Skip to content
CipherQuay

Use cases

Where machine authority already carries consequence.

For each environment: the consequential action, the authority risk, the CipherQuay control, and the evidence outcome. Scenarios are illustrative and do not describe any named organisation.

Case 01

AI coding and DevOps agents

The first priority environment. These agents reach repositories, dependencies, shell environments, secrets, CI/CD, cloud infrastructure, IAM, databases and production deployment.

Consequential action

Open a pull request, run a pipeline, apply infrastructure changes, deploy a service.

Authority risk

Self-approval, merge of unreviewed changes, environment confusion between staging and production, dependency substitution, standing credentials retained after the task.

CipherQuay control

Mandates separate propose from approve and staging from production. Gate requires an independently controlled approval for production, issues short-lived purpose-scoped credentials, and can narrow, delay or revoke.

Evidence outcome

Which agent proposed the change, which sponsor authorised the mandate, which approvals were obtained, what was deployed where, and whether the action stayed within authority.

Illustrative — not live data

Case 02

Cloud and identity administration

Agents that inspect and remediate infrastructure quickly accumulate the broadest reach in the estate.

Consequential action

Modify security groups, rotate keys, alter IAM roles, resize or delete resources.

Authority risk

Privilege escalation through role editing, silent expansion of reach, destructive action in the wrong account, loss of separation between read and write authority.

CipherQuay control

Read authority granted broadly; write authority granted narrowly and by purpose. IAM alteration and destructive operations require quorum approval or verification, or are simulated first.

Evidence outcome

The state before and after, the mandate and policy applied, the approvers involved, and confirmation of reversal if containment was required.

Illustrative — not live data

Case 03

Financial and procurement agents

Agents that negotiate, raise orders, reconcile invoices or initiate payments create direct financial commitments.

Consequential action

Create a supplier, amend payment details, raise a purchase order, release a payment.

Authority risk

Unauthorised financial commitment, supplier impersonation, thresholds bypassed through task decomposition, instructions injected via invoices or emails.

CipherQuay control

Value and counterparty limits are written into the mandate. Gate applies thresholds, quorum approval above a defined value, delay windows for new payees, and denial of standing payment authority.

Evidence outcome

Who sponsored the commitment, which limit applied, which humans approved, and whether the payment matched the declared purpose.

Illustrative — not live data

Case 04

Customer-support and communications agents

Agents that speak on behalf of the organisation create contractual, reputational and data-protection consequences.

Consequential action

Issue refunds or credits, amend customer records, send outbound communications at scale.

Authority risk

Commitments beyond policy, disclosure of personal data, mass communication error, instructions embedded in inbound customer content.

CipherQuay control

Mandates bound remedy values, recipient scope and data categories. Gate narrows bulk sends, requires human approval above thresholds and denies access to data outside the declared purpose.

Evidence outcome

What was sent or granted, to whom, under which mandate, with which approval, and which data was accessed.

Illustrative — not live data

Case 05

Security-response agents

Response automation must act quickly, yet the same speed can amplify a mistaken or manipulated instruction.

Consequential action

Isolate a host, disable an account, block a network range, quarantine data.

Authority risk

Denial of service to the business, disabling of oversight or logging, response triggered by manipulated telemetry, containment of the wrong asset.

CipherQuay control

Pre-authorised containment within a bounded blast radius; anything wider requires verification or quorum. Oversight and evidence functions are excluded from agent authority.

Evidence outcome

What was contained, on which signal, under which pre-authorisation, and how and when normal service was restored.

Illustrative — not live data

Case 06

Cross-agent delegation and cascade containment

Agents increasingly invoke other agents, tools and MCP servers. Authority must not be created by delegation.

Consequential action

One agent instructs another, or calls an external tool or MCP server, to complete a task.

Authority risk

Authority laundering through a second machine, confused-deputy behaviour, inherited privileges, cascading failure across a fleet, unattributable action.

CipherQuay control

Delegated authority cannot exceed the delegating mandate and must remain traceable to the original human sponsor. Gate applies cascade limits, rate and fan-out constraints, and fleet-wide revocation.

Evidence outcome

The full delegation chain from human sponsor to acting machine, the authority available at each hop, and the point at which containment took effect.

Illustrative — not live data

Next step

Understand the authority your machines already hold.

The Machine Authority Exposure Assessment is a read-only engagement that establishes what your agents can do today, who sponsors them, and what evidence exists if something goes wrong.