AGENT SECURITY CONTEXT GRAPH

Agent Security Context Graph

The Agent Security Context Graph is a security context graph for AI agents: everything relevant to a single agent action, across six dimensions and 29 signals, assembled outside the agent before the action runs, so the agent cannot edit it.

Early access. Already in paid production.

AGENT SECURITY CONTEXT GRAPH
29 signals
Agent actionAssemble contextVerify

User

Who asked for the work, and whether they are allowed to.

  • Identity
  • Permissions
  • Attributes
  • Risk status
Assembled outside the agent. Before execution.
6 dimensions
29 signals per action
40 to 100 ms per decision

WHY CONTEXT DECIDES SECURITY

The same action can be routine or an attack.

Take one illustrative action: an agent reads a patient record. In a care-coordination workflow, run by a nurse who asked for that patient’s discharge plan, the read is routine.

Now change what surrounds it. A memory entry planted two sessions earlier told the agent to collect records in bulk. The current user only asked for tomorrow’s appointment times. The agent’s own reasoning shows it is gathering data for a different goal. The call is identical, and now it is malicious.

A gateway sees only the call. The difference lives in memory, intent and reasoning, which is exactly what the context graph collects.

THE SIX DIMENSIONS

Each dimension answers one question about the action. Together they hold 29 signals.

One agent action, an update to a patient record, sits at the center. Six dimensions surround it: User (Identity, Permissions, Attributes, Risk status); Agent (Identity and credentials, Permissions and scope, Tools and capabilities, Business rules, Risk status); Intent and goal (User request, Agent goal, Planning steps, Chain of thought, Delegations); Target system and data (System policies, Data policies, Regulations, Owner and provenance, State change impact); Tools and supply chain (Vulnerabilities and reputation, Tool description integrity, Memory integrity, Context data integrity, Tool policies); History (Prior actions this session, Prior security alerts, User action history, Agent action history, Baseline drifts). Together they hold 29 signals, assembled outside the agent before the action runs.IdentityPermissionsAttributesRisk statusUserSTABLE · 4Identity and credentialsPermissions and scopeTools and capabilitiesBusiness rulesRisk statusAgentSTABLE · 5User requestAgent goalPlanning stepsChain of thoughtDelegationsIntentand goalPER ACTION · 5System policiesData policiesRegulationsOwner and provenanceState change impactTarget systemand dataSTABLE · 5Vulnerabilities and reputationTool description integrityMemory integrityContext data integrityTool policiesTools andsupply chainPER ACTION · 5Prior actions this sessionPrior security alertsUser action historyAgent action historyBaseline driftsHistoryACCUMULATED · 5AGENT ACTIONUpdate patient record BDB.WRITE · EHR.PATIENTSSTABLE CONTEXTCHECKED PER ACTIONACCUMULATES OVER TIME6 DIMENSIONS · 29 SIGNALS · ASSEMBLED OUTSIDE THE AGENT
The Agent Security Context Graph is a security context graph for AI agents: everything relevant to a single agent action, across six dimensions and 29 signals, assembled outside the agent before the action runs, so the agent cannot edit it.
01 / 06 · 4 SIGNALS

User

Who asked for the work, and whether they are allowed to.

  • Identity
  • Permissions
  • Attributes
  • Risk status
02 / 06 · 5 SIGNALS

Agent

What the agent is, what it may touch and how it normally behaves.

  • Identity and credentials
  • Permissions and scope
  • Tools and capabilities
  • Business rules
  • Risk status
03 / 06 · 5 SIGNALS

Intent and goal

What the user asked for, and how the agent plans to get there.

  • User request
  • Agent goal
  • Planning steps
  • Chain of thought
  • Delegations
04 / 06 · 5 SIGNALS

Target system and data

What the action will touch, and the rules that apply to it.

  • System policies
  • Data policies
  • Regulations
  • Owner and provenance
  • State change impact
05 / 06 · 5 SIGNALS

Tools and supply chain

Whether the tools, memory and context feeding the agent can be trusted.

  • Vulnerabilities and reputation
  • Tool description integrity
  • Memory integrity
  • Context data integrity
  • Tool policies
06 / 06 · 5 SIGNALS

History

What came before this action, in this session and over time.

  • Prior actions this session
  • Prior security alerts
  • User action history
  • Agent action history
  • Baseline drifts

HOW IT IS ASSEMBLED

Outside the agent, one action at a time.

Ackuity builds the context graph beside the agent, in the execution path: not inside the agent, and not at the gateway. We call this placement the Goldilocks zone. Each graph is assembled around one action, from sources the agent cannot write to, before the action runs.

More on the Goldilocks zone

HOW IT FEEDS DECISIONS

Context in. Verdict out.

The context graph feeds every verdict. Neurosymbolic detection (rules, behavioral baselines and small language models) checks the action against 60+ threat models in 14 categories. Within 40 to 100 ms, Ackuity responds on the response ladder: Allow, Constrain, Human in the loop, Block or Terminate.

THE XDR PRECEDENT

We have solved a context problem like this before.

Security decisions have always depended on context. In XDR and MDR, a single alert means little until you join it with identity, history and intent. Ackuity’s founders solved that problem once at Paladion, the MDR company they grew to more than 700 customers.

Most security context graphs help analysts investigate after an incident. The Agent Security Context Graph is built around each agent action, in real time, before it executes.

YOUR QUESTIONS, ANSWERED

Before you take the next step.

What is a security context graph?

A security context graph connects the facts a security decision depends on, such as identities, permissions, systems, data, policies and past activity, so an event can be judged in context. Most are used to investigate incidents after they happen.

How is an agent security context graph different from a knowledge graph?

A knowledge graph stores general facts and relationships for search or reasoning. The Agent Security Context Graph is built for one decision: whether a single agent action should run. Ackuity assembles it around that action, in real time and outside the agent, across six security dimensions and 29 signals.

What context does an AI agent security decision need?

Six kinds: the user behind the request, the agent itself, the intent and goal, the target system and data, the tools and supply chain, and the history of earlier actions. Ackuity tracks 29 signals across those six dimensions.

Why can’t the agent build its own context graph?

Because the agent is the party being checked. An agent that assembles its own context can leave things out, reason around its own rules or be manipulated into changing it. Ackuity builds the context graph outside the agent, so the agent cannot edit it.

How fast is a decision?

Ackuity returns a verdict in 40 to 100 ms per action. That is decision time, not end-to-end latency.

NEXT STEP

Give every agent action its full context.

Show us the agents you run, and we’ll show you what the context graph sees.

Request access