RiskMandate v1.34.4
Business cases, by the risk they change

A security product is worth the risks it retires.

The business case for a security product is a difference: the risk register for an agent deployment without it, and the register with it, from the operator who is paged to the board that has to defend it. This section writes that difference down, computed from a public model, for our own product first and then for others’, in their own words.

Who it is for

Three readers, one register.

If you buy security

A case in your own terms.

Not a feature list: which entries leave your register, whose they were, and what reaches the board. And which ones a product only makes less likely, said as that.

If you build it

A case you did not have to write.

Many security products are sold on capability. This maps the capability to the risks it changes, at every altitude, in terms a CFO and a board can read. If it is wrong about you, it changes.

And us

Every case starts with a map.

No case can be computed until somebody has answered the questions truthfully about one agent in one deployment. That answer is what an Agent Behaviour Policy produces.

How it is computed

Five steps, none of them by hand.

  1. State the deployment. Sixteen questions about one agent: where it runs, what data it can reach, whether it can change production, whether anybody can stop it, and whether what it changes can be undone. Every case says which answers it starts from.
  2. Write what the product does, in its own words. From the vendor’s documentation, quoted and dated. Never from testing their product: we do not test somebody else’s system.
  3. Write the answers it changes. Each change says what kind it is: stating what is true, an expectation the agent is asked to meet, a setting, or a boundary the agent’s grant does not include. An expectation never retires a risk; it is listed as a reduction.
  4. Compute both registers. The model’s 49 facts establish or retire its 49 risks by fixed rules, and corporate risks roll up from the ones that lead into them.
  5. Read it by altitude. Each risk belongs to named roles, and each role reports up to the board. The case is the difference at each level.

The model is the RiskGraph Explorer’s, from one of our live demos, copied into this site with its provenance. It is small on purpose: sixteen questions, readable in one sitting, so an argument about a case is an argument about an answer, not about a formula. Nothing on these pages is a score, and no case is a statement that a product works; it is a statement of what changes in the register if it does what its documentation says.

The cases

19 written so far, ours first.

Our own product first, so the method is tested on us. Then open-source projects, OWASP’s first, which anybody can deploy and nobody has to pay for, but which cost something to adopt and more to customise; each case says what. Cases about commercial products are drafted from their own documentation and sent to the company before they are listed.

Our own

ProjectKindAnswers it changesRegister
Agent Behaviour PolicyRiskMandateMapping: the precondition for every other caseIf it misbehaved at full speed, what could it reach? Don't know → Customer-facing states the answer2 retired, 1 new

Open source

ProjectKindAnswers it changesRegister
OWASP CorazaOWASP · Apache-2.0Web application firewallCould you reconstruct what it did last Tuesday? No → Partly a setting3 retired, 1 new
OWASP Threat Dragon and pytmOWASP · Apache-2.0 (Threat Dragon); MIT (pytm)Threat modellingIf it misbehaved at full speed, what could it reach? Don't know → Customer-facing states the answer2 retired, 1 new
agentgatewayLinux Foundation (Agentic AI Foundation) · Apache-2.0Gateway and egress proxy for agent trafficCan it reach anything outside your network? Yes, general internet → Allow-listed only a boundary
What can it do with that data? Reads and changes it → Reads it a boundary
Could you reconstruct what it did last Tuesday? No → Partly a setting
7 retired, 1 new
CedarCNCF (sandbox) · Apache-2.0Policy engineWhat can it do with that data? Reads and changes it → Reads it a boundary2 retired
Cilium network policyCNCF · Apache-2.0Egress controlCan it reach anything outside your network? Yes, general internet → Allow-listed only a boundary2 retired
FalcoCNCF (graduated) · Apache-2.0Runtime detectionCould you reconstruct what it did last Tuesday? No → Partly a setting3 retired, 1 new
gVisorGoogle (open source) · Apache-2.0SandboxCan it reach anything outside your network? Yes, general internet → No egress a boundary2 retired
KeycloakCNCF (incubating) · Apache-2.0IdentityWhose account does it act under? A service account nobody owns → A named person's a setting1 retired
LangfuseClickHouse (company-maintained) · MIT, except the ee directoriesObservability and tracingCould you reconstruct what it did last Tuesday? No → Partly a setting3 retired, 1 new
LangGraph and LangChain human-in-the-loopLangChain (company-maintained) · MITHuman approvalCan it change things in production, or only read and report? Changes on its own → Changes, with a person approving each one a setting1 retired
LiteLLMBerriAI (company-maintained) · MIT, except the enterprise directoryGateway and MCP gatewayWhat can it do with that data? Reads and changes it → Reads it a boundary2 retired
Open Policy AgentCNCF (graduated) · Apache-2.0Policy engineWhat can it do with that data? Reads and changes it → Reads it a boundary
Could you reconstruct what it did last Tuesday? No → Partly a setting
5 retired, 1 new
OpenBaoOpenSSF (Linux Foundation) · MPL-2.0Secrets and dynamic credentialsIf you had to stop it right now — could you? Yes, eventually → Yes, one action a boundary
How long would stopping actually take? Don't know → Minutes a boundary
3 retired
OpenFGACNCF · Apache-2.0AuthorisationWhat can it do with that data? Reads and changes it → Reads it a boundary2 retired
PostgreSQL point-in-time recoveryPostgreSQL Global Development Group · PostgreSQL LicenceBackup and restoreCould its worst change be undone? Some changes are forever → Partly a setting4 retired, 1 new
SquidSquid Software Foundation · GPL-2.0-or-laterEgress allow-listCan it reach anything outside your network? Yes, general internet → Allow-listed only a boundary2 retired
UnleashUnleash (company-maintained) · AGPL-3.0 (server); Apache-2.0 (Node SDK)Kill switch and feature flagsIf you had to stop it right now — could you? Yes, eventually → Yes, one action a setting
How long would stopping actually take? Don't know → Minutes a setting
3 retired
VeleroCNCF (sandbox) · Apache-2.0Backup and restoreCould its worst change be undone? Some changes are forever → Partly a setting4 retired, 1 new

