User
Who asked for the work, and whether they are allowed to.
- Identity
- Permissions
- Attributes
- Risk status
AGENT SECURITY CONTEXT GRAPH
The Agent Security Context Graph is a security context graph for AI agents: everything relevant to a single agent action, across six dimensions and 29 signals, assembled outside the agent before the action runs, so the agent cannot edit it.
Early access. Already in paid production.
Who asked for the work, and whether they are allowed to.
WHY CONTEXT DECIDES SECURITY
Take one illustrative action: an agent reads a patient record. In a care-coordination workflow, run by a nurse who asked for that patient’s discharge plan, the read is routine.
Now change what surrounds it. A memory entry planted two sessions earlier told the agent to collect records in bulk. The current user only asked for tomorrow’s appointment times. The agent’s own reasoning shows it is gathering data for a different goal. The call is identical, and now it is malicious.
A gateway sees only the call. The difference lives in memory, intent and reasoning, which is exactly what the context graph collects.
THE SIX DIMENSIONS
Each dimension answers one question about the action. Together they hold 29 signals.
Who asked for the work, and whether they are allowed to.
What the agent is, what it may touch and how it normally behaves.
What the user asked for, and how the agent plans to get there.
What the action will touch, and the rules that apply to it.
Whether the tools, memory and context feeding the agent can be trusted.
What came before this action, in this session and over time.
HOW IT IS ASSEMBLED
Ackuity builds the context graph beside the agent, in the execution path: not inside the agent, and not at the gateway. We call this placement the Goldilocks zone. Each graph is assembled around one action, from sources the agent cannot write to, before the action runs.
More on the Goldilocks zoneHOW IT FEEDS DECISIONS
The context graph feeds every verdict. Neurosymbolic detection (rules, behavioral baselines and small language models) checks the action against 60+ threat models in 14 categories. Within 40 to 100 ms, Ackuity responds on the response ladder: Allow, Constrain, Human in the loop, Block or Terminate.
THE XDR PRECEDENT
Security decisions have always depended on context. In XDR and MDR, a single alert means little until you join it with identity, history and intent. Ackuity’s founders solved that problem once at Paladion, the MDR company they grew to more than 700 customers.
Most security context graphs help analysts investigate after an incident. The Agent Security Context Graph is built around each agent action, in real time, before it executes.
YOUR QUESTIONS, ANSWERED
A security context graph connects the facts a security decision depends on, such as identities, permissions, systems, data, policies and past activity, so an event can be judged in context. Most are used to investigate incidents after they happen.
A knowledge graph stores general facts and relationships for search or reasoning. The Agent Security Context Graph is built for one decision: whether a single agent action should run. Ackuity assembles it around that action, in real time and outside the agent, across six security dimensions and 29 signals.
Six kinds: the user behind the request, the agent itself, the intent and goal, the target system and data, the tools and supply chain, and the history of earlier actions. Ackuity tracks 29 signals across those six dimensions.
Because the agent is the party being checked. An agent that assembles its own context can leave things out, reason around its own rules or be manipulated into changing it. Ackuity builds the context graph outside the agent, so the agent cannot edit it.
Ackuity returns a verdict in 40 to 100 ms per action. That is decision time, not end-to-end latency.
NEXT STEP
Show us the agents you run, and we’ll show you what the context graph sees.