Here is the honest situation. Here is the honest situation. Organisations are moving agents from demos into production faster than they are learning to contain them. Securing a model endpoint or a web service is well understood, but an autonomous agent is different: it plans, it reads untrusted content, it calls tools, and it acts on its own non deterministic output, so a single poisoned instruction can turn a helpful capability into an unauthorised action. A working demo proves the agent can do the task, not that an attacker cannot make it do something else, and boards are approving agentic projects while asking, often for the first time, how the thing is contained. Reusing a generic model risk template or a stateless service security checklist does not close that gap, it hides it, because neither was calibrated to autonomous action.
This Kit removes the guesswork. It is AI agent containment and runtime security written as adopt-ready controls, so every production agent is inventoried and risk assessed, execution is isolated and identities are scoped to the task, tools are allow listed and irreversible actions are gated behind a human, content the agent reads is treated as untrusted while egress and secrets are locked down, actions are logged to an audit standard the agent cannot reach, agents are adversarially tested before launch, and an escape playbook with framework mapping keeps governance and engineering describing the same system.
What you get, the moment you buy
Grounded in real agent security practice, including runtime sandboxing and microVM style isolation, ephemeral per task environments, short lived task scoped identities, default deny tool allow lists with parameter validation, human approval gates for high consequence and irreversible actions, direct and indirect prompt injection defence, default deny egress and secrets brokering outside the model's reach, audit grade tamper evident logging, adversarial red teaming, an agent escape incident playbook, and control mapping to the NIST AI Risk Management Framework and ISO/IEC 42001 on an ISO/IEC 27001 baseline.
What one control looks like
This is the opening control, where the containment programme begins. All 18 are built to this depth.
Why this is not another template pack
- The architecture is real. A demo that works proves nothing about what an attacker can make the agent do. This tells you how to isolate, scope, allow list, gate, defend, log, test, respond and map, for every control.
- The specifics built in. Sandbox and microVM isolation, ephemeral per task environments, short lived task scoped identities, default deny allow lists, human approval on irreversible actions, direct and indirect injection defence, default deny egress, secrets brokering, and NIST AI RMF and ISO/IEC 42001 mapping are written into the controls, not left generic.
- Built on real security practice, not one vendor or stack. The controls are principle-level, so they hold across agent frameworks and cloud platforms and stay useful as agents and attacks change.
Who buys this
Security architects, MLOps and platform engineers, and AI risk and compliance officers putting autonomous agents into regulated or high risk production, and the leads who must answer to a board how those agents are contained.
Common questions
Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.
Does it cover the whole programme? Yes. Agent risk assessment and scoping, runtime isolation and least privilege, action control and human oversight, injection defence and perimeter control, logging, testing and detection, and incident response and governance mapping each have their own controls with their own evidence.
Is this tied to one agent framework or cloud? No. The controls are principle-level, drawn from real agent security practice and mapped to the NIST AI Risk Management Framework and ISO/IEC 42001 on an ISO/IEC 27001 baseline, so they apply across agent frameworks, orchestration stacks and cloud platforms.
Who is it for? Security architects, MLOps and platform engineers, and AI risk and compliance officers who own how an autonomous agent is contained in production rather than trusting the model to behave.
Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com