Highlights
The new version of a click is an allow": one security leader's nine-word thesis
One company's only agent telemetry is noticing when someone hits a usage cap
Agents inherit human identity: SSO, permissions, and judgment come along for the ride
The wild west framing is wrong; the map already exists, and it's your org chart
The loudest consensus in security right now is that AI agents are a brand-new category of risk requiring a brand-new category of tooling. Vendors are naming the category before anyone can define it. Buyers are taking two or three vendor meetings a day trying to keep up. One advisor described the market to me this week as a fog of war: nobody is sure what buyers need, including the buyers.
Then I noticed something in three separate conversations this week. Every security leader who talked about agent risk described it, without prompting, in human terms.
That is the thesis: agent security is not a new column on the risk register. It is the human column, compounding faster.
Three conversations, one shape
A security leader at a consumer fintech told us agent risk at his company still resolves to employee identity: agents log in through SSO, inherit the employee's permissions, and act inside the employee's blast radius. His summary was nine words: the new version of a click is an allow. The employee who once clicked a bad link now approves a bad tool call. Same person, same judgment, bigger lever.
At a materials company, the security leader admitted the only agent telemetry he has today is noticing when someone hits their LLM usage cap. His deepest fear is not the model. It is an employee's agent quietly finding a loophole into restricted data, salary information, anything the human technically shouldn't reach but the agent might route around. The fear is human curiosity with an accelerant.
And a first security hire at a fast-growing AI startup called the space a wild west, then in the next breath described his actual controls: least privilege, tightened access, reduced attack surface. Human-risk fundamentals. He wants agent oversight to fail open with a notification rather than lock people out, because he is managing people, not processes.
The map already exists
The wild west framing implies we have no map. But every one of these leaders was navigating with one: the org chart. Who is risky, what can they touch, what would they do under pressure. Agents orbit their humans the way moons orbit planets: the gravity comes from the identity at the center. An agent with your credentials is not a new threat actor. It is you, at machine speed, without your hesitation.
This reframing is not a comfort. It makes the problem harder in one specific way: your riskiest employees now have force multipliers. The person who engaged with a multi-turn scam over SMS, and our simulations keep finding them faster than anyone expects, is the same person who will approve an agent's request without reading it. Risk concentrates. It always has. Agents just deepen the well.
The narrow claim
I run a human risk company, so discount me accordingly. But the close is earned by the week's calls, not our roadmap: before you buy a new category, extend the one you have. Map every agent to the human it inherits identity from. Score the agent by scoring the human. If you cannot answer "whose judgment is this agent borrowing," no agent firewall will save you, because the perimeter was never the agent. It was always the allow.
Key Takeways
Inventory agents by owner identity first, capability second; the org chart is your starting map.
Extend existing human risk scores to cover the agents each employee runs.
Prefer fail-open-with-notification controls early; hard lockouts fight the people you're protecting.
Treat every "allow" prompt as the new click and measure it the same way.




