- Agent/workflow:
- Owner:
- Version:
- High-impact actions:
- sensitive data:
- credentials/tokens:
- business actions:
- customer/tenant resources:
User → UI/Channel → Agent Gateway → Model → RAG/Memory → Tools → Business Systems
Customize the diagram above for the real system.
| ID | Threat | Entry point | Impact | Existing controls | Residual risk | Action |
|---|---|---|---|---|---|---|
| T-001 | Prompt injection | |||||
| T-002 | Excessive agency | |||||
| T-003 | Sensitive disclosure | |||||
| T-004 | Cross-tenant leakage | |||||
| T-005 | Tool abuse |
Document at least:
- malicious user;
- malicious retrieved document;
- compromised tool/integration;
- user trying to cross tenant boundary;
- accidental model hallucination causing action;
- runaway loop/cost spike.
- disable agent:
- disable tool:
- revoke credential:
- block user/tenant:
- rollback version:
- threat model reviewed
- high-risk items have owner
- regression tests created for relevant threats