{"version":1,"pages":[{"id":"oUDbLfkpKKy2oFG6lAhe","title":"AI Security Handbook","pathname":"/","siteSpaceId":"sitesp_vIBM8","description":"Harmonic Security’s practical AI security handbook for governing AI tools, agents, MCP, data protection, runtime controls, and incident response."},{"id":"vh6CNNZuu3Hc9JIUAseL","title":"What is AI Security?","pathname":"/start-here/what-is-ai-security","siteSpaceId":"sitesp_vIBM8","description":"A plain-language scope for AI security in this handbook: helping security practitioners roll out AI tools, agents, connectors, and data access safely across the business.","breadcrumbs":[{"label":"Start Here"}]},{"id":"C3gExlezd8nMDpW45uwE","title":"How to Use This Handbook","pathname":"/start-here/how-to-use-this-handbook","siteSpaceId":"sitesp_vIBM8","description":"A guide for security practitioners on navigating the AI Sec Handbook - how articles are structured, what the depth labels mean, and where to start based on your deployment model.","breadcrumbs":[{"label":"Start Here"}]},{"id":"Ro4PbYRx7UNUpZrXH494","title":"Security Team Checklist","pathname":"/start-here/security-team-checklist","siteSpaceId":"sitesp_vIBM8","description":"A practical checklist for security teams deploying AI tools across identity, data, runtime, supply chain, observability, and rollout.","breadcrumbs":[{"label":"Start Here"}]},{"id":"gEtFdGCmkc6eQNehZMHS","title":"Glossary","pathname":"/start-here/glossary","siteSpaceId":"sitesp_vIBM8","description":"Plain-language definitions of every technical term used across the AI Sec Handbook, from AI agent and MCP to vibe coding and Zero Data Retention.","breadcrumbs":[{"label":"Start Here"}]},{"id":"NNVzIV4fDMSPZrMTpmSk","title":"Anthropic","pathname":"/by-ai-vendor/anthropic","siteSpaceId":"sitesp_vIBM8","icon":"claude","description":"Security configuration, governance controls, and risk guidance for Claude Cowork, Claude Code, and Claude Tag.","breadcrumbs":[{"label":"By AI Vendor"}]},{"id":"GFfHTiADhBtlHjubgWcS","title":"Claude Cowork","pathname":"/by-ai-vendor/anthropic/claude-cowork","siteSpaceId":"sitesp_vIBM8","description":"Security guidance for Claude Cowork, including workspace access, connectors, browser use, approvals, data handling, and agent activity evidence.","breadcrumbs":[{"label":"By AI Vendor"},{"label":"Anthropic","icon":"claude"}]},{"id":"ZkYpZcWqZPsVXzXgn4j2","title":"Claude Code","pathname":"/by-ai-vendor/anthropic/claude-code","siteSpaceId":"sitesp_vIBM8","description":"Security guidance for Claude Code, including identity, MCP servers, hooks, filesystem access, sandboxing, approvals, telemetry, and incident response.","breadcrumbs":[{"label":"By AI Vendor"},{"label":"Anthropic","icon":"claude"}]},{"id":"ykvXy0IJ1wgRhXwDXMxY","title":"Claude Tag","pathname":"/by-ai-vendor/anthropic/claude-tag","siteSpaceId":"sitesp_vIBM8","description":"Security guidance for Claude Tag, including identity, deployment scope, data handling, integrations, user access, monitoring, and evidence collection.","breadcrumbs":[{"label":"By AI Vendor"},{"label":"Anthropic","icon":"claude"}]},{"id":"OD62sqxU02c8xMIUcymd","title":"OpenAI","pathname":"/by-ai-vendor/openai","siteSpaceId":"sitesp_vIBM8","icon":"chatgpt","description":"Security configuration, governance controls, and risk guidance for ChatGPT Work and ChatGPT Codex.","breadcrumbs":[{"label":"By AI Vendor"}]},{"id":"rRuMibnG6M6G9vSPemgU","title":"ChatGPT Work","pathname":"/by-ai-vendor/openai/chatgpt-work","siteSpaceId":"sitesp_vIBM8","description":"Security guidance for ChatGPT Work, including managed workspace use, connectors, browser and Computer Use policy, scheduled work, artifacts, sandbox boundaries, and evidence gaps.","breadcrumbs":[{"label":"By AI Vendor"},{"label":"OpenAI","icon":"chatgpt"}]},{"id":"97N1oY9pQjjJOAuAb0QL","title":"ChatGPT Codex","pathname":"/by-ai-vendor/openai/chatgpt-codex","siteSpaceId":"sitesp_vIBM8","description":"Security guidance for ChatGPT Codex across desktop, CLI, IDE, cloud, SDK, and automation workflows, including sandboxing, hooks, OpenTelemetry, approvals, network access, and evidence.","breadcrumbs":[{"label":"By AI Vendor"},{"label":"OpenAI","icon":"chatgpt"}]},{"id":"LWzzRyKLSNcyEo06DHLk","title":"1. Identity & Access","pathname":"/handbook/1.