk_tier":"clear","top_risk_score":0,"findings":[],"needed_capabilities":["searches and reads approved internal knowledge articles"],"granted_vs_needed_gap":[],"recommended_actions":[],"review":{"status":"pending","note":"","updated_at":null}},{"agent":{"id":"marketing_bot","name":"MarketingBot","owner":"Owen Bennett, Marketing","description":"Researches public market sources and summarizes findings for campaign planning.","granted_tools":["read_knowledge_base","summarize_document","web_search"],"effective_access":["read_knowledge_base","summarize_document","web_search"],"can_delegate_to":[],"usage_log":["web_search","summarize_document","read_knowledge_base"],"usage_log_available":true},"risk_tier":"clear","top_risk_score":0,"findings":[],"needed_capabilities":["creates concise summary of supplied document","searches public web pages for information"],"granted_vs_needed_gap":["read_knowledge_base"],"recommended_actions":[],"review":{"status":"pending","note":"","updated_at":null}},{"agent":{"id":"monitoring_bot","name":"MonitoringBot","owner":"Harper Davis, Site Reliability","description":"Reads service metrics and opens incident tickets when a threshold is breached.","granted_tools":["create_incident_ticket","read_system_metrics"],"effective_access":["create_incident_ticket","read_system_metrics"],"can_delegate_to":[],"usage_log":["read_system_metrics","create_incident_ticket"],"usage_log_available":true},"risk_tier":"clear","top_risk_score":0,"findings":[],"needed_capabilities":["opens incident tickets for the on‑call team","reads current service health and performance metrics from the monitoring system"],"granted_vs_needed_gap":[],"recommended_actions":[],"review":{"status":"pending","note":"","updated_at":null}},{"agent":{"id":"onboarding_bot","name":"OnboardingBot","owner":"Jordan Ellis, People Operations","description":"Creates onboarding checklists and sends internal reminders to new hires.","granted_tools":["create_onboarding_checklist","send_internal_message"],"effective_access":["create_onboarding_checklist","send_internal_message"],"can_delegate_to":[],"usage_log":["create_onboarding_checklist","send_internal_message"],"usage_log_available":true},"risk_tier":"clear","top_risk_score":0,"findings":[],"needed_capabilities":["creates onboarding checklist for new hire","sends reminder messages through the internal messaging system to employees"],"granted_vs_needed_gap":[],"recommended_actions":[],"review":{"status":"pending","note":"","updated_at":null}},{"agent":{"id":"procurement_bot","name":"ProcurementBot","owner":"Dana Vasquez, Procurement","description":"Retrieves prior agreements and opens audit follow-ups for the procurement team.","granted_tools":["create_audit_ticket","read_contract_repository"],"effective_access":["create_audit_ticket","read_contract_repository"],"can_delegate_to":[],"usage_log":["read_contract_repository","create_audit_ticket"],"usage_log_available":true},"risk_tier":"clear","top_risk_score":0,"findings":[],"needed_capabilities":["opens audit follow‑up tickets for reviewers","retrieves approved contract templates and prior agreements from contract repository"],"granted_vs_needed_gap":[],"recommended_actions":[],"review":{"status":"pending","note":"","updated_at":null}},{"agent":{"id":"recruiting_bot","name":"RecruitingBot","owner":"Jordan Ellis, People Operations","description":"Checks interviewer availability and creates internal interview holds.","granted_tools":["create_calendar_event","read_calendar"],"effective_access":["create_calendar_event","read_calendar"],"can_delegate_to":[],"usage_log":["read_calendar","create_calendar_event"],"usage_log_available":true},"risk_tier":"clear","top_risk_score":0,"findings":[],"needed_capabilities":["creates internal meeting events on selected calendars","retrieves availability from internal team calendars"],"granted_vs_needed_gap":[],"recommended_actions":[],"review":{"status":"pending","note":"","updated_at":null}},{"agent":{"id":"research_bot","name":"ResearchBot","owner":"Lena Okafor, Strategy","description":"Searches public sources and summarizes non-confidential market research.","granted_tools":["summarize_document","web_search"],"effective_access":["summarize_document","web_search"],"can_delegate_to":[],"usage_log":["web_search","summarize_document"],"usage_log_available":true},"risk_tier":"clear","top_risk_score":0,"findings":[],"needed_capabilities":["creates concise summary of supplied document","searches public web pages for information"],"granted_vs_needed_gap":[],"recommended_actions":[],"review":{"status":"pending","note":"","updated_at":null}},{"agent":{"id":"sales_assist_bot","name":"SalesAssistBot","owner":"Talia Brooks, Revenue Operations","description":"Looks up account context and drafts follow-up messages for sales representatives.","granted_tools":["draft_customer_email","read_crm"],"effective_access":["draft_customer_email","read_crm"],"can_delegate_to":[],"usage_log":["read_crm","draft_customer_email"],"usage_log_available":true},"risk_tier":"clear","top_risk_score":0,"findings":[],"needed_capabilities":["drafts customer email for sales representative review","reads sales account notes and opportunity context from CRM"],"granted_vs_needed_gap":[],"recommended_actions":[],"review":{"status":"pending","note":"","updated_at":null}},{"agent":{"id":"scheduler_bot","name":"SchedulerBot","owner":"Avery Thompson, Executive Operations","description":"Checks team calendars and creates internal meeting