Field Notes

Agentic security reviews must assess the workflow

Agentic security reviews must assess the workflow

The problem with treating agentic security reviews like any other SaaS review is that you never evaluate the thing that actually runs.

The usual questions still matter:

Is the vendor trustworthy?
Do they align with security best practices?
And of course... Do they have a SOC 2?

Those are not necessarily bad questions, but agentic systems force a different question:

“What risk are we taking on when people use this system to build workflows that can reason, connect tools, use credentials, access business data, trigger actions, expose information, retain context and evolve over time?”

That is a very different kind of risk. It's no longer just software sitting in the stack, it's software participating in a business process.

In many cases, the workflows that it can run create new exposure long after the vendor review is complete.

Without asking some of the below, it's easy to end up with a massive blind spot and taking on unquantified risk without realizing it.

Whose authority does it use? The user? A service account? Both?
What systems can it read from or write to? Who can add them?
Do we know where the data that will enter its context window came from?
Can it send data externally?
Can it act without human approval?
Does it retain memory?
What evidence would show what happened?

Without knowing this and other properties, organizations are accepting an unscoped, unowned, and often unpriced risk rather than making that as a deliberate decision

The shift to agentic doesn't require a better vendor questionnaire (although that wouldn't hurt either), it requires moving from point-in-time approval to active and ongoing risk management of the workflows people actually build.

SaaS reviews aren't obsolete but need to adapt because agentic systems are not just another piece of software.