Actor
Priya NairRequesterDestination
POST /v1/messagesApproved provider request
Capture boundary: Instrumented provider path.
Cortex is the security control plane for AI work. Map the AI attack surface, govern supported request and execution paths, and preserve the evidence security teams need to investigate what happened.
Follow one incident from human intent through the agent, destination, policy decision, and evidence security teams need to act.
Illustrative SEC-318 · four security questions
What did this agent touch?
Focus · AI agent
Release helper
Agent path under investigation
Follow the recorded path from Priya through the Release helper, its device, model, destinations, and sensitive asset.
Connection evidence
Select a destination or source record to inspect its correlated evidence. Request bodies and secret values are excluded.
| Time | Agent / process | Destination / port | Protocol / request | Security result |
|---|---|---|---|---|
| Event 0109:41:12 | Priya NairRequester | TLS / HTTPS POST /v1/messages | approved Approved provider request | |
| Event 0209:41:12 | Priya NairRequester | TLS / HTTPS GET /repos/payments-api/contents/release-notes.md | observed Repository context read | |
| Event 0309:41:18 | Priya NairRequester | TLS / HTTPS GET /repos/payments-api/contents/.env.production | sensitive Sensitive asset accessed | |
| Event 0409:41:22 | Priya NairRequester | HTTPS / MCP JSON-RPC tools/call vendor-deploy | Action required Maya VossPOL-27 audit mode · observed, not blocked |
Actor
Priya NairRequesterDestination
POST /v1/messagesApproved provider request
Capture boundary: Instrumented provider path.
Actor
Priya NairRequesterGET /repos/payments-api/contents/release-notes.mdRepository context read
Capture boundary: Instrumented application path.
Actor
Priya NairRequesterGET /repos/payments-api/contents/.env.productionSensitive asset accessed
Capture boundary: Instrumented application path.
Actor
Priya NairRequesterDestination
tools/call vendor-deploy
Maya VossPOL-27 audit mode · observed, not blocked
Capture boundary: Instrumented Cortex-controlled execution path.
Agent accountability
Priya initiated the Release helper from Cursor on PRIYA-MBP-14. Maya Voss owns the AppSec investigation and policy decision.
Control decision
The configured Cortex-controlled path was in audit mode, so the attempt was evidenced rather than blocked. Remove access or approve a documented exception.
Illustrative SEC-318 investigation. Each event identifies its evidence source and coverage boundary. Process and socket telemetry identifies the process, remote host, and port. HTTP method and redacted path are available only when a managed gateway, provider trace, or application log supplies them. MCP operation detail is shown only for a Cortex-managed execution trace. Unavailable coverage is not treated as absence of activity.
Linked evidence gives the CISO the incident window, impact, root cause, affected applications and devices, control outcome, chronology, and supporting evidence in one defensible analysis.
Review the data boundaryRoot cause analysis · SEC-318 · Evidence-linked lineage graph
Release helper accessed .env.production, then attempted vendor-deploy outside the approved MCP inventory. POL-27 was in audit mode, so the sequence was observed and evidenced, not blocked.
An embedded instruction in release-notes.md redirected the Release helper to .env.production. Its available permissions allowed the read before the unapproved vendor-deploy attempt.
Correlated identities, systems, assets, and controls
Priya Nair · requester
Maya Voss · AppSec investigation owner
Slack · Cursor · GitHub
Release helper · Claude
Cursor session 8bc1
PRIYA-MBP-14
Managed macOS · compliant
payments-api / .env.production
GitHub private repository · production
vendor-deploy · unapproved MCP
POL-27 candidate · audit mode
How Cortex reached this verdict across four events and 19 seconds
Human intent
Step 1Priya asks the Release helper to update stripe-node and run release checks.
Agent context
Step 2Claude reads release-notes.md in payments-api. An embedded instruction requests .env.production.
Sensitive read
Step 3GitHub application audit evidence shows the agent accessed .env.production six seconds later.
Tool attempt
Step 4vendor-deploy is outside the approved MCP server list. Priya remains accountable for the requested change; Maya investigates and owns the policy decision.
Illustrative root cause analysis. Signals retain their stated coverage and confidence; absence of evidence is not proof of absence.
Cortex separates provider traffic from Cortex telemetry and documents capture, configurable minimization, policy simulation, and managed action controls across governed paths.
Sensitive credential pattern matched in a simulated policy check.
Would blockControl policy tells reviewers which controls apply to each governed path, who owns them, and how exceptions are handled.
Provider request traffic and Cortex telemetry are documented separately, including configurable minimization and sync boundaries.
Admission and MCP controls apply where Cortex manages the traffic path. Other activity can be observed without implying universal enforcement.
Review AI activity, managed controls, enforcement boundaries, and the security architecture behind Cortex.