RedactSure Research
Research
Data reports on AI agent security. Every article answers the question in its title, with sourced numbers and the mechanism named. Start with the terms, or go straight to your industry's question. To talk it through with the founders, book an AI Agent Security Review or a pilot discussion.
Buying and piloting
- What Should a Security Review of an AI Agent Vendor Cover? Twenty Questions, and the Answer to Each
Six subjects, twenty questions. A security review of an AI agent vendor covers what the model receives, what a successful … - How Does a Governed AI Workflow Pilot Work? One Workflow, Thirty Days, Three Numbers
One workflow, fixed scope, fixed timeline, a named approver on the customer's side, and success criteria agreed before …
The terms
- What Is Least Exposure?
Least Exposure is a security principle for AI agents: for each piece of work, the agent receives exactly the data the task … - What Is Render-Layer Tokenization?
Render-layer tokenization replaces sensitive values with consistent stand-in tokens (SSN_001, ACCT_001, USER_001) at the point … - What Is the PII Wall?
The PII Wall is the point in an AI program where the valuable workflow turns out to run on sensitive data (personal, financial … - What Is Supervised Delegation?
Supervised Delegation is the operating model in which an AI agent works for a named person who grants its access, chooses its … - What Is a Tethered Agent?
A tethered agent is an AI agent that stays tethered to a named person for the whole run: the person grants the access, sees what … - RedactSure Definitions: The Canonical Terms in One Place
This page holds the canonical definition of each term RedactSure has defined, in the exact wording used everywhere the term …
Industry questions
- Can an AI Agent Work Claim Files in Guidewire Without Exposing PII?
Yes, if the agent never receives the PII in the first place. An AI agent can work a claim from first notice of loss to a queued … - Can an AI Agent Work in Duck Creek Without Exposing Policyholder PII? Yes, From Endorsement to Billing, With the Identifiers Never in the Model
Yes, if the model never receives the policyholder. An AI agent can work an endorsement request from the broker's email … - Who Approves When an AI Agent Is About to Pay a Claim?
A named adjuster does, every time, on the record. In an insurance workflow governed by Supervised Delegation, the AI agent takes … - How Can Staff Use AI on Patient Records Without the Model Ever Holding PHI?
By changing what the model receives, not what the staff can do. When patient identifiers and clinical values are replaced with … - Does the AI Have a Break-Glass Path to Patient Data?
No, and the absence is the design. Break-glass access is healthcare security's established mechanism for emergency human access … - Can an AI Agent Work in Epic Without the Model Holding PHI? Yes, If the Identifiers Never Reach It
Yes, if the model never receives the identifiers in the first place. An AI agent can work a patient account from the billing … - Does Using an AI Agent on Patient Records Require a BAA With the Model Vendor? It Depends on What the Model Receives
It depends on what the model receives, and that is a determination the covered entity makes with counsel, not one a vendor … - How Can a School District Let Staff Use AI on Student Records Without Exposing the Data?
By giving staff a sanctioned path in which the AI model never receives the records. When student names, IDs and family details … - Does FERPA's School-Official Exception Cover an AI Tool That Reads Student Records?
It can, but only when the district can satisfy the exception's conditions, and the analysis turns almost entirely on one … - Can an AI Agent Work in PowerSchool Without Exposing Student Records? Yes, If the Model Never Receives the Student
Yes, if the model never receives the student. An AI agent can work attendance follow-up, intervention drafting, scheduling … - Can an AI Agent Prepare Budget Transfers in Tyler Munis Without Exposing Vendor or Staff Data? Yes, and the Principal Still Approves Every One
Yes. An AI agent can gather the account balances, find the lines that are over and under, draft the transfer with the … - How Can an Agency Use AI on Records Covered by the Privacy Act?
By ensuring the AI model never receives the records, which keeps the Privacy Act analysis where the agency can win it. The … - Can an AI Agent Touch Cardholder Data Without Expanding PCI Scope?