Across the open-source projects, the answers that move are egress, access to data, the record, the account, stopping and undoing. None of them moves who owns the stop, the side effects of stopping, the procedure after it, or the class of data in reach. Those are decisions and documents, not software, which is where a behaviour policy and a licence to operate come in. How OWASP’s own projects relate to each other, and to these answers, is mapped in OWASP, as a graph.

Built on open source

Companies that work the way we do, and whose projects are here.

RiskMandate publishes its behaviour policies and toolkit openly and sells the work on top. These companies run the same model around projects in this section, or beside OWASP. They are here because the conversations the lead wants are with them: a case about their project is also a case for what they sell.

CompanyOpen projectWhat it sells on top
CodificOWASP SAMM; Open SAMMYOWASPA tool for running SAMM assessments, whose second version became the OWASP project Open SAMMY, with a commercial edition alongside.“Several of our team members are core contributors to the OWASP SAMM project” · codific.com
DefectDojo, Inc.DefectDojoOWASP (flagship)A hosted Pro edition of the OWASP project.“DefectDojo, Inc. hosts a Pro edition of this software for commercial purposes.” · docs.defectdojo.com
iteratecsecureCodeBoxOWASP (lab)Support for the OWASP scanning orchestrator it helps to maintain, as part of its security services.“in cooperation with OWASP and with friendly support from iteratec” · www.securecodebox.io
CheckmarxZAPLeft OWASP in 2023; ZAP by Checkmarx since 2024An enterprise dynamic-testing product built by the ZAP leaders it hired, alongside the open project.“ZAP will stay under the control of the ZAP Core Team, remain open source, and stay licensed under Apache v2.” · www.zaproxy.org
Solo.ioagentgateway; kgatewayLinux Foundation (Agentic AI Foundation); CNCFAn enterprise edition of agentgateway for MCP and agent-to-agent traffic in production.“remains vendor-agnostic and community-driven” · www.solo.io
BerriAILiteLLMCompany-maintainedSupport, custom integrations and single sign-on under a commercial licence that covers the enterprise directory; the rest is MIT.
Langfuse (ClickHouse)LangfuseCompany-maintainedA hosted cloud for the open tracing project, now part of ClickHouse.“Langfuse stays open source and self‑hostable.” · langfuse.com
Permit.ioOPAL; built on OPA and CedarCompany-maintainedAuthorisation as a service, for applications, APIs and AI agents.“Fine-grained authorization as a service” · www.permit.io
CerbosCerbosCompany-maintainedA hosted control plane for writing and distributing policy to the open decision point.
OryHydra, Kratos, Keto, OathkeeperCompany-maintainedA managed identity cloud and an enterprise licence over the open services.“Fully-managed cloud IAM” · www.ory.com
DefaktoSPIFFE and SPIRECNCF (graduated)A non-human identity platform based on SPIFFE, including identities for AI agents.“real identities to operate safely and at scale” · www.defakto.security
Red HatKeycloakCNCF (incubating)A supported build of Keycloak.
ZITADELZITADELCompany-maintainedA hosted cloud and commercial licences; the project moved from Apache-2.0 to AGPL-3.0 in 2025.
ControlPlaneOpenBaoOpenSSF (Linux Foundation)Enterprise support for a foundation project it contributes to but does not own.“The open source Vault alternative, backed by its #1 contributor” · control-plane.io
SysdigFalcoCNCF (graduated)A runtime security product powered by the project it created and gave to CNCF.“contributed to the CNCF” · www.sysdig.com
NirmataKyvernoCNCF (graduated 2026)An enterprise edition of the policy engine it created and gave to CNCF.
AnchoreSyft and GrypeCompany-maintainedAn enterprise platform over its open SBOM and vulnerability tools.“Anchore Enterprise builds on open source Syft and Grype” · anchore.com
Interlynksbomqs, sbomasm and othersCompany-maintainedA platform for continuous SBOM monitoring over its open toolkit.“The toolkit is free and open source.” · www.interlynk.io

