Home / Companies / Snyk / Blog / Post Details
Content Deep Dive

The Agent Baseline: 35 Controls, But Where Should You Start?

Blog post from Snyk

Post Details
Company
Date Published
Author
Krysztof Huszcza and Ezra Tanzer
Word Count
2,957
Company Posts That Month
11
Language
English
Hacker News Points
-
Post removed?
No
Summary

Agent Baseline, developed with Docker and Keycard, proposes six vendor-agnostic security outcomes—Discover, Constrain, Authorize, Observe, Validate, and Respond—and 35 controls for enterprise AI agents, but its authors acknowledge that organizations also need practical sequencing rather than a broad coverage checklist. The recommended priorities differ by use case: developer coding agents should begin with constrained execution and scoped capability profiles, informed by continuous discovery of components and effective access; shared internal agents should prioritize verifiable, task-scoped identities and attribution to prevent confused-deputy authority problems; and production agents should focus first on incident response, component quarantine, manual fallbacks, and validation of consequential outcomes. The framework argues that security controls must operate outside the model so agents cannot override them, balancing productivity with enforceable limits rather than either blanket bans or unrestricted deployment with monitoring alone. The authors note that the current baseline lacks both a maturity model and an explicit use-case lens, and invite public feedback on the open-source draft through September 30.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
MCP 5 8,729 854 211 -20%
AI Agents 2 5,780 1,243 245 -15%
AI Coding Assistant 1 1,513 470 139 -19%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.