“For CISOs, materiality should be determined by tracing three things,” said Grover. “First, which agents consume untrusted content such as pull requests, issues, emails, support tickets, or external documents? Second, can the output of those agents directly or indirectly trigger another agent or workflow with higher privileges? Third, what is the maximum effective capability of the identities, credentials, and tools involved?”
Mapping transitive authority
Existing security tools may provide only a partial view of how authority moves between agents and workflows.
Grover said IAM, PAM, CIEM, and application-security tools can expose individual identities, permissions, and unsafe workflow configurations, but may not recognize that those components form a single event-driven delegation path.

