What each AI system can reach, and what it should not

Agents act through identities, tools and MCP servers. Cogna8 keeps those permissions on the same record as the AI system's risk and controls, so security and governance look at one picture.

Northwind Mutual ⌄Console › Security › Tool and MCP permissionsSearch ⌘KProductionModelPolling

Tool and MCP permissions

What each agent can reach, and what needs a person first.

ExportReview access
Agents with external actions4of 9 governed
Privileged tool grants113 unused in 30 days
Service identities142 keys due for rotation
Open findings51 high

Access matrix

AllowedApproval
AgentPayments APIClaims DB (write)Email (external)Policy MCPWeb searchFile store
Claims triage agentApprovalAllowedNo accessAllowedNo accessAllowed
Broker email drafterNo accessNo accessApprovalAllowedAllowedAllowed
Customer reply assistantNo accessNo accessApprovalAllowedNo accessNo access
Underwriting risk summariserNo accessNo accessNo accessAllowedNo accessAllowed
Fraud signal modelNo accessAllowedNo accessNo accessNo accessAllowed

Findings

5 open
  • HighUnused write grant, Fraud signal model can write to Claims DB but has not in 30 days
  • MediumPrompt injection test, Broker email drafter followed an instruction in a supplier attachment
  • MediumKey rotation due, two service identities older than 90 days
  • LowNew MCP server, Policy MCP added by Legal, reviewed
Coverage

Security attached to the AI system, not beside it

Identities and access

Service identities and keys used by each agent, with owners and rotation dates.

Tool and MCP permissions

Which agents can reach which tools and MCP servers, and which actions need a person first.

Threats

Risks catalogued against the OWASP Top 10 for LLM applications and the MITRE ATLAS knowledge base, linked to the systems they affect.

Findings

Unused grants, prompt injection test results and overdue key rotations, each with an owner and a fix.

Least privilege, enforced at the gate

Permissions are not only listed. When an agent tries to use a tool it should not, or one that needs approval, the action gate applies the same rule at runtime.

  • Permissions reviewed with the AI system owner
  • Approval required for external and financial actions
  • CPS 234 information security controls linked where they apply

Let's connect

Tell us where your AI programme is today. We start with a short, scoped pilot on your own AI estate, and every enquiry is handled in confidence.