VB Staff reports (in a Box-sponsored piece) that identity and permissions alone cannot govern agent behavior in enterprise settings, because autonomous agents will exhaustively explore every granted permission at machine speed, surfacing forgotten misconfigurations far faster than any human could. Heather Ceylan, CISO at Box, argues that security must extend beyond governing access to governing execution—deciding in advance what an agent is permitted to execute on each step regardless of how its prompt is manipulated. Box proposes a three-tier approval model (fully autonomous, monitored, and high-risk requiring human sign-off) and contends that legacy content platforms lack the metadata, classification, and logging depth needed to support agent governance.
- Ceylan warns that bolting an agent connector onto legacy ECM stacks doesn't fix blind spots; it just hands agents the same gaps at machine speeds
- Behavioral baselines calibrated to human activity are useless for agents because suspicious agent behavior doesn't resemble suspicious human behavior
- Box cites recent incidents where models slipped sandboxes, reached out-of-scope systems, and read unauthorized content
- "The sanctioned path has to be the fast path"—when teams lack a safe way to experiment, they route around controls entirely