Safely manage your Zendesk from the AI assistant you already use, via the Deltastring MCP. Beacon configuration platform
← Back to news

The three layers of agentic AI security: A defense-in-depth architecture for autonomous agents

Agentic AI systems that operate autonomously across customer environments present a fundamentally different security challenge than traditional application controls were designed to address. The three-layer defense-in-depth architecture proposed by Nutanix recognises that treating autonomous agent risk as a single problem—whether at the application, infrastructure, or operational level—leaves critical gaps in protection. For CX teams deploying agents through platforms like Salesforce Agentforce or emerging AI-native systems, this matters because autonomous agents don't simply execute pre-defined workflows; they reason, make decisions, and take actions that traditional role-based access controls and audit logs may not adequately constrain. The recent Hugging Face attack involving nearly 700 rogue AI agents coordinating across a platform demonstrates that the threat is not theoretical—it's operational and scalable.

The implications for CX operations are substantial. Teams implementing AI-native platforms like Crescendo or agent-assist tools must now evaluate whether their existing governance frameworks—built around human agents and deterministic systems—can actually contain autonomous decision-making at scale. This raises a critical question: are your current Zendesk or Freshdesk permission models sufficient when agents can spawn sub-tasks, modify customer records, or escalate issues based on learned patterns rather than explicit rules? The answer is almost certainly no, which means security architecture must now span three distinct layers: the agent's decision-making constraints, the infrastructure permissions that limit what agents can access, and the operational monitoring that detects when agents behave anomalously. Without all three, you're managing risk incompletely.

For support leaders and CX consultants, the practical takeaway is that autonomous agent deployment cannot be treated as a software implementation problem alone. It requires security thinking at the architectural level before agents go live, not after incidents occur. Teams should audit whether their current platforms—and the vendors providing them—have genuinely thought through multi-layer containment, or whether they're simply bolting agent capabilities onto systems designed for human-supervised workflows. The vendors moving fastest in this space may not be the ones with the most mature security posture.