Work with the author of CUSTODY.
CUSTODY is free to read and free to adopt. If you want help applying it — or help with the broader problem of threat modeling and risk assessing AI applications and agents — that engagement is available directly.
Four areas, one underlying problem
Organizations are deploying agents faster than they can classify them, and governance built for stable human identities does not hold. These engagements address that from different angles.
Threat modeling AI applications and agents
Structured threat modeling for systems that reason, use tools, and act. This covers prompt injection and untrusted-input exposure, tool-mediated blast radius, supply chain risk across models and MCP servers, identity and credential paths, and the attack surface created when an agent consumes attacker-controllable content as a core function.
Output is a documented threat model your engineering and security teams can act on, not a generic checklist.
Risk assessing agentic deployments
Assessment of what your agents can actually reach, as opposed to what they were granted. This is the gap between granted and effective authority, measured rather than asserted: network position, identity scope, credential paths, delegation behavior, and the arbitrary-execution tools that quietly reclassify an agent.
Useful before an audit, before scaling autonomy, or when you need a defensible answer to "what happens if this agent is compromised right now?"
Agentic containment architecture
Design and review of the controls that make containment independent of agent behavior: dedicated execution environments and egress brokering, ephemeral per-assignment identity, credential quarantine, enforced level ceilings, tree-wide revocation, and verified teardown.
Vendor neutral. The objective is a working boundary, built from whatever mix of purchased tooling, existing infrastructure, and process fits your environment.
CUSTODY adoption
Direct support applying the framework: inventory and independent classification, defining the conditions artifact so build, deployment, and security systems can consume it, working through the delegation algebra for L5 systems and epoch boundaries for L6, and honest maturity assessment across the seven pillars.
Including the parts the specification says are hard: embedded agentic features, third-party agents, and cross-organizational delegation.
Scaled to where you actually are
Most programs sit at maturity 0 to 1 across the board. The right first engagement is usually smaller than people expect.
Assessment & classification
- Agent inventory, including embedded agentic features and shadow deployments
- Independent profile assignment: level, mandate, and measured reach
- Identification of agents nominally below L4 holding arbitrary-execution capability
- Prioritized findings against the seven pillars
Architecture & advisory
- Containment design review and platform guidance
- Conditions artifact schema and enforcement integration
- Delegation algebra and epoch model for L5 and L6 systems
- Policy, roles, approval tiers, and risk acceptance language
Workshops & enablement
- Threat modeling AI systems, for security and engineering teams together
- Classifying agents by capability rather than intent, with hands-on misclassification exercises
- CUSTODY walkthrough for security leadership and risk owners
- SOC enablement: agent deconfliction and drift detection
If you are not sure which of these you need, the inventory-and-classification work is almost always the right first step. It is the first item on the adoption path for a reason, and it is where organizations most consistently discover that the problem is larger and differently shaped than they assumed.
The framework stays free
Vendor neutral
CUSTODY names no products and endorses none, and engagements follow the same rule. Where a control objective happens to describe what a product does, that is convergence on the problem, not a recommendation.
No paywall
The full specification is on GitHub and free to adopt, in whole or in part, with or without any engagement. Consulting is for organizations that want help applying it faster or more defensibly.
Disagreement welcome
Feedback, corrections, and implementation experience improve the framework. That conversation is not a sales conversation, and it does not need to become one.
Tell me what you are running
A short description of your agent estate and what is worrying you is enough to start. If an engagement is not the right answer, I will say so.