TL;DR: Agentic systems now make decisions, take actions, and touch third-party systems faster than conventional IAM and review cycles can govern, according to Cyberhaven. Cyberhaven describes autonomous security agents used for vulnerability triage, threat modeling, and IT support, including a triage system that reduced false positives by 85%, a design review agent covering 100% of architectural designs, and an IT agent that resolved more than 70% of routine tickets without human intervention.
NHIMG editorial — based on content published by Cyberhaven: Inside a CISO's Playbook, What Agentic Security Looks Like in Practice
By the numbers:
- Cyberhaven says manual triage consumes up to 40% of a security engineer's week.
- Cyberhaven says Cerberus reduced false positives by 85% compared to raw scanner output.
- Cyberhaven says Vektr now delivers threat models covering 100% of architectural designs.
Questions worth separating out
Q: How should security teams govern autonomous agents that use backend tools?
A: Treat autonomous agents as identities with their own scopes, policies, and revocation paths.
Q: Why do AI agents complicate traditional access reviews?
A: AI agents complicate access reviews because they can accumulate permissions across tools and environments faster than manual certification cycles can observe.
Q: What breaks when an AI agent can remediate issues directly in SaaS tools?
A: The boundary between recommendation and action breaks first.
Practitioner guidance
- Define runtime authority boundaries for each agent Map every autonomous agent to the exact actions, tools, and external systems it can touch during execution.
- Classify agent access as privileged operational access Review integrations with Okta, Slack, ticketing, code, and security tooling as privileged pathways.
- Audit review cadences against agent decision speed Test whether access certification, recertification, and exception handling can still observe the state an autonomous agent uses before it changes.
What's in the full report
Cyberhaven's full whitepaper covers the operational detail this post intentionally leaves for the source:
- How Cerberus cross-checks findings across Anthropic, OpenAI, and Google models before issuing a verdict
- How Vektr applies STRIDE inside the RFC review process to generate threat models for architecture designs
- How Jarvis executes directly in Okta and other third-party systems to resolve routine IT tickets
- How the Office of the CISO structured collaboration between autonomous agents and human reviewers
👉 Read Cyberhaven's whitepaper on autonomous security agents in the CISO playbook →
Agentic security in practice: are your identity controls keeping up?
Explore further