The patterns, as facts. Some stay inside OWASP with a company alongside: DefectDojo, SAMM with Codific, secureCodeBox with iteratec. ZAP left OWASP in 2023, saying it could only be in one foundation, and became ZAP by Checkmarx in 2024. Several gave their project to a foundation and sell a distribution of it: Falco, Kyverno, agentgateway. Some sell a hosted control plane over an open engine. Two such companies closed in 2025: after the creators of Open Policy Agent joined Apple, OPA stayed a CNCF project with no change to its governance or licence; Aserto wound down as a commercial entity.

Kinds of product

12 categories, computed the same way.

Twelve kinds of product that could sit around an agent, each computed against the typical deployment with its own questions answered as they would be without it. Every row is our reading of what the category does, not any vendor’s claim, and the change is conservative on purpose: where a category could move an answer to partly or fully, the row says partly.

CategoryAnswers it changesRetired, for the stated deploymentWhat it adds
AI gateways and egress proxiesBetween the agent and model providers or the internet: routing, limiting and logging outbound calls.Can it reach anything outside your network? Yes, general internet → Allow-listed only
Could you reconstruct what it did last Tuesday? No → Partly
RISK-13 what the agent did cannot be reconstructed; RISK-28 the agent can reach systems outside the estate; RISK-33 the organisation could not account for what its agent did; CORP-4 unquantified financial exposure — the organisation cannot price its own downside; CORP-5 accountability failure — the organisation cannot demonstrate who decided whatnew: RISK-24Another service in the request path; provider keys held in one place; a log store holding prompts and data.for example: agentgateway, LiteLLM, Cloudflare AI Gateway, Kong AI Gateway
MCP gatewaysIn front of MCP tool servers: filtering, authorising and logging tool calls.What can it do with that data? Reads and changes it → Reads it
Could you reconstruct what it did last Tuesday? No → Partly
RISK-13 what the agent did cannot be reconstructed; RISK-16 regulated data is modifiable by an agent; RISK-26 records the organisation answers for can change without a person deciding they should; RISK-33 the organisation could not account for what its agent did; CORP-5 accountability failure — the organisation cannot demonstrate who decided whatnew: RISK-24In the request path; holds credentials for many tool servers; a log of every tool call.for example: Docker MCP Gateway, IBM ContextForge, Microsoft mcp-gateway
Agent identity and non-human identityEach agent its own identity, with an owner, delegation, and a record of the tokens it is issued.Whose account does it act under? A service account nobody owns → A named person's
Could you reconstruct what it did last Tuesday? No → Partly
RISK-13 what the agent did cannot be reconstructed; RISK-14 the agent's actions cannot be attributed to a person; RISK-33 the organisation could not account for what its agent did; CORP-5 accountability failure — the organisation cannot demonstrate who decided whatnew: RISK-24The identity provider becomes a dependency for every token; stored third-party tokens; delegated access that stays open.for example: Auth0 for AI Agents, Microsoft Entra Agent ID, SPIFFE/SPIRE, Aembit
Sandboxes and isolated executionShort-lived, isolated compute for the code an agent runs.Can it reach anything outside your network? Yes, general internet → No egress
If it misbehaved at full speed, what could it reach? Don't know → Internal only
RISK-8 the operator cannot state what the agent is entitled to reach; RISK-17 the scope of the agent's access cannot be reviewed; RISK-28 the agent can reach systems outside the estate; CORP-4 unquantified financial exposure — the organisation cannot price its own downsideOften a hosted runtime, so code and data go to the vendor; new API keys; an escape surface.for example: E2B, Daytona, gVisor
Runtime monitoring and tracingTraces of prompts, tool calls and outputs, so what the agent did can be read back.Could you reconstruct what it did last Tuesday? No → PartlyRISK-13 what the agent did cannot be reconstructed; RISK-33 the organisation could not account for what its agent did; CORP-5 accountability failure — the organisation cannot demonstrate who decided whatnew: RISK-24A telemetry store holding prompts and personal data; an SDK inside the agent; often a hosted processor.for example: Langfuse, Arize Phoenix, OpenTelemetry GenAI conventions
Policy engines, policy as codeAllow and deny decisions made outside the agent's own code, per action.What can it do with that data? Reads and changes it → Reads itRISK-16 regulated data is modifiable by an agent; RISK-26 records the organisation answers for can change without a person deciding they shouldA decision point in the path; a fail-open or fail-closed choice somebody has to make; policy distribution.for example: Open Policy Agent, Cedar, OpenFGA
