Use cases
Where machine authority already carries consequence.
For each environment: the consequential action, the authority risk, the CipherQuay control, and the evidence outcome. Scenarios are illustrative and do not describe any named organisation.
Case 01
AI coding and DevOps agents
The first priority environment. These agents reach repositories, dependencies, shell environments, secrets, CI/CD, cloud infrastructure, IAM, databases and production deployment.
Open a pull request, run a pipeline, apply infrastructure changes, deploy a service.
Self-approval, merge of unreviewed changes, environment confusion between staging and production, dependency substitution, standing credentials retained after the task.
Mandates separate propose from approve and staging from production. Gate requires an independently controlled approval for production, issues short-lived purpose-scoped credentials, and can narrow, delay or revoke.
Which agent proposed the change, which sponsor authorised the mandate, which approvals were obtained, what was deployed where, and whether the action stayed within authority.
Illustrative — not live data
Case 02
Cloud and identity administration
Agents that inspect and remediate infrastructure quickly accumulate the broadest reach in the estate.
Modify security groups, rotate keys, alter IAM roles, resize or delete resources.
Privilege escalation through role editing, silent expansion of reach, destructive action in the wrong account, loss of separation between read and write authority.
Read authority granted broadly; write authority granted narrowly and by purpose. IAM alteration and destructive operations require quorum approval or verification, or are simulated first.
The state before and after, the mandate and policy applied, the approvers involved, and confirmation of reversal if containment was required.
Illustrative — not live data
Case 03
Financial and procurement agents
Agents that negotiate, raise orders, reconcile invoices or initiate payments create direct financial commitments.
Create a supplier, amend payment details, raise a purchase order, release a payment.
Unauthorised financial commitment, supplier impersonation, thresholds bypassed through task decomposition, instructions injected via invoices or emails.
Value and counterparty limits are written into the mandate. Gate applies thresholds, quorum approval above a defined value, delay windows for new payees, and denial of standing payment authority.
Who sponsored the commitment, which limit applied, which humans approved, and whether the payment matched the declared purpose.
Illustrative — not live data
Case 04
Customer-support and communications agents
Agents that speak on behalf of the organisation create contractual, reputational and data-protection consequences.
Issue refunds or credits, amend customer records, send outbound communications at scale.
Commitments beyond policy, disclosure of personal data, mass communication error, instructions embedded in inbound customer content.
Mandates bound remedy values, recipient scope and data categories. Gate narrows bulk sends, requires human approval above thresholds and denies access to data outside the declared purpose.
What was sent or granted, to whom, under which mandate, with which approval, and which data was accessed.
Illustrative — not live data
Case 05
Security-response agents
Response automation must act quickly, yet the same speed can amplify a mistaken or manipulated instruction.
Isolate a host, disable an account, block a network range, quarantine data.
Denial of service to the business, disabling of oversight or logging, response triggered by manipulated telemetry, containment of the wrong asset.
Pre-authorised containment within a bounded blast radius; anything wider requires verification or quorum. Oversight and evidence functions are excluded from agent authority.
What was contained, on which signal, under which pre-authorisation, and how and when normal service was restored.
Illustrative — not live data
Case 06
Cross-agent delegation and cascade containment
Agents increasingly invoke other agents, tools and MCP servers. Authority must not be created by delegation.
One agent instructs another, or calls an external tool or MCP server, to complete a task.
Authority laundering through a second machine, confused-deputy behaviour, inherited privileges, cascading failure across a fleet, unattributable action.
Delegated authority cannot exceed the delegating mandate and must remain traceable to the original human sponsor. Gate applies cascade limits, rate and fan-out constraints, and fleet-wide revocation.
The full delegation chain from human sponsor to acting machine, the authority available at each hop, and the point at which containment took effect.
Illustrative — not live data
Next step
Understand the authority your machines already hold.
The Machine Authority Exposure Assessment is a read-only engagement that establishes what your agents can do today, who sponsors them, and what evidence exists if something goes wrong.