-identity-and-access","siteSpaceId":"sitesp_vIBM8","description":"How to manage human and non-human identity across AI platforms, including SSO, SCIM, RBAC, tenant restrictions, domain claiming, and agent service accounts.","breadcrumbs":[{"label":"Handbook"}]},{"id":"n6ERtJq0AdkD6xlxTrvP","title":"1.1 SSO & SCIM for AI platforms","pathname":"/handbook/1.-identity-and-access/1.1-sso-and-scim-for-ai-platforms","siteSpaceId":"sitesp_vIBM8","description":"Force managed login and automate lifecycle provisioning so AI platform access follows your joiners, movers, and leavers process.","breadcrumbs":[{"label":"Handbook"},{"label":"1. Identity & Access"}]},{"id":"VJkKf6WdWIIwC8oXiXjP","title":"1.2 RBAC across AI platforms","pathname":"/handbook/1.-identity-and-access/1.2-rbac-across-ai-platforms","siteSpaceId":"sitesp_vIBM8","description":"How each vendor exposes roles and permissions, and how to design access models that grant the right capabilities without over-granting.","breadcrumbs":[{"label":"Handbook"},{"label":"1. Identity & Access"}]},{"id":"yezFtmpS1ACXc7QK1w25","title":"1.3 Tenant restrictions: blocking personal accounts","pathname":"/handbook/1.-identity-and-access/1.3-tenant-restrictions-blocking-personal-accounts","siteSpaceId":"sitesp_vIBM8","description":"How to block personal AI accounts using tenant restrictions, organization headers, proxies, browser controls, detection, and exception handling.","breadcrumbs":[{"label":"Handbook"},{"label":"1. Identity & Access"}]},{"id":"aduAYZyY8nvsQsSWtV4g","title":"1.4 Domain claiming: bringing shadow accounts into enterprise","pathname":"/handbook/1.-identity-and-access/1.4-domain-claiming-bringing-shadow-accounts-into-enterprise","siteSpaceId":"sitesp_vIBM8","description":"How to identify and migrate accounts using your verified corporate domain into a managed enterprise workspace.","breadcrumbs":[{"label":"Handbook"},{"label":"1. Identity & Access"}]},{"id":"nXd5PBeNeUXpZixQd0Zi","title":"1.5 Agent and non-human identity","pathname":"/handbook/1.-identity-and-access/1.5-agent-and-non-human-identity","siteSpaceId":"sitesp_vIBM8","description":"How to give AI agents scoped, attributable identities instead of borrowed human credentials.","breadcrumbs":[{"label":"Handbook"},{"label":"1. Identity & Access"}]},{"id":"GaubBPati5XXDKFdKHUM","title":"1.6 API keys and service accounts governance","pathname":"/handbook/1.-identity-and-access/1.6-api-keys-and-service-accounts-governance","siteSpaceId":"sitesp_vIBM8","description":"How to keep personal keys out of automation and scope, rotate, monitor, and attribute machine access properly.","breadcrumbs":[{"label":"Handbook"},{"label":"1. Identity & Access"}]},{"id":"huZf25YLAPMsWAeJ4eLi","title":"1.7 Human-in-the-loop and approval policies","pathname":"/handbook/1.-identity-and-access/1.7-human-in-the-loop-and-approval-policies","siteSpaceId":"sitesp_vIBM8","description":"Where to require human approval in agentic workflows and how approvals can fail under prompt injection, fatigue, or unsafe defaults.","breadcrumbs":[{"label":"Handbook"},{"label":"1. Identity & Access"}]},{"id":"9QuM8MYn93PV8tLxL4fu","title":"2. Supply Chain & Extensibility","pathname":"/handbook/2.-supply-chain-and-extensibility","siteSpaceId":"sitesp_vIBM8","description":"How to govern connectors, MCP servers, plugins, skills, extensions, hooks, and agent frameworks as a software supply chain with real attack surface.","breadcrumbs":[{"label":"Handbook"}]},{"id":"qT7QmCdmrnmCsqqoz5Hh","title":"2.1 Connectors and apps: the integration backbone","pathname":"/handbook/2.-supply-chain-and-extensibility/2.1-connectors-and-apps-the-integration-backbone","siteSpaceId":"sitesp_vIBM8","description":"Every connector is standing authenticated access to a real system — how to approve, scope, monitor, and review them.","breadcrumbs":[{"label":"Handbook"},{"label":"2. Supply Chain & Extensibility"}]},{"id":"ayK1rLcLEcjwl2sAiInG","title":"2.2 MCP servers: securing the protocol","pathname":"/handbook/2.