5.6 The orchestrator’s security job is not Infosec’s job
The division of labor is simple to state. Infosec owns the perimeter: the network, the identity provider, the endpoints, the policy enforcement points. The orchestrator owns what the system is trusted to do inside it — which grants it holds, which content can instruct it, which actions are checked, and what the trail shows. The two jobs meet at the permission boundary, and in most organizations today the permission boundary of an agent system is built by one person on a deadline: the orchestrator. That is not a complaint; it is the job description. Infosec can approve a token scope, but only the orchestrator knows which agents exist and what each one is for.
What the division requires in practice is an inventory, and the orchestrator is the only person positioned to produce it. On Monday, before anything else: list every MCP server the agents load, with its version, its source, and the credential it runs under. List every rules file and skill in the repositories the agents touch, with an owner beside each. Find the tokens — what each can reach, and whether any can see production from a workspace that is supposed to be development. Find the flags — which agents run with the prompt turned off, and whether anyone decided that. Then check egress: which domains, recipients, and branches each agent can actually reach, as enforced outside the model. That list is the permission boundary written down, and most organizations running agents do not have one.
Hand it to Infosec. That handoff is where the orchestrator’s security job ends, and it is a real boundary. Infosec can filter egress, watch a token’s use, and revoke a credential at three in the morning; Infosec cannot know which of the forty MCP servers on the inventory is load-bearing for the customer-email agent and which was installed for a demo in March. The orchestrator knows that and Infosec does not, and the reverse holds for everything past the boundary. An organization in which neither side has produced its half is the one where the next postinstall finds a wide token. What remains open is what a system built this way costs to run — isolation, short-lived credentials, and deterministic checks at every point of effect are not free — and that bill is the next constraint.
HQ 6 — Assembled. The human and AI each wrote portions of this chapter. I assembled, reviewed, and take responsibility for the whole; the voice and arguments are mine, and I know which parts are which.
- 5.1 What compromise looks like
- 5.2 The common controls, in stack order
- 14.2.1 The five controls against the real incidents
- 5.3 The supply chain of an agent
- 5.4 The approval-prompt problem
- 5.5 What security cannot do
- 5.6 The orchestrator’s security job is not Infosec’s job