Scope is the assessor's call, and the architecture decides how that call goes. Under the PCI Security Standards Council's scoping …
Finance and ERP questions
- Can an AI Agent Work Accounts Payable in NetSuite Without Exposing Vendor Bank Details? Yes, Through the Three-Way Match, With Payment Approval Kept by a Person
Yes. An AI agent can take an invoice from the AP inbox, find the purchase order and the receipt in NetSuite, run the … - Can an AI Agent Work Accounts Payable in Oracle Without Exposing Vendor Bank Details? Yes, Across Fusion Cloud ERP or E-Business Suite and Everything Around It
Yes. An AI agent can work the payables queue in Oracle Fusion Cloud ERP or E-Business Suite, from the invoice image in the … - Can an AI Agent Work Accounts Payable in SAP Without Exposing Vendor Bank Details? Yes, in S/4HANA or ECC, Across the GUI, Fiori and the Systems Around Them
Yes. An AI agent can work the payables queue in SAP S/4HANA or ECC, from the invoice in the workflow inbox through the …
Security and strategy questions
- Why Do Most Agentic AI Projects Fail to Reach Production in Regulated Industries?
Because the valuable workflows run on records a model must not see, and most agent architectures have no answer when security … - What Does a Prompt-Injection Attack Get From an Agent That Sees Only Tokens?
Tokens. Assume the attack works completely: the hidden instruction is read, the model complies, and everything in its context is … - What Does an AI Agent See When It Takes a Screenshot? Everything on the Page, Including What the Task Never Needed
Everything the page renders, whether or not the task needs it. A screenshot-based agent receives the whole picture: the … - Does Banning AI Tools Stop Employees From Using Them?
No. The published numbers say bans move AI use out of sight rather than out of existence. Microsoft and LinkedIn's Work Trend … - What Should the AI See for This Piece of Work?
Exactly the data the task requires and nothing more, decided in advance by the person who owns the work. The question sounds … - Does Least Privilege Cover What an AI Agent Can See?
No. Least privilege governs what an agent may do: which systems it can enter, which actions it can take, which credentials it …
Comparisons and category maps
- What Tools Tokenize Data Before an LLM Sees It?
Three categories of tool tokenize or otherwise strip sensitive data before it reaches a language model, and they differ by where … - Enterprise Browser vs. Render-Layer Tokenization: Two Different Answers to AI Data Exposure
They answer different questions. An enterprise browser governs where data can go: it watches the human acts, copy, paste, upload … - Data Privacy Vault vs. Screen-Level Tokenization: Where Should Tokens Be Made?
Where your sensitive data actually meets your AI, which usually means both, in different parts of the organization. A data … - Can a Credential Vault Protect the Data an AI Agent Reads? It Protects What You Deposit, Not What the Agent Encounters
No. A credential vault protects what the user deposits in it: a password, a one-time code, a payment card. The agent uses … - AI Gateway, DLP, or Tokenization: Which Layer Decides What the AI Sees?
Only the layer where the reading happens can decide what gets read, and for an AI agent that layer is the render. Every other … - Alternatives to Prisma Browser and Island for Controlling What AI Can See
The honest first answer is that Prisma Browser and Island are strong at what they actually do, which is controlling where data …
The environment and the model
- Does an AI Agent Need Its Own Virtual Machine? What the Isolated Environment Governs, and the One Thing It Cannot
Yes. An AI agent that operates applications, holds credentials and moves data needs an environment of its own: a machine … - Does a Confidential VM Keep Sensitive Data Away From the AI? No. It Keeps the Data Away From the Provider
No. A confidential virtual machine keeps the data away from the provider. A trusted execution environment encrypts a … - Secure VM, Confidential VM, or Render Layer: Which One Decides What the AI Sees?
Only the render layer. A secure VM decides where the agent runs and what may leave it. A confidential VM decides who besides … - Should the AI Agent's Secure Environment Belong to the Model Vendor? Separation of Model and Control
No. Separation of model and control is the principle that the environment deciding what an AI agent sees and who approves … - What Is the Enterprise Version of Meta Muse? There Isn't One From Meta, and Here Is What It Would Have to Add
Meta does not make one. Muse is a personal agent: it runs one person's tasks in a dedicated cloud machine, acts across their …
The stack and the audit
- What Are the Two Gaps AI Agents Opened in the Security Stack?
The visibility gap and the accountability gap. Every enterprise security stack was built on two promises: control over what … - How Do You Audit What an AI Agent Saw and Did?
With five artifacts the architecture produces as it runs: the setup record, the exposure policy, the run history, the approval … - What Is an AI Control Record? The Runtime System of Record for Sensitive AI Work
An AI Control Record is the complete evidence set for one governed AI workflow. What it reports is both sides of the work: …