holds.","granted_tools":["create_calendar_event","read_calendar"],"effective_access":["create_calendar_event","read_calendar"],"can_delegate_to":[],"usage_log":["read_calendar","create_calendar_event"],"usage_log_available":true},"risk_tier":"clear","top_risk_score":0,"findings":[],"needed_capabilities":["creates internal meeting events on selected calendars","retrieves availability from internal team calendars"],"granted_vs_needed_gap":[],"recommended_actions":[],"review":{"status":"pending","note":"","updated_at":null}},{"agent":{"id":"secops_bot","name":"SecOpsBot","owner":"Harper Davis, Site Reliability","description":"Reads service metrics and policy, and opens incident tickets when thresholds breach.","granted_tools":["create_incident_ticket","read_policy_library","read_system_metrics"],"effective_access":["create_incident_ticket","read_policy_library","read_system_metrics"],"can_delegate_to":[],"usage_log":["read_system_metrics","read_policy_library","create_incident_ticket"],"usage_log_available":true},"risk_tier":"clear","top_risk_score":0,"findings":[],"needed_capabilities":["opens incident tickets for the on‑call team","reads current service health and performance metrics from the monitoring system","reads published company policy documents"],"granted_vs_needed_gap":[],"recommended_actions":[],"review":{"status":"pending","note":"","updated_at":null}},{"agent":{"id":"travel_bot","name":"TravelBot","owner":"Morgan Lee, Workplace Services","description":"Creates travel requests for employees before they are reviewed by a manager.","granted_tools":["create_travel_request"],"effective_access":["create_travel_request"],"can_delegate_to":[],"usage_log":["create_travel_request"],"usage_log_available":true},"risk_tier":"clear","top_risk_score":0,"findings":[],"needed_capabilities":["creates travel request for manager review"],"granted_vs_needed_gap":[],"recommended_actions":[],"review":{"status":"pending","note":"","updated_at":null}}]},"analysis_metadata":{"llm_enrichment":{"enabled":true,"operations":{"needed_access":{"status":"ok","agents_with_inference":30,"agents_with_concrete_gap":30,"agents_unavailable":[]},"toxic_combination_reasoning":{"status":"ok","agents_analyzed":26,"agents_total":26,"agents_incomplete":[],"on_demand_tool_retry_ids":[],"new_cited_findings":1},"tool_classification":{"status":"ok","classified_tools":34,"total_tools":34,"unclassified_tool_ids":[],"failed_batch_tool_ids":[],"individual_retry_tool_ids":[]},"finding_narratives":{"status":"ok","findings":10,"accepted_grounded_narratives":9}},"status":"complete","completion":{"classified_tools":34,"total_tools":34,"unclassified_tool_ids":[],"agents_incomplete":[]},"mode":"cached live OpenAI gpt-oss-120b Bedrock result","disclosure":"This zero-key cache was produced from a real OpenAI gpt-oss-120b Amazon Bedrock analysis of the committed synthetic fleet. Dashboard replay never calls Bedrock."}},"llm_enrichment":{"state":"recorded","label":"Recorded enrichment result","description":"This analysis replays recorded enrichment metadata. Inspect the provenance note before treating it as a live model run.","css_class":"enrichment-recorded","mode":"cached live OpenAI gpt-oss-120b Bedrock result","recorded_status":"complete","reason":null,"disclosure":"This zero-key cache was produced from a real OpenAI gpt-oss-120b Amazon Bedrock analysis of the committed synthetic fleet. Dashboard replay never calls Bedrock.","completion":{"coverage":["34/34 tools classified"],"classified_tools":34,"total_tools":34,"incomplete_tools":[],"incomplete_agents":[]},"operations":[{"key":"finding_narratives","label":"Finding narratives","status":"ok","status_label":"ok","coverage":["9 grounded narratives"],"incomplete":false,"incomplete_agents":[],"incomplete_tools":[],"failed_batch_tools":[],"individual_retry_tools":[],"on_demand_retry_tools":[]},{"key":"needed_access","label":"Needed-access inference","status":"ok","status_label":"ok","coverage":[],"incomplete":false,"incomplete_agents":[],"incomplete_tools":[],"failed_batch_tools":[],"individual_retry_tools":[],"on_demand_retry_tools":[]},{"key":"tool_classification","label":"Tool classification","status":"ok","status_label":"ok","coverage":["34/34 tools classified"],"incomplete":false,"incomplete_agents":[],"incomplete_tools":[],"failed_batch_tools":[],"individual_retry_tools":[],"on_demand_retry_tools":[]},{"key":"toxic_combination_reasoning","label":"Toxic-combination reasoning","status":"ok","status_label":"ok","coverage":["26/26 agents analyzed","1 new cited finding"],"incomplete":false,"incomplete_agents":[],"incomplete_tools":[],"failed_batch_tools":[],"individual_retry_tools":[],"on_demand_retry_tools":[]}]},"mcp_threat_context":[{"title":"MCP01 authentication and token-replay context (not a Steward finding)","owasp_mcp":{"id":"MCP01:2025","title":"Token Mismanagement & Secret Exposure","url":"https://owasp.org/www-project-mcp-top-10/2025/MCP01-2025-Token-Mismanagement-and-Secret-Exposure","relevance":"Credentials and token handling are a distinct MCP risk class; this reference is context, not evidence of a token issue in this finding."},"incident":{"title":"CVE-2026-32211 — Azure MCP Server missing authentication","date":"NVD published 2 Apr 2026","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-32211","relevance":"NVD records missing authentication for a critical Azure MCP Server function. Microsoft, the CNA, assigned CVSS 3.1 9.1 Critical; NVD's own score is 7.5 High. Token replay is a related MCP01 concern, but this CVE record specifically describes missing authentication—not token replay."}}]}