TL;DR: Continuous web attack-surface coverage now depends on balancing automation depth with human-reviewed assurance for auditors and stakeholders, according to Terra. Riskified’s use of Terra’s agentic AI-driven pentesting shows why the governance issue is no longer whether automation can find more, but whether its outputs remain credible, controlled, and acceptable in regulated programmes.
NHIMG editorial — based on content published by terra: Riskified scales penetration testing depth while preserving audit assurance
Questions worth separating out
Q: How should security teams govern AI agents used for offensive testing?
A: Treat offensive AI agents as distinct workloads with explicit ownership, scoped tools, and logged approvals.
Q: Why do autonomous testing tools still need human oversight?
A: Autonomous testing tools still need human oversight because auditors and governance teams need validated evidence, not just generated findings.
Q: What breaks when pentest automation is not tied to audit controls?
A: When pentest automation is not tied to audit controls, teams often end up with findings that are difficult to trust, reproduce, or sign off.
Practitioner guidance
- Define execution boundaries for agentic test agents Limit target scope, allowed actions, and escalation paths before any agentic pentest run begins.
- Keep human validation in the reporting chain Make a reviewer responsible for confirming exploitability, safety, and report quality before results enter risk registers, board packs, or audit evidence.
- Treat testing platforms as non-human identities Assign unique credentials, least-privilege permissions, logging, and revocation to every autonomous testing workflow.
What's in the full article
Terra's full article covers the operational detail this post intentionally leaves for the source:
- The exact hybrid pentesting workflow used to combine agentic exploration with human validation.
- The Terra Platform capabilities that support continuous testing, review, and audit-ready reporting.
- How the organisation balanced safety controls with deeper attack-surface coverage in practice.
- The deployment context on AWS and Amazon Bedrock that underpins the agentic testing workflow.
👉 Read terra's analysis of agentic AI pentesting and audit assurance →
Agentic AI pentesting and audit assurance: what changes for security teams?
Explore further
Hybrid pentesting is now a governance model, not a tooling preference. The central shift in this topic is that agentic automation and human assurance are solving different problems. Automation improves depth and continuity, while humans preserve defensibility, reviewer accountability, and audit acceptance. Organisations that treat this as a simple efficiency upgrade will miss the control design implications. The practical conclusion is that penetration testing governance must define where autonomous execution ends and human sign-off begins.
A question worth separating out:
Q: Should organisations treat agentic security tools like non-human identities?
A: Yes. Once a security tool can choose actions and execute them independently, it needs the same lifecycle discipline applied to other non-human identities. That means unique credentials, scoped permissions, monitoring, and revocation. The governance question is not whether the tool is intelligent, but whether its access is controllable and attributable.
👉 Read our full editorial: Agentic ai pentesting needs human assurance to satisfy audit demands