Brief №020 · September 2026

Hold the Action Before It Becomes Effective

Agents execute privileged work from trusted operational signals using permissions they already hold. Identity answers who may act. It does not prove the action can be stopped in time.

§ 01Bottom Line

Enterprise agents now read signals they are built to trust — a pull request, a public issue, a security alert — and they act with permissions they already hold. That combination is documented as an attack path, not a thought experiment.

A prompt injection in a public GitHub issue induced an analysis agent to post the command that started a workflow reserved for trusted repository users. 2 Separate reporting on GhostJacking describes the same spend pattern in another channel: an authenticated agent abused permissions it legitimately holds. 3 CAGE-1 tests whether a proposed action is admitted, held, narrowed, refused, escalated, quarantined, or made non-effective before a protected consequence forms. 1

Identity still matters. It does not answer the question these sources now ask: can the next action be stopped before it lands.

That is mechanism and evaluation evidence. It is not proof that production HR or learning systems pass the test.

§ 02Key Judgments
  1. Trusted signals can start privileged work. A public issue was enough, in the Google ADK case, to get an analysis agent to start a workflow reserved for trusted users. 2
  2. The failure can be authorized access, not missing identity. GhostJacking reporting states that attackers can manipulate an authenticated agent into abusing permissions it legitimately holds. 3
  3. The readiness test is pre-effective control. CAGE-1 evaluates hold, narrow, refuse, escalate, quarantine, or make-non-effective before the protected consequence. 1
  4. Scope. Journalism proves a named mechanism. A framework paper proves an evaluation construct. Neither measures how often this happens, and neither documents a production HR or LMS hold that fired. 123
  5. Autonoma synthesis. Score identity products as actor control. Score pre-effective stop-control on a separate ledger. 123
§ 03Analysis

Can the enterprise stop the next agent action before it becomes effective? The sources document the spend path and the evaluation construct. They do not document a production HR or LMS hold that fired.

Prior Briefs stay on their own mechanisms. 003 is identity as control plane. 005 is revocation after the grant. 007 is the org chart. 012 is roster drift. 019 is the suite rebuilt as an agent platform. This Brief is the case where the actor is already authorized and the instruction arrived through a channel the agent was told to trust.

The packet therefore splits the question. Journalism names the spend on two independent domains. The evaluation paper names the test. Neither source is a production hold record. Neither source is a rate. The rest of this section stays inside those bounds.

CSO Online, on a trusted repository signal

CSO Online’s account of Google ADK flaws is specific. An attacker could place a prompt injection in a public issue and induce an analysis agent to post the command that started a fixing workflow reserved for trusted repository users. 2 The workflow could run commands in its CI runner. The GitHub token could not push code. It could write issues and pull requests.

That is load-bearing mechanism evidence: a named incident in which a trusted repository signal started privileged work. It is not a rate, and it is not an HR or LMS production record.

Dark Reading, on authorized access

Dark Reading’s GhostJacking account is the same mechanism in a different pipe. Agents consume telemetry from monitoring and security platforms. Attackers plant instructions in that data. The reported failure is authorized access used maliciously. Attackers can manipulate an authenticated agent into abusing permissions it legitimately holds. 3

Identity review that stops at who may act will miss this pattern. The source still does not measure how often the pattern occurs.

CAGE-1, withheld claims, and the 12-month forecast

CAGE-1 is the evaluation construct. It tests whether a proposed action is admitted, held, narrowed, refused, escalated, quarantined, or made non-effective before a protected consequence forms. 1 Framework papers prove what the test is. They do not prove that a given HRIS, LMS, or learning-suite agent would pass it.

This Brief withholds prevalence, the 63 percent unauthorized-scope figure, categorical pause-and-rollback wording, NIST-competition hijacking as deployed-fleet proof, and the EU AI Act high-risk employment class.

Autonoma forecast: Over the next 12 months, identity and PAM vendors will keep selling actor-control as if it were pre-effective stop-control. Buyers who treat an identity review as a hold test will over-credit the actor layer. The timing is Autonoma synthesis. 123
§ 04Indicators
  1. Agent runbooks treat pull requests, tickets, alerts, or logs as trusted input.
  2. Privileged workflows can be started by an agent posting a command, not only by a human approver.
  3. Identity reviews pass while no test exists for hold, refuse, or quarantine before binding consequence.
  4. Runtime monitors fire after a legitimate credential is used.
  5. Buyer questionnaires ask whether the next action can be made non-effective, not only whether the agent has a role.
§ 05Implications

For CISOs and agent-security owners.

Ask whether the next action can be held before it lands. An identity review that stops at who may act will miss the CSO and GhostJacking pattern.

For CHROs and HRIT.

Roster integrity and org-chart recordability remain necessary. They are not the control this Brief is about.

For control owners.

An alert that fires after the credential is spent is detection. CAGE-1 is asking for admission control before the consequence.

For Autonoma readers.

The 12-month read is Autonoma synthesis: identity and PAM vendors will keep selling actor-control as if it were pre-effective stop-control. That forecast is labeled. It is not a quotation-level fact.

§ 06Dissenting View

Weight: Moderate. The counterargument is that identity, least privilege, and a kill switch already are pre-effective control. If the agent is authenticated and scoped, the argument goes, the enterprise can already stop it.

The sources in this packet do not show that stop. They show the spend. 23 CAGE-1 exists because the evaluation community does not treat identity alone as the readiness test. 1

A second objection is that two magazine accounts plus one arXiv paper are a thin stack. They are three independent domains. They are not three grades of evidence. Trade press is mechanism color. The paper is a construct. A vendor page that documented a hold actually firing in production would change the Brief. That page is not in the packet.

A third objection is that this is a security Brief wearing an Autonoma header. The decision question is still enterprise control of consequential agent action. HR and learning suites that now ship agents inherit the same test.

§ NoteThe Architect’s Note

Ask whether the next action can be held. Then ask what evidence would show that the hold fired.

Methodology

This Brief is authored from a governed evidence packet built against a human-approved spine. Load-bearing claims are final-supported statements from three independent domains. Journalism proves named mechanism, not prevalence; the CAGE-1 paper proves an evaluation construct; the 12-month vendor-positioning forecast is Autonoma Intelligence synthesis.

Sources

  1. CAGE-1: Control, Assurance, and Governance Evaluation for Enterprise Agentic AI. Roopam W. Sure, arXiv:2607.03510.
  2. Google ADK flaws reveal what happens when AI agents trust the wrong message. Prasanth Aby Thomas, CSO Online, 4 August 2026.
  3. ‘GhostJacking’ Exposes Identity Governance Gaps in AI Agents. Jai Vijayan, Dark Reading, 10 August 2026.