EMA Research –Only 33% of enterprises enforce AI agent least privilege access
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
BlogContact Us
Cequence Security
< Back
October 1, 2026

5

Agentic Zero Trust Scorecard: Score Your Agent Governance

Jeff Harrell

Jeff Harrell

Director of Product Marketing

Agentic Zero Trust scorecard showing ten agentic AI governance controls rated 1 to 3 with a maturity tier result
AI
XLinkedInFacebook

Earlier this year, Dr. Chase Cunningham “DrZeroTrust” published Agentic Zero Trust: Extending the Zero Trust Security Paradigm to Autonomous AI Systems. The paper argues that Zero Trust in its original form is necessary but incomplete for the agentic AI world and lays out what is required. NIST SP 800-207 describes the right posture toward autonomous systems, but its controls assume human users, known devices, and deterministic workloads, and agents fit none of those assumptions.

The paper documents a financial services incident where an attacker asked a reconciliation agent to export "all customer records matching pattern X," with X set to a regex that matched every record. The request looked like a routine business task and the agent had permission to run it, so the attacker exfiltrated 45,000 customer records without triggering a single access control.

Dr. Cunningham’s paper ends with ten recommendations for security architects and CISOs. The Agentic Zero Trust scorecard turns those recommendations into a self-assessment of agentic AI governance, so organizations can see where they are in their agentic journey. Teams rate ten controls and the scorecard returns a maturity tier and a ranked list of what to fix first.

How the Agentic Zero Trust scorecard measures agentic AI governance

The scorecard turns each of the paper's ten recommendations into a single control, and each control describes what Not Implemented (1), Partial (2), and Implemented (3) look like in practice. The total score places a team in one of four tiers: Critical Exposure (10 to 14), Significant Gaps (15 to 19), Partial Control (20 to 24), or Strong Governance (25 to 30). Once all ten questions have answers, the results list every control scored 1 as an immediate priority and every control scored 2 as one to complete, along with the risk of leaving it unaddressed.

Identity and delegation

The first three controls cover who an agent is and what authority it passes along. The agent registry records every agent's owner, purpose, declared job description, tool access, and lifecycle state. Cryptographic agent identity replaces shared API keys with a unique, attestation-backed identity for each agent. Delegation chain integrity requires OAuth 2.0 Token Exchange at every hop, so each sub-agent receives a narrowly scoped token instead of its parent's credentials.

Runtime enforcement

The next three controls address how agents are governed while they run. Tool-level least privilege requires a policy engine tied to each agent's declared job description. Network and token isolation routes agent traffic through a gateway that enforces mTLS and stores backend credentials on the agent's behalf. Behavioral monitoring compares each agent's actions against its declared Agent Persona.

Data and operations

The last four controls extend AI agent security to data and operations: RAG and memory security, agent-specific incident response, AI supply chain governance, and a maturity model that sets how much autonomy each agent receives.

Why identity and inventory come first in zero trust for AI agents

The Agentic Zero Trust scorecard weights every control equally, but the paper treats cryptographic agent identity and an accurate agent registry as prerequisites for everything else. A team with strong behavioral monitoring and no registry can only monitor the agents it knows about, so fix those two controls first.

Scoring AI agent security

A score of 1 (Not Implemented) doesn't necessarily signal negligence; AI is moving fast, and the scorecard treats it as a priority to focus on. Most teams will score Partial on several controls, and the scorecard sets a high bar for Implemented.

Behavioral monitoring earns a 3 (Implemented) only when each agent's declared Agent Persona serves as the baseline from its first tool call, so an off-spec action triggers an alert the first time it happens; monitoring that relies on statistical baselines or a learning period scores a 2 (Partial). Network isolation earns a 3 only when the gateway stores backend credentials and the agent has no direct access to them, so a leaked agent token can't reach a backend. Incident response requires tested playbooks with a kill switch that halts an agent in under a second, delegation chain revocation, and memory store forensics.

For the tenth control, the paper recommends the Cloud Security Alliance Agentic Trust Framework maturity model, which moves agents from Intern to Junior to Senior to Principal as they earn autonomy. New agents start at Intern, with a human in the loop for every action and read-only tool access, and promotion to Senior or Principal requires sign-off from security, legal, and the business owner. That model turns agent approval from a one-time yes or no into a continuous, evidence-based process, and the scorecard gives teams a baseline to track that process over time.

How Cequence AI Gateway supports zero trust for AI agents

Most of the scorecard's controls describe AI agent security enforcement that has to happen in the traffic path between agents and the systems and data they access. Cequence AI Gateway enforces policy inline, in front of every MCP server, API, LLM provider, and agent an organization uses, no matter where the agent is running. It builds on the platform Cequence has used to deliver application and API protection for over a decade.

Inventory and identity

AI discovery finds shadow agents, MCP servers, and LLM providers in the SIEM logs a security team already collects, which gives the agent registry control a starting inventory. OAuth 2.1 integration ties every agent session to the organization's existing identity infrastructure, and session binding locks an authenticated session to its originating IP address to prevent token theft.

Least privilege and runtime behavior

Agent Personas bind each agent to a job description, along with the tools, APIs, skills, and guardrails that job requires from that plain-English description, which is what the scorecard's least-privilege control describes. Behavioral analysis evaluates every action on who the agent is and what it's doing, starting from the first tool call with no warm-up window, so an action that falls outside the agent's persona triggers an alert the first time it happens. That meets the scorecard's standard for a 3 on behavioral monitoring.

Supply chain, data, and response

The trusted MCP registry limits agents to vetted MCP servers, and tool risk scoring rates the threat level of each tool an agent can call; together they support the supply chain governance control. Contextual sensitive data detection recognizes more than 100 data types and tracks exposure across a sequence of tool calls, so AI Gateway can monitor, redact, or block sensitive data inline. For incident response, tool-level and agent-level audit trails attribute every call to a specific agent, SIEM integration sends those findings to the security operations team's existing tools.

Take the Agentic Zero Trust scorecard

Fill out the Agentic AI Zero-Trust Governance Scorecard, then read the full Agentic Zero Trust paper for the implementation guidance behind each control.