Home / Companies / Endor Labs / Blog / Post Details
Content Deep Dive

What are agentic workflows? A practical guide to building and securing them

Blog post from Endor Labs

Post Details
Company
Date Published
Author
AI/ML
Word Count
2,287
Company Posts That Month
22
Language
English
Hacker News Points
-
Post removed?
No
Summary

Agentic workflows are AI-driven processes in which one or more autonomous agents use language models, tools, memory, and orchestration systems to assess context, choose actions at runtime, and work toward goals with limited human intervention, unlike traditional automation based on fixed rules. They are increasingly used in customer support, IT operations, finance, software development, and security, but their ability to call APIs, execute scripts, modify records, generate code, and install dependencies creates risks including excessive permissions, manipulated inputs, insecure code, malicious packages, and dependency vulnerabilities. The text argues that effective governance requires least-privilege access, protected credentials, early code scanning, reachability analysis to prioritize exploitable vulnerabilities, audit logs, stop conditions, and human approval for consequential actions. It also presents security-focused agents as useful for automating vulnerability triage, remediation, malware response, and policy checks, citing Endor Labs research and products to support an evidence-based security harness approach that provides agents with contextual risk and fix information.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
AI Agents 11 5,780 1,243 245 -15%
LLM 8 5,068 1,020 229 -34%
AI Coding Assistant 3 1,513 470 139 -19%
Secrets Management 3 2,244 480 132 -13%
Multi-agent systems 2 432 163 64 -19%
Harness engineering 1 203 125 57 -23%
Real-time 1 4,432 1,050 222 -31%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.