- Rapid7 says security tools built around users and devices may not capture AI agents delegating tasks to other agents, which limits visibility and accountability.
- The issue is a chain of actions with no clear owner. Rapid7 names five challenges, including delegation limits and fragmented logs.
- Rapid7 advises auditing agents, using temporary task-scoped credentials and standardising logs. This is vendor guidance, not incident data.
One request, several actors, one question
After an incident, security teams ask a simple question: who did this? With autonomous AI agents, the answer can be a chain.
A person asks one agent for help. That agent hands part of the job to a second agent. The second agent queries a production database and sends a summary to outside systems.
Rapid7 describes this scenario in a post published October 6. It says traditional controls may struggle to capture the whole interaction. Teams may lack visibility into intent, delegation chains and the scope of each agent's authority.
Here is the idea to hold onto. The unit of accountability is shifting. It used to be the person or the device. It is becoming the chain of hand-offs between them. A log that shows who signed in says little about who decided.
How the gap opens
In Rapid7's scenario, the second agent reaches the database through the Model Context Protocol. This is a standard way for agents to connect to tools and data.
Each step may be logged by a different system. The formats may differ. No single record may show the whole path.
Rapid7 lists five problems that follow.
First, identity and delegation. An agent's identity must be verified. The authority it passes on must never exceed what the initiating user could do.
Second, behavioural drift. Agents change their route as they work. That makes it hard to tell normal variation from compromise or prompt injection. Prompt injection means hiding instructions in content so an agent follows them.
Third, tool and protocol abuse. An agent that calls tools on its own can become an unwitting route for data exfiltration or unauthorised actions if guardrails are weak.
Fourth, cascading access. A compromised high-privilege agent can influence other agents. That can widen access across connected systems.
Fifth, observability. Fragmented API logs may not rebuild a multi-agent decision path. They may not explain why an action happened.
A familiar problem in a new form
Picture a contractor who passes a job to a subcontractor. The subcontractor hands a key to someone else. The front-desk sign-in sheet records only the first name. Physical sites rely on scoped access and records of each hand-over. Agents need a digital version of that.
Rapid7's answer is to treat agents as identities in their own right. Each has its own permissions, behaviour and activity to monitor.
In practice, agents would become entities in the investigations analysts already run. Records of which agent called which tool, and what data it touched, would sit beside login, endpoint and network logs. An analyst could then read one timeline that begins with the person who made the request.
Rapid7 also proposes extending User Behavior Analytics to Agent Behavior Analytics. Teams would first set a baseline for normal agent behaviour. Detection would then flag oddities. Examples are unexpected agent-to-agent contact, sudden privilege jumps and unusually large transfers.
Authorization gateways can enforce preventive rules where agents act.
Read it as guidance, not evidence
This is a vendor blog post. It cites no breach, survey or measurement of how often these failures occur.
One of its four recommendations is to send agent event data to Rapid7's own platform. Rapid7 also says agent-to-agent security is still evolving.
That limits what a reader can conclude. The post offers a sound way to frame the problem. It does not show how large the problem is today.
Questions to put to your team
Rapid7's first three steps do not depend on any product. Ask whether your team can answer them.
Do we have a list of every AI agent in use, custom or third-party? Does it show each agent's communication paths and tool access?
Do agents act on temporary, task-scoped credentials? Or do they hold persistent administrative permissions?
Do our logs capture delegation between agents, tool calls and dataset access in a structured form?
Then run one test of your own. This is WebPulse's suggestion, not Rapid7's. Pick a recent agent action. Ask your security team to reconstruct who started it, which agents touched it and what data moved.
If that takes days, or cannot be done, you likely have a version of the gap Rapid7 describes. Slow reconstruction can have other causes, so treat it as a prompt for questions, not a verdict.
An agent that acts for someone needs an owner on the record. Without that record, it becomes hard to say who answers for what it did.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Rapid7.