-supply-chain-and-extensibility/2.2-mcp-servers-securing-the-protocol","siteSpaceId":"sitesp_vIBM8","description":"Local and remote MCP servers are both attack surfaces — treat every server like a software dependency with permissions and update risk.","breadcrumbs":[{"label":"Handbook"},{"label":"2. Supply Chain & Extensibility"}]},{"id":"sBiQg3GT343VviLRZKZM","title":"2.3 MCP gateways and allowlisting","pathname":"/handbook/2.-supply-chain-and-extensibility/2.3-mcp-gateways-and-allowlisting","siteSpaceId":"sitesp_vIBM8","description":"How to centralize which MCP servers exist and who can reach them so users cannot freely add unreviewed tools.","breadcrumbs":[{"label":"Handbook"},{"label":"2. Supply Chain & Extensibility"}]},{"id":"PegSL3e4exKnTUs2oicS","title":"2.4 Analyzing skills for risk","pathname":"/handbook/2.-supply-chain-and-extensibility/2.4-analyzing-skills-for-risk","siteSpaceId":"sitesp_vIBM8","description":"Skills and instruction bundles can encode trusted behavior — how to review the full package, dependencies, permissions, and sharing path before use.","breadcrumbs":[{"label":"Handbook"},{"label":"2. Supply Chain & Extensibility"}]},{"id":"d7bDKqn3AqvMwjipymek","title":"2.5 Plugins and marketplaces","pathname":"/handbook/2.-supply-chain-and-extensibility/2.5-plugins-and-marketplaces","siteSpaceId":"sitesp_vIBM8","description":"Plugins and marketplaces bundle skills, connectors, agents, extensions, and actions — how to curate distribution and review updates like code.","breadcrumbs":[{"label":"Handbook"},{"label":"2. Supply Chain & Extensibility"}]},{"id":"PxfMxyPujeVsLetl4qQH","title":"2.6 AI hooks: inference controls and lifecycle automation","pathname":"/handbook/2.-supply-chain-and-extensibility/2.6-ai-hooks-inference-controls-and-lifecycle-automation","siteSpaceId":"sitesp_vIBM8","description":"How AI hooks work, which products support them, how Anthropic's inference hooks differ from lifecycle hooks, and how to use hooks for narrow control and useful runtime evidence.","breadcrumbs":[{"label":"Handbook"},{"label":"2. Supply Chain & Extensibility"}]},{"id":"4PrzcFB3B4NDWNr5wniJ","title":"2.7 The supply-chain review workflow","pathname":"/handbook/2.-supply-chain-and-extensibility/2.7-the-supply-chain-review-workflow","siteSpaceId":"sitesp_vIBM8","description":"A repeatable intake process covering allowlist, owner, scopes, credential handling, runtime permissions, update path, and review date for every AI extension.","breadcrumbs":[{"label":"Handbook"},{"label":"2. Supply Chain & Extensibility"}]},{"id":"HGkaJIkZH0bWGvW1W5ih","title":"2.8 Signing and packaging","pathname":"/handbook/2.-supply-chain-and-extensibility/2.8-signing-and-packaging","siteSpaceId":"sitesp_vIBM8","description":"How to prefer signed, centrally versioned, and managed packages over hand-deployed binaries or ad hoc local extensions.","breadcrumbs":[{"label":"Handbook"},{"label":"2. Supply Chain & Extensibility"}]},{"id":"7G4ask9GiwxdyGC9JARP","title":"2.9 SaaS agent-building supply-chain","pathname":"/handbook/2.-supply-chain-and-extensibility/2.9-saas-agent-building-supply-chain","siteSpaceId":"sitesp_vIBM8","description":"How to govern the connectors, actions, triggers, and data sources that non-security staff wire together in Copilot Studio and similar low-code builders.","breadcrumbs":[{"label":"Handbook"},{"label":"2. Supply Chain & Extensibility"}]},{"id":"bSWM1guMHqpgP9YtGnxx","title":"2.10 Hosted-agent framework dependencies","pathname":"/handbook/2.-supply-chain-and-extensibility/2.10-hosted-agent-framework-dependencies","siteSpaceId":"sitesp_vIBM8","description":"How to secure hosted-agent dependencies across SDKs, tools, MCP servers, prompts, models, containers, deployment pipelines, and runtime services.","breadcrumbs":[{"label":"Handbook"},{"label":"2. Supply Chain & Extensibility"}]},{"id":"NmSi2RrnBjkWLdse30Hs","title":"3. Runtime, Sandbox & Autonomy","pathname":"/handbook/3.-runtime-sandbox-and-autonomy","siteSpaceId":"sitesp_vIBM8","description":"How to contain what AI agents can do at runtime — sandbox isolation, network egress, browser access, filesystem scope, approvals, and scheduled task governance.","breadcrumbs":[{"label":"Handbook"}]},{"id":"ycfyf0tqH65Z6wL5UlBG","title":"3.1 What Even is an AI Sandbox?","pathname":"/handbook/3.-runtime-sandbox-and-autonomy/3.1-what-even-is-an-ai-sandbox","siteSpaceId":"sitesp_vIBM8","description":"What AI sandboxes give you, which AI work products support them, and how security teams should configure, test, and evidence the boundary.","breadcrumbs":[{"label":"Handbook"},{"label":"3. Runtime, Sandbox & Autonomy"}]},{"id":"EQgbosMCby4SWW9pVSNL","title":"3.2 Approval policies and least-privilege autonomy","pathname":"/handbook/3.-runtime-sandbox-and-autonomy/3.2-approval-policies-and-least-privilege-autonomy","siteSpaceId":"sitesp_vIBM8","description":"How to tune how much an agent can do without asking, based on posture, data sensitivity, user role, and task risk.","breadcrumbs":[{"label":"Handbook"},{"label":"3. Runtime, Sandbox & Autonomy"}]},{"id":"xWWXtaOKLKoarFD2Bbf7","title":"3.3 Network egress control","pathname":"/handbook/3.-runtime-sandbox-and-autonomy/3.3-network-egress-control","siteSpaceId":"sitesp_vIBM8","description":"Why default-deny outbound access with administrator-owned allowlists is safer than broad internet access for AI agents.","breadcrumbs":[{"label":"Handbook"},{"label":"3. Runtime, Sandbox & Autonomy"}]},{"id":"09Uxlvzfvm2e206Pr4Fz","title":"3.4 Internet access and browser automation","pathname":"/handbook/3.-runtime-sandbox-and-autonomy/3.4-internet-access-and-browser-automation","siteSpaceId":"sitesp_vIBM8","description":"Browser agents operate near the user’s signed-in sessions, so controls must cover page context, blocklists, per-site approval, and browser bridges.","breadcrumbs":[{"label":"Handbook"},{"label":"3. Runtime, Sandbox & Autonomy"}]},{"id":"P4BhPk2fBT54hNClyXEd","title":"3.5 Computer Use / desktop control risks","pathname":"/handbook/3.-runtime-sandbox-and-autonomy/3.5-computer-use-desktop-control-risks","siteSpaceId":"sitesp_vIBM8","description":"Screen-and-click control can see and act across desktop apps, creating risks that differ from sandboxed code execution.","breadcrumbs":[{"label":"Handbook"},{"label":"3. Runtime, Sandbox & Autonomy"}]},{"id":"h1r98KLb7h40eAs4aFf6","title":"3.6 Scheduled and background tasks","pathname":"/handbook/3.-runtime-sandbox-and-autonomy/3.6-scheduled-and-background-tasks","siteSpaceId":"sitesp_vIBM8","description":"Unattended agent runs execute without a human watching, so they need stricter controls than interactive sessions.","breadcrumbs":[{"label":"Handbook"},{"label":"3. Runtime, Sandbox & Autonomy"}]},{"id":"f51k2Csyhp4VyyRx4Iz1","title":"3.7 Remote access, dispatch and SSH","pathname":"/handbook/3.-runtime-sandbox-and-autonomy/3.7-remote-access-dispatch-and-ssh","siteSpaceId":"sitesp_vIBM8","description":"Mobile-to-desktop bridges, remote dispatch, and SSH can let remote triggers drive local tools and files, expanding the attack surface.","breadcrumbs":[{"label":"Handbook"},{"label":"3. Runtime, Sandbox & Autonomy"}]},{"id":"qOLZ6UULVIH1RkNwlsRV","title":"3.8 File and filesystem access controls","pathname":"/handbook/3.-runtime-sandbox-and-autonomy/3.8-file-and-filesystem-access-controls","siteSpaceId":"sitesp_vIBM8","description":"How to scope which folders an agent can read and write, and how to keep home directories, secrets, and cloud-synced roots out of default access.","breadcrumbs":[{"label":"Handbook"},{"label":"3. Runtime, Sandbox & Autonomy"}]},{"id":"9oFYxtVOK8eggE7f3XY8","title":"3.9 Central hosted-agent runtime hardening","pathname":"/handbook/3.-runtime-sandbox-and-autonomy/3.9-central-hosted-agent-runtime-hardening","siteSpaceId":"sitesp_vIBM8","description":"For agents you run yourself on frameworks or cloud platforms — container isolation, egress, secrets, tool sandboxing, and audit are yours to own end-to-end.","breadcrumbs":[{"label":"Handbook"},{"label":"3. Runtime, Sandbox & Autonomy"}]},{"id":"ZGZ6HfFSaOmIUBnfGTQC","title":"4. Data Protection & Residency","pathname":"/handbook/4.-data-protection-and-residency","siteSpaceId":"sitesp_vIBM8","description":"How to control sensitive data in AI prompts, outputs, files, tools, and agent actions — including DLP, classification, residency, retention, and secrets hygiene.","breadcrumbs":[{"label":"Handbook"}]},{"id":"Hk3oQTfH1Zc31XarVQF5","title":"4.1 DLP for GenAI","pathname":"/handbook/4.-data-protection-and-residency/4.1-dlp-for-genai","siteSpaceId":"sitesp_vIBM8","description":"How to detect and control sensitive data moving into prompts, files, tools, connectors, and outputs where classic DLP often lacks visibility.","breadcrumbs":[{"label":"Handbook"},{"label":"4. Data Protection & Residency"}]},{"id":"9Y8ANNOBlP2WNDLs64wT","title":"4.2 Data classification for AI prompts and outputs","pathname":"/handbook/4.-data-protection-and-residency/4.2-data-classification-for-ai-prompts-and-outputs","siteSpaceId":"sitesp_vIBM8","description":"Which data classes may touch which AI tools and how to enforce the matrix technically across browsers, endpoints, APIs, and agents.","breadcrumbs":[{"label":"Handbook"},{"label":"4. Data Protection & Residency"}]},{"id":"z5uO6UBvarZKrFmEmt6Y","title":"4.3 Data residency and regional inference","pathname":"/handbook/4.-data-protection-and-residency/4.3-data-residency-and-regional-inference","siteSpaceId":"sitesp_vIBM8","description":"How to keep AI processing in-region using cloud model hosting and vendor-specific regional controls rather than assuming a plan setting solves residency.","breadcrumbs":[{"label":"Handbook"},{"label":"4. Data Protection & Residency"}]},{"id":"QGjDY3wLWxIUelUpY8Y7","title":"4.4 Retention and Zero Data Retention","pathname":"/handbook/4.-data-protection-and-residency/4.4-retention-and-zero-data-retention","siteSpaceId":"sitesp_vIBM8","description":"Where conversations, prompts, files, logs, and tool data live, for how long, and what Zero Data Retention does and does not cover.","breadcrumbs":[{"label":"Handbook"},{"label":"4. Data Protection & Residency"}]},{"id":"nEHHWO7jy1K5QIaxvmSA","title":"4.5 Training opt-out and data usage","pathname":"/handbook/4.-data-protection-and-residency/4.5-training-opt-out-and-data-usage","siteSpaceId":"sitesp_vIBM8","description":"How to confirm whether prompts, files, connector data, and feedback are used for model improvement across consumer, business, enterprise, and API plans.","breadcrumbs":[{"label":"Handbook"},{"label":"4. Data Protection & Residency"}]},{"id":"fjbA2B7QoCJ7oJ8FH0y7","title":"4.6 Cross-app data flow and live artifacts","pathname":"/handbook/4.-data-protection-and-residency/4.6-cross-app-data-flow-and-live-artifacts","siteSpaceId":"sitesp_vIBM8","description":"How to control AI data moving through apps, connectors, generated artifacts, shared links, publishing workflows, and downstream systems.","breadcrumbs":[{"label":"Handbook"},{"label":"4. Data Protection & Residency"}]},{"id":"Ypi3dZhWh16UWiJLQjay","title":"4.7 Secrets and credential hygiene in prompts and tools","pathname":"/handbook/4.-data-protection-and-residency/4.7-secrets-and-credential-hygiene-in-prompts-and-tools","siteSpaceId":"sitesp_vIBM8","description":"How to keep secrets out of prompts, files, tool parameters, shell history, logs, telemetry, and model-visible context.","breadcrumbs":[{"label":"Handbook"},{"label":"4. Data Protection & Residency"}]},{"id":"mV7EKUOeCZuoX7r3Wqf1","title":"5. Threats & Adversarial","pathname":"/handbook/5.-threats-and-adversarial","siteSpaceId":"sitesp_vIBM8","description":"The attack patterns unique to AI systems — prompt injection, tool-based exfiltration, supply-chain compromise, tool poisoning, confused deputy, and AI red-team response.","breadcrumbs":[{"label":"Handbook"}]},{"id":"WEEY3YsjqczrmrT3p6UM","title":"5.1 Prompt injection: the connective risk","pathname":"/handbook/5.-threats-and-adversarial/5.1-prompt-injection-the-connective-risk","siteSpaceId":"sitesp_vIBM8","description":"Direct and indirect prompt injection runs through every other AI security risk — how it works, where it comes from, and how to test for it.","breadcrumbs":[{"label":"Handbook"},{"label":"5. Threats & Adversarial"}]},{"id":"ARGzyEUot5zYOLvX27AF","title":"5.2 Data exfiltration via tools and connectors","pathname":"/handbook/5.-threats-and-adversarial/5.2-data-exfiltration-via-tools-and-connectors","siteSpaceId":"sitesp_vIBM8","description":"The injection-to-egress chain uses legitimate tools to move data out, making egress allowlists, connector scoping, and approvals key choke points.","breadcrumbs":[{"label":"Handbook"},{"label":"5. Threats & Adversarial"}]},{"id":"DCc1HmvXMZyoW3nWsSq5","title":"5.3 Supply chain attacks and notable CVEs","pathname":"/handbook/5.-threats-and-adversarial/5.3-supply-chain-attacks-and-notable-cves","siteSpaceId":"sitesp_vIBM8","description":"AI supply-chain attack patterns and CVEs involving repositories, MCP configurations, packages, extensions, hooks, clients, and agent runtimes.","breadcrumbs":[{"label":"Handbook"},{"label":"5. Threats & Adversarial"}]},{"id":"7OJtiam18ONFV7j2NWFj","title":"5.4 Agent-specific threats: tool poisoning and confused deputy","pathname":"/handbook/5.-threats-and-adversarial/5.4-agent-specific-threats-tool-poisoning-and-confused-deputy","siteSpaceId":"sitesp_vIBM8","description":"Threats unique to tool-using agents include poisoned tool descriptions, misleading instructions, overbroad credentials, and confused-deputy privilege abuse.","breadcrumbs":[{"label":"Handbook"},{"label":"5. Threats & Adversarial"}]},{"id":"5NQpDKAg6FstTnRLMiZZ","title":"5.5 Red-teaming AI systems","pathname":"/handbook/5.-threats-and-adversarial/5.5-red-teaming-ai-systems","siteSpaceId":"sitesp_vIBM8","description":"A repeatable program to probe injection, exfiltration, destructive actions, permission abuse, tool misuse, and unsafe agent autonomy across your AI deployment.","breadcrumbs":[{"label":"Handbook"},{"label":"5. Threats & Adversarial"}]},{"id":"LVgGcVs9lHgvJWCy0G83","title":"5.6 Incident response for AI system","pathname":"/handbook/5.-threats-and-adversarial/5.6-incident-response-for-ai-system","siteSpaceId":"sitesp_vIBM8","description":"An AI incident response runbook covering tokens, API keys, MCP grants, apps, connectors, automations, browser permissions, desktop access, and hooks.","breadcrumbs":[{"label":"Handbook"},{"label":"5. Threats & Adversarial"}]},{"id":"6WJix9a0WaDOqqpDiFxm","title":"5.7 Threat modeling AI systems","pathname":"/handbook/5.-threats-and-adversarial/5.7-threat-modeling-ai-systems","siteSpaceId":"sitesp_vIBM8","description":"A lightweight method to threat-model an AI workflow before enabling it, covering surface enumeration, trust boundaries, data flows, tools, and failure modes.","breadcrumbs":[{"label":"Handbook"},{"label":"5. Threats & Adversarial"}]},{"id":"Qn4ibTdc49wppj7kXVhh","title":"6. Observability, Audit & Evidence","pathname":"/handbook/6.-observability-audit-and-evidence","siteSpaceId":"sitesp_vIBM8","description":"What security teams can and cannot see across AI platforms — compliance APIs, usage logs, OpenTelemetry, SIEM routing, investigation paths, and review cadence.","breadcrumbs":[{"label":"Handbook"}]},{"id":"6w2vbNgrXW35xaQsdVmG","title":"6.1 The audit gap: what you can and can't see","pathname":"/handbook/6.-observability-audit-and-evidence/6.1-the-audit-gap-what-you-can-and-cant-see","siteSpaceId":"sitesp_vIBM8","description":"Every AI platform has blind spots, and knowing exactly what each platform’s logs miss is the difference between a real control and an assumption.","breadcrumbs":[{"label":"Handbook"},{"label":"6. Observability, Audit & Evidence"}]},{"id":"MtOQxzlsEl29iIlcbKJe","title":"6.2 OpenTelemetry for AI runtime visibility","pathname":"/handbook/6.-observability-audit-and-evidence/6.2-opentelemetry-for-ai-runtime-visibility","siteSpaceId":"sitesp_vIBM8","description":"How to use OpenTelemetry for AI runtime visibility across Work, Cowork, Codex, Claude Code, Copilot, Grok, and adjacent evidence sources.","breadcrumbs":[{"label":"Handbook"},{"label":"6. Observability, Audit & Evidence"}]},{"id":"If7f4jSGJKVHjRVV0NgC","title":"6.3 Compliance APIs by platform","pathname":"/handbook/6.-observability-audit-and-evidence/6.3-compliance-apis-by-platform","siteSpaceId":"sitesp_vIBM8","description":"The programmatic audit endpoint per vendor, what each one returns, and exactly where each one stops.","breadcrumbs":[{"label":"Handbook"},{"label":"6. Observability, Audit & Evidence"}]},{"id":"1EJfcgkrf0d0rbcorntg","title":"6.4 Analytics and usage APIs","pathname":"/handbook/6.-observability-audit-and-evidence/6.4-analytics-and-usage-apis","siteSpaceId":"sitesp_vIBM8","description":"Adoption, cost, and usage telemetry help spot shifts in AI behavior, tool adoption, connector usage, and spend anomalies.","breadcrumbs":[{"label":"Handbook"},{"label":"6. Observability, Audit & Evidence"}]},{"id":"L1RjEFg7mN3cr88GHmlZ","title":"6.5 Routing AI telemetry to your SIEM","pathname":"/handbook/6.-observability-audit-and-evidence/6.5-routing-ai-telemetry-to-your-siem","siteSpaceId":"sitesp_vIBM8","description":"How to get compliance APIs, usage logs, and runtime telemetry into the SOC with starter detections for AI-specific events.","breadcrumbs":[{"label":"Handbook"},{"label":"6. Observability, Audit & Evidence"}]},{"id":"HeWoDZl8zgABVIhWQ0RI","title":"6.6 Evidence by surface and investigation paths","pathname":"/handbook/6.-observability-audit-and-evidence/6.6-evidence-by-surface-and-investigation-paths","siteSpaceId":"sitesp_vIBM8","description":"Which log answers which question, per AI surface — the reference table you reach for during an AI security incident.","breadcrumbs":[{"label":"Handbook"},{"label":"6. Observability, Audit & Evidence"}]},{"id":"uJTuX4xf4wAtmVKcz1HH","title":"6.7 Continuous review cadence","pathname":"/handbook/6.-observability-audit-and-evidence/6.7-continuous-review-cadence","siteSpaceId":"sitesp_vIBM8","description":"The monthly, weekly, and quarterly rhythm that keeps AI security controls from drifting as tools and capabilities evolve.","breadcrumbs":[{"label":"Handbook"},{"label":"6. Observability, Audit & Evidence"}]},{"id":"IPVqjMyaMGM0DsARLUmG","title":"7. Rollout & Operations","pathname":"/handbook/7.-rollout-and-operations","siteSpaceId":"sitesp_vIBM8","description":"How to deploy AI tools safely by risk phase, design pilots, measure adoption and control effectiveness, and maintain AI governance over time.","breadcrumbs":[{"label":"Handbook"}]},{"id":"x4QkO9sy5XEl7ea84Ofg","title":"7.1 Roll out by risk: the phased plan","pathname":"/handbook/7.-rollout-and-operations/7.1-roll-out-by-risk-the-phased-plan","siteSpaceId":"sitesp_vIBM8","description":"Four phases from inventory and ownership through pilot, controlled expansion, and steady-state operations — the sequence that avoids governance gaps.","breadcrumbs":[{"label":"Handbook"},{"label":"7. Rollout & Operations"}]},{"id":"ycTDdD8rOsf7seth3mhh","title":"7.2 Pilot design and success metrics","pathname":"/handbook/7.-rollout-and-operations/7.2-pilot-design-and-success-metrics","siteSpaceId":"sitesp_vIBM8","description":"What a good AI security pilot looks like, how to select cohorts, and how to know whether controls worked before widening rollout.","breadcrumbs":[{"label":"Handbook"},{"label":"7. Rollout & Operations"}]},{"id":"7zfpotMK4sJjXCv3doLE","title":"7.3 The security team checklist","pathname":"/handbook/7.-rollout-and-operations/7.3-the-security-team-checklist","siteSpaceId":"sitesp_vIBM8","description":"A keep-it-by-your-desk checklist across identity, runtime, browser, desktop, supply chain, cloud, data, and audit controls.","breadcrumbs":[{"label":"Handbook"},{"label":"7. Rollout & Operations"}]},{"id":"u6wg1azZg0PcONMqApp9","title":"7.4 The vendor-neutral control matrix","pathname":"/handbook/7.-rollout-and-operations/7.4-the-vendor-neutral-control-matrix","siteSpaceId":"sitesp_vIBM8","description":"One matrix mapping every control to deployment model and posture so readers can apply the handbook to any AI surface.","breadcrumbs":[{"label":"Handbook"},{"label":"7. Rollout & Operations"}]},{"id":"qlGQjR6e8YgUnxiAG0cl","title":"Governance & Frameworks","pathname":"/reference/governance-and-frameworks","siteSpaceId":"sitesp_vIBM8","description":"Frameworks, regulations, and program-level guidance for enterprise AI security - covering NIST AI RMF, NIST CSF 2.0, EU AI Act, DORA, ISO 42001, acceptable use policy, and ownership models.","breadcrumbs":[{"label":"Reference"}]},{"id":"Wx7lIZE7fpAsQKLsgdBB","title":"G.1 Map your controls to NIST AI RMF and CSF 2.0","pathname":"/reference/governance-and-frameworks/g.1-map-your-controls-to-nist-ai-rmf-and-csf-2.0","siteSpaceId":"sitesp_vIBM8","description":"The backbone mapping every AI security control family to NIST AI RMF GOVERN, MAP, MEASURE, and MANAGE and NIST CSF 2.0 functions.","breadcrumbs":[{"label":"Reference"},{"label":"Governance & Frameworks"}]},{"id":"T6exH056zOi5OA79C4e0","title":"G.2 EU AI Act obligations for deployers","pathname":"/reference/governance-and-frameworks/g.2-eu-ai-act-obligations-for-deployers","siteSpaceId":"sitesp_vIBM8","description":"EU AI Act obligations for enterprise deployers, including classification, human oversight, monitoring, logging, transparency, and evidence.","breadcrumbs":[{"label":"Reference"},{"label":"Governance & Frameworks"}]},{"id":"GCgR4pUY48pVv1UNXQBh","title":"G.3 DORA and AI resilience in financial services","pathname":"/reference/governance-and-frameworks/g.3-dora-and-ai-resilience-in-financial-services","siteSpaceId":"sitesp_vIBM8","description":"ICT risk management, third-party risk, operational resilience testing, and incident reporting applied to AI vendors, agents, and model-hosting platforms under DORA.","breadcrumbs":[{"label":"Reference"},{"label":"Governance & Frameworks"}]},{"id":"2NSXJAhCrwh8we4ghNMs","title":"G.4 Colorado AI Act and the US state patchwork","pathname":"/reference/governance-and-frameworks/g.4-colorado-ai-act-and-the-us-state-patchwork","siteSpaceId":"sitesp_vIBM8","description":"Colorado’s 2026 ADMT law, consequential-decision disclosures, consumer rights, and the emerging multi-state AI regulation picture.","breadcrumbs":[{"label":"Reference"},{"label":"Governance & Frameworks"}]},{"id":"oWVDi7wnQHnBSxlhB0b9","title":"G.5 SANS Critical AI Security Guidelines mapping","pathname":"/reference/governance-and-frameworks/g.5-sans-critical-ai-security-guidelines-mapping","siteSpaceId":"sitesp_vIBM8","description":"How the handbook controls map to the SANS Critical AI Security Guidelines for a practitioner-first cross-check.","breadcrumbs":[{"label":"Reference"},{"label":"Governance & Frameworks"}]},{"id":"5CgXItuoGNEPM4ZIXczh","title":"G.6 Write an AI Acceptable Use Policy that holds up","pathname":"/reference/governance-and-frameworks/g.6-write-an-ai-acceptable-use-policy-that-holds-up","siteSpaceId":"sitesp_vIBM8","description":"A reusable AUP template covering approved tools, data classes, personal accounts, connectors, agents, coding tools, mobile apps, and incident duties.","breadcrumbs":[{"label":"Reference"},{"label":"Governance & Frameworks"}]},{"id":"EAUboVoWVcHCXKxAiaSF","title":"G.7 Ownership and RACI for AI security","pathname":"/reference/governance-and-frameworks/g.7-ownership-and-raci-for-ai-security","siteSpaceId":"sitesp_vIBM8","description":"Names the owners across workspace admin, platform admin, security policy, endpoint, compliance, legal, privacy, procurement, and incident response.","breadcrumbs":[{"label":"Reference"},{"label":"Governance & Frameworks"}]},{"id":"kaoDAixBUnFvy9dnFDXX","title":"G.8 ISO/IEC 42001 AI management system","pathname":"/reference/governance-and-frameworks/g.8-iso-iec-42001-ai-management-system","siteSpaceId":"sitesp_vIBM8","description":"How the handbook supports an AI management system certification effort with clause mapping, control ownership, and evidence artifacts.","breadcrumbs":[{"label":"Reference"},{"label":"Governance & Frameworks"}]},{"id":"pwJv3UArE8aXJzFyDCcw","title":"G.9 HIPAA controls for AI systems handling PHI","pathname":"/reference/governance-and-frameworks/g.9-hipaa-controls-for-ai-systems-handling-phi","siteSpaceId":"sitesp_vIBM8","description":"HIPAA security and privacy controls for AI systems handling PHI, including BAAs, access, data flows, de-identification, evidence, and incident response.","breadcrumbs":[{"label":"Reference"},{"label":"Governance & Frameworks"}]}]}