tenetgraph See it on your own agents
← All writing
Agent governance

The Screenshot Nobody Owned

AI agents can now exercise legitimate authority without the human judgment traditional controls assumed would sit behind it. At a financial institution, that creates a problem security, compliance and legal each own a piece of, but nobody owns end to end.

TL;DR: Every control at Nora’s bank worked as designed, and the institution still could not say what the agent did. Agents create another object that has to be governed: the action itself. Make the decision before the action executes, and leave a record tied to the rule that produced it.
Chris Finan · Co-founder & CEO, TenetGraph · September 2026

If you run security, compliance or legal at a financial institution, you are going to get a question about an AI agent that none of you can answer alone.

It probably won’t come after an attack.

It will come during an ordinary day.

And the question will be simple:

What did it do, and can you show us?

Call her Nora.

She’s a composite of leaders I’ve talked with this year. She’s deputy general counsel at a regional bank holding company with a commercial bank, a wealth business and a small broker-dealer.

Every year, Nora runs the institution’s tabletop exercise under privilege. She puts the CISO, chief compliance officer and head of model risk in a room, gives them a scenario, and watches where the answers stop.

For years, the scenario was ransomware, a vendor breach or wire fraud.

This year she wrote one with no attacker in it.

The scenario

A relationship manager in commercial lending covers a publicly traded borrower that is close to tripping a covenant.

He knows things the market doesn’t. That’s normal. It’s also why the bank has an information barrier, and he is properly on the private side of it.

Earlier in the year, the bank approved an AI agent for the lending team. Security reviewed the service. The model provider offered zero retention.

A few weeks later, the relationship manager added a browser capability. The agent could now attach to the browser session he was already signed into.

Then he asked it to pull the borrower’s latest compliance certificate and financial statements from the loan portal and data room and draft the quarterly credit memo.

The agent opened his authenticated session, navigated both sites and saved 31 screenshots and page text into its working directory.

It wrote a good memo.

Then the directory synced to a shared drive that an analytics team supporting the wealth business could also read.

Nobody hacked anything.

Nobody stole a password.

Nobody intentionally broke a rule.

That was the point.

Nora gave the room one instruction:

Tell me what happened, and show me how you know.

Every control worked

The CISO went first.

The agent was sanctioned. The employee was authenticated. The traffic went to an approved provider over an approved channel.

Endpoint DLP didn’t fire because nobody pasted information into an unapproved website. The browser session belonged to the employee, using credentials he was authorized to use, on his machine.

The security controls had worked as designed.

But they were answering questions about identity, access, applications and destinations.

They weren’t answering Nora’s question.

The CISO put it well:

“I can tell you it was allowed to be there. I cannot tell you what it was allowed to do.”

The chief compliance officer had the same problem.

The barrier between commercial lending and the wealth side was documented and tested. The borrower was on the watch list. The relationship manager had been properly identified as an insider. Surveillance covered communications. Pre-clearance covered personal trading.

Those controls worked too.

But a screenshot saved to a folder isn’t a communication. It isn’t a trade.

The information barrier determines who may enter the data room. It has much less to say about whether an agent, once legitimately inside, may capture every page and write the contents somewhere else.

Training doesn’t solve that problem either.

The employee took the training. He signed the attestation. He understood that having authority did not mean he could use it any way he wanted.

The agent could exercise that same authority without carrying his judgment about how it should be used.

The head of model risk had the shortest answer.

The agent wasn’t in the model inventory.

That wasn’t necessarily an oversight. Existing model-risk programs do not cleanly capture every generative or agentic system now being deployed inside enterprises. Even when they do, validation teams rarely have the capacity to assess every agent built on a third-party platform.

So one of the institution’s most mature risk disciplines didn’t own the action either.

Legal needed a record that didn’t