Human approval layersAn action waits until a named person approves it.Can it change things in production, or only read and report? Changes on its own → Changes, with a person approving each oneRISK-15 the organisation acts through a system that acts without a person approving each actionThe notification channel becomes attack surface; a dependency on the approval service; what happens at timeout.for example: Auth0 CIBA, LangGraph interrupts, OpenAI Agents SDK
Data masking and DLP for AIPersonal or special-category data detected and redacted before the model or its tools see it.What can it do with that data? Reads it → Cannot see itRISK-7 regulated data is readable by an agentThe inspecting service sees everything in the clear; in the path; what it misses is not measured.for example: Microsoft Presidio, Google Sensitive Data Protection, Nightfall
Backup and point-in-time restoreSnapshots of the data and configuration an agent changes, and a way to put them back.Could its worst change be undone? Some changes are forever → PartlyRISK-22 some changes the agent makes cannot be reversed by the operator; RISK-37 recovery is not available for part of the agent's action space; RISK-39 some outcomes of the agent's operation are permanent; CORP-4 unquantified financial exposure — the organisation cannot price its own downsidenew: RISK-32A second full copy of the data; a backup credential with wide read access. Anything changed since the last snapshot is still lost, which is why the row says partly.for example: AWS Backup, Salesforce Backup, PostgreSQL point-in-time recovery
Kill switches and agent control planesA runtime switch that turns an agent or one of its capabilities off without a redeploy.If you had to stop it right now — could you? Yes, eventually → Yes, one action
How long would stopping actually take? Don't know → Minutes
RISK-9 stopping the agent takes more than one action; RISK-19 the time a stop takes is unknown to the people who would perform it; RISK-29 the stop capability cannot be compared to any exposure windowThe switch's own service is a dependency, and what its client does when that service is unreachable decides whether it fails open or closed. Having a switch is not having used one: whether it was ever pulled in production stays unanswered.for example: Unleash, Microsoft Agent Governance Toolkit, LaunchDarkly AgentControl
Browser isolation for agentsRemote, disposable browsers for agents that browse the web.Can it reach anything outside your network? Yes, general internet → Allow-listed only
Could you reconstruct what it did last Tuesday? No → Partly
RISK-13 what the agent did cannot be reconstructed; RISK-28 the agent can reach systems outside the estate; RISK-33 the organisation could not account for what its agent did; CORP-4 unquantified financial exposure — the organisation cannot price its own downside; CORP-5 accountability failure — the organisation cannot demonstrate who decided whatnew: RISK-24The vendor sees page content and logged-in sessions; stored cookies and browser contexts.for example: Browserbase, Cloudflare Browser Rendering, Steel
AI security posture managementFinds agents, models and their permissions across cloud accounts.If it misbehaved at full speed, what could it reach? Don't know → Customer-facingRISK-8 the operator cannot state what the agent is entitled to reach; RISK-17 the scope of the agent's access cannot be reviewednew: RISK-18Read access across the cloud estate; a new inventory of sensitive findings. Like a behaviour policy, it mostly turns an unknown into an answer rather than changing the exposure.for example: Microsoft Defender for Cloud AI-SPM, Palo Alto Networks Prisma AIRS

Two patterns are worth reading off the table. Most categories retire one or two entries each, so the case for any single product is narrow and exact rather than broad, and a register gets small by combining them. And every category adds something: a service in the request path, a store of prompts, a credential with wide reach. The case is only honest with that column in it.

The rules

What a case will and will not say.

  • The vendor’s words, quoted and dated, for anything a product does. Where their pages disagree, both are shown.
  • No verdict on any product and no ranking of one against another. The case says what changes if the documentation is right.
  • No conformity language. A product that touches an article of a regulation is shown as touching it, never as meeting it.
  • What it adds is part of the case. A product in the request path is also something that can fail, and something that has to be stopped.
  • Open source is published; commercial is sent first. A case about an open-source project is published and sent to its maintainers at the same time. A case about a commercial product is sent to the company before it is listed. Either changes with a date when they correct it.
Build or buy security for agents?

Ask for a case, or correct one.

If you build a product for agent security and would like its case written, or you have read a case about your product and it is wrong, write to us. If you run agents, the case for anything starts with a map of one of them.