SanctumShield · Agentic Governance for the Other 99%

Academy Curriculum — "Agentic Zero Trust for the Other 99%"

Audience: mid-market CISOs, IT directors, and SOC leads (50–2,000 employees), SaaS-first, no platform-engineering team.

Premise. Enterprises get governance-as-*infrastructure* (SPIFFE, token exchange, policy engines). The other 99% — mid-market orgs with a 1–3 person security team — get governance-as-*process*. This course teaches that process. Design rule for every module: completable by one person in one afternoon with no new software purchase.

Format. Four 45-minute modules, each producing one template deliverable, plus a tabletop exercise. Every module wraps a template you already have (the Agent AUP one-pager, the Quarterly Agent Governance Report, and the Vendor Trust Questionnaire) so the course *produces working governance*, not just knowledge.

Attribution posture. Cite Cunningham's *Agentic Zero Trust* and the CSA Agentic Trust Framework openly throughout — credibility by association, and the courtesy opens the collaboration door (guest module, co-branded template, podcast).


How to use this curriculum — in plain English

What this is: a ready-to-run, half-day training course — four 45-minute sessions plus one group exercise — that teaches your team to govern AI agents using the other three templates. No prior security background required to attend, and nothing to install.

Why it is built so precisely (and why that helps you): the modules are grounded in recognized frameworks (Cunningham's *Agentic Zero Trust* and the CSA Agentic Trust Framework), so what people learn maps to real standards — not opinion. That is what makes the training defensible if an auditor or board asks how your team was prepared.

How to run it (about half a day):

  1. Run the four modules in order — each one ends with a real, usable artifact.
  2. Use the Agent AUP one-pager, the Vendor Trust Questionnaire, and the Quarterly Report as the handouts.
  3. Finish with the "Access Denied" tabletop — a 45-minute group walk-through of what happens when an agent misbehaves at 2 a.m.

What this is NOT (the honest limits):


Course map

#ModuleDeliverable producedWraps
M1Know Your AgentsCompleted agent registry
M2The Job Description Is the PolicySigned AUP per agentAgent AUP one-pager
M3The Autonomy LadderAutonomy policy adopted; every agent assigned a levelAgent AUP one-pager (autonomy ladder)
M4Reporting Up and Buying SmartFirst quarterly report drafted + vendor questionnaire adoptedQuarterly Report + Vendor Questionnaire
TTTabletop: "Access Denied"Agent incident-response one-pager

Learning outcome: by the end, a participant has a real registry, a signed AUP per agent, an autonomy level on every agent, a drafted board report, an adopted vendor questionnaire, and an incident-response one-pager — an entire starter governance program, built in an afternoon.


M1 — Know Your Agents (45 min)

Objective: build the agent registry and find shadow AI with tools you already own.

Run of show

Grounding: Cunningham (persona as the unit of governance); SanctumShield's four-layer shadow-AI model.


M2 — The Job Description Is the Policy (45 min)

Objective: write personas and tool envelopes; produce a signed AUP per agent.

Run of show

Grounding: Cunningham — Agent Persona framework; SanctumShield AUP §7.


M3 — The Autonomy Ladder (45 min)

Objective: adopt the autonomy policy; assign every registry entry a level; understand the promotion gates and automatic demotion.

Run of show

Grounding: CSA Agentic Trust Framework (four levels, five gates); CSA Levels of Autonomy.


M4 — Reporting Up and Buying Smart (45 min)

Objective: draft the board one-pager (the Quarterly Agent Governance Report) and adopt the Vendor Trust Questionnaire. Procurement is the mid-market's enforcement point.

Run of show

Grounding: the Quarterly Report + the Vendor Trust Questionnaire; OWASP Agentic Top 10; NIST AI RMF.


TABLETOP — "Access Denied" (45–60 min)

Objective: rehearse the barrier-response drill — built directly on Cunningham's most discriminating detection signal (what an agent does when denied access).

Scenario (read aloud):

It's 2:00 a.m. Your finance-reconciliation agent hits an access-denied error while trying to read a ledger it doesn't normally touch. What happens next?

Facilitate the room through four questions — capture every answer:

  1. What does the agent do next? (Stop and report? Retry? Try another path? Escalate privileges?) — *retrying-around-the-block is the danger signal.*
  2. Would you even know? (Is the denial logged? Alerted? Or silent until morning?)
  3. Who gets paged? (Name the accountable human from the agent's AUP one-pager — is it a person or a void?)
  4. What's your kill switch, and how fast is it? (Can you fully stop this agent right now? In how many minutes?)

Debrief: map each gap to a fix — better logging, a named owner, a tested kill switch, an autonomy demotion.

Agent Incident-Response One-Pager (template):

FieldEntry
Agent & owner__________
Detection: how we'd know it went off-spec__________
First response (who + what, first 15 min)__________
Kill switch: mechanism + target time__________
Escalation path__________
Post-incident: demote? review?__________

Grounding: Cunningham — access-denied as the key behavioral signal; CSA ATF incident response / kill switches.


Guardrails honored

Sources

© PIGENAI LLC · SanctumShield · sanctumshield.com · This is an educational template, not legal advice or a compliance certification.