Agent Security Controls Checklist
44 controls in 12 groups to check before an AI agent touches your data, tools or production, with where to start by agent type. Free from AgentSec Brief.
Version 1.1 · October 2026 · From AgentSec Brief, published by AM Technology Solutions. Use it as a review checklist for any AI agent that can read data, call tools or act on your behalf.
How to use it: go agent by agent. Tick a control only if you can show evidence for it. Anything unticked is your backlog.
Where to start
You don't have to work through all 44 controls in order. Start with the ones that match how the agent is used:
- Coding and developer agents: sandboxing (6), inspecting repos before the agent opens them (6), egress allow-lists (5) and supply chain (8).
- Internal enterprise copilots: delegated identity (2), authorization before retrieval (4), memory isolation (4) and tool access (3).
- External or production agents that act on their own: human approval gates (10), rate and budget limits (7), logging through an external proxy (9) and a tested shutoff (10).
Then cover groups 1 (inventory) and 12 (evidence) for every agent, whatever its type.
What's inside
- 1. Inventory and ownership (4 controls)
- 2. Identity and credentials (6 controls)
- 3. Tool and data access (5 controls)
- 4. Context, retrieval and memory (5 controls)
- 5. Network egress (2 controls)
- 6. Runtime and sandboxing (3 controls)
- 7. Resource limits and cost controls (2 controls)
- 8. Supply chain (4 controls)
- 9. Logging and monitoring (3 controls)
- 10. Human oversight, shutoff and recovery (4 controls)
- 11. Testing (3 controls)
- 12. Evidence for auditors and regulators (3 controls)
Get the full checklist free: all 44 controls with the evidence to look for, plus a printable PDF. Sign up with your email for the free daily AgentSec Brief and the checklist unlocks right here.