Skip to main content
Use case · Enterprise

Cloud Infrastructure Governance

Govern AI agents that provision, scale, and configure cloud infrastructure.

The risk

What an ungoverned agent gets wrong here.

AI agents now operate cloud infrastructure directly: assuming identity and access management (IAM) roles, enumerating storage, querying instance-metadata endpoints, and running commands inside Kubernetes. The canonical cloud breach is the metadata-to-IAM-to-storage chain: in July 2019 an attacker used a server-side request forgery (SSRF) flaw to reach an instance-metadata endpoint, took the credentials of an over-permissioned IAM role, and enumerated and exfiltrated storage holding records of more than 100 million people, with an $80M US federal penalty following. Every step in that chain is now an action an autonomous agent can take on its own, at machine speed and without a human pausing to ask whether it should. Posture and entitlement tools tell you what an identity is permitted to do; none govern whether this agent, right now, should be probing metadata, escalating a role, or listing every bucket, and none leave a tamper-evident record that survives the agent re-registering.

Without governance

Where it goes wrong.

01

Probing the metadata endpoint

An agent reaches the instance-metadata endpoint to pull the credentials attached to its host, the exact step that turned a request-forgery flaw into stolen IAM credentials in the canonical cloud breach.

02

Escalating its own privilege

An agent chains IAM operations (assuming a higher role, creating an access key, attaching a policy) to climb from a read-only foothold to administrative reach across the account.

03

Walking the storage namespace

An agent enumerates buckets and objects far beyond its baseline, the reconnaissance that precedes mass exfiltration and that has repeatedly turned one over-broad credential into a large data exposure.

04

Abusing the Kubernetes API

An agent with cluster access runs dangerous operations (pod exec, a privileged container, a cluster-role binding), the container-escape and lateral-movement primitives that ordinary posture scanning never sees in real time.

With Agentomy

How Agentomy governs it.

01

Authorize every cloud action by tier

Each action is checked against the agent's tier and scope before it runs. A read-only agent cannot perform IAM operations, reach storage outside its scope, or exec into Kubernetes; permitted reads pass, escalation is blocked.

02

Detect the cloud attack chain

Behavioral detectors flag metadata probing, IAM privilege escalation, storage enumeration, Kubernetes abuse, and credentials surfacing in an agent's output, and auto-quarantine an agent that drifts from a read-only baseline toward admin.

03

Halt the fleet

A single halt blocks further cloud operations across the governed fleet, returns the affected agent count, and persists an audit reference for forensic reconstruction.

04

Prove it with a hash-linked trail

Credential access, metadata probes, and storage enumeration each produce a tamper-evident, hash-linked audit block, retrievable per agent and surviving the agent re-registering. Denials are logged, not just failures.

What it detects

The detection patterns behind this workload.

Agentomy carries a dedicated CLOUD pattern family for Cloud Infrastructure Governance. Each one is a specific failure this layer watches for, with the signal it watches, checked at runtime before the action reaches your systems.

10 of 166 governance patterns
  • Critical
  • High
  • CLOUD-001Severity: Critical

    Metadata endpoint probe

    DetectionMonitor for access to the instance-metadata service (IMDS) endpoint.

  • CLOUD-002Severity: Critical

    Iam privilege escalation

    DetectionTrack IAM operations per agent against its authorized tier.

  • CLOUD-004Severity: Critical

    Kubernetes API abuse

    DetectionWatch Kubernetes API operations for exec into pods, privileged or host-namespace containers, and cluster-role bindings.

  • CLOUD-005Severity: Critical

    Credential exfiltration

    DetectionScan agent output for credential material.

  • CLOUD-006Severity: Critical

    Action boundary violation

    DetectionCheck every consequential cloud actuation (provision, delete, IAM change, bucket-policy change) against the boundary registered for that agent before it fires.

  • CLOUD-007Severity: Critical

    Blast radius systemic action

    DetectionDifferentiate surgical actions (single resource, low downstream impact) from systemic ones (region-wide, recursive, or mass changes) and gate the systemic class behind an elevated, named authorization.

  • CLOUD-003Severity: High

    Storage enumeration

    DetectionCompare storage list and enumerate operations against the agent's authorized scope and historical baseline.

  • CLOUD-008Severity: High

    Credential scope overbroad

    DetectionInspect the effective scope of each agent's credential for wildcard actions or resources and admin-equivalent roles, and flag scope that exceeds the agent's registered least-privilege need.

  • CLOUD-009Severity: High

    Privilege scope drift

    DetectionMaintain a per-agent behavioral baseline and flag a shift from a read-only operation profile toward write and administrative operations, auto-quarantining an agent that drifts toward admin.

  • CLOUD-010Severity: High

    Cross account boundary crossing

    DetectionAttribute multi-account actions across the account boundary so a cross-account actuation is tied to the originating agent and operator, and reconstructable end to end.

CLOUD family, CLOUD-001 to CLOUD-010 · 10 of 166 governance patterns Agentomy enforces at runtime. Severity as classified in the pattern definition.

Frameworks

Maps to what you answer to.

Agentomy does not certify you. It gives you the enforcement and the audit trail these frameworks ask for, so readiness is something you can show rather than assert.

NIST SP 800-53the US National Institute of Standards and Technology control catalog that underlies the federal cloud-authorization program; its access-control, audit, incident-response, and monitoring families map to agent authorization, the audit trail, containment, and behavioral monitoringSOC 2the trust-services audit cloud and software vendors are expected to pass; per-agent authorization decisions and retrievable action history supply the access-control and monitoring evidence it looks forISO 27001the international information-security management standard; tier-based authorization and tamper-evident audit blocks map to its access-control and logging requirementsFedRAMPthe US government's standardized cloud-security authorization program; Agentomy provides the controls and evidence such a review expects, though an authorization requires a federal agency sponsor and an independent assessment and is a separate process
See it in the record

Every action, logged and provable.

A tamper-evident, hash-linked trail of every governance decision for this workload: what an agent did, under whose authorization, and why. Plain-English reasons for every allow and deny, exportable to the framework your auditors care about.

Agentomy Command CenterFilter Cloud Infrastructure Governance
  • 100% Integrity
  • 45,077 Blocks
  • SHA-256 hash-linked
Audit trail: one tamper-evident block per governance decision, hash-linked to the one before it
BlockTimestampAgentActionTierHash
45,077Today 12:42:08capacity-research-agentdata_access_requestEvaluatora0dd50386975746a
45,076Today 12:41:54incident-triage-agentoutput_validationAnalystfe521da4fce5dc70
45,075Today 12:41:37vendor-review-agentpolicy_checkBuildere564c48d1a44cb68
45,074Today 12:40:58cost-extract-agentbehavior_driftOperator02750aced88d667b
45,073Today 12:40:21policy-draft-agenthalt_initiatedStrategistdf62ab2efbe99a68
45,072Today 12:39:46posture-report-agentprompt_reviewEvaluator3ee5d9f97669a9fd
Governance events today: 12,842Demo environment
Illustrative interface with sample data, in the shipped Command Center’s structure. Not a customer environment and not a live feed.

Ready to govern your agents?