For the CISO · A briefing from Proxy.Me

Security at machine speed.

A single AI agent has modest permissions. A chain of coordinating agents has combined permissions no role was ever intended to authorise.

Proxy.Me: Agentic AI Digital Apprentices by Christopher Jackson
SECTION 01

Cumulative operational authority

The traditional access model assumes one actor, one set of permissions. AI agents break that assumption. Each agent has reasonable, scoped access to its own systems. A flow that chains five agents accumulates the union of all their permissions, often without anyone declaring that combination as a single authority.

This is cumulative operational authority. It cannot be governed if it cannot be measured. The book treats it as a first-class metric: every flow has a calculated total, every total is compared against thresholds, and combinations the enterprise hasn't authorised get blocked or escalated automatically.

SECTION 02

Blast radius as a planning surface

For every proposed flow, the question is simple: if this flow fails, goes wrong, or is misused, what is the impact? Not just the data accessed. Systems modified, communications sent, downstream agents' decisions based on what they received. Authority measures capacity. Blast radius measures consequence.

  • a.Combined permissions calculated continuously, not just at flow-design time.
  • b.Forbidden combinations declared explicitly and enforced by the mesh.
  • c.Kill switches, circuit breakers, and rate limits that act on flows, not just on individual agents.
  • d.Scenario-aware constraint: when posture changes, in-flight work conforms or is torn down.
Authority that cannot be measured cannot be governed.
Proxy.Me · Appendix C
SECTION 03

The CISO's mesh

Mesh governance becomes a security architecture in its own right. Identity propagation rules. Direct-channel security configurations for agent-to-agent protocols. Replayable evidence as the audit substrate. Drift detection on coordination patterns, not just on individual agent behaviour.

For CISOs designing the security model for the next decade of enterprise AI, Proxy.Me is the reference. Three of the four governance appendices are addressed directly to this work.

Proxy.Me cover
The Full Argument

Proxy.Me: Agentic AI Digital Apprentices

Including Appendix C (mesh governance: cumulative authority, blast radius, drift, control towers, sentinels). By Christopher Jackson, May 2026.

Read about the book arrow_forward

Get notified at launch

A single email when Proxy.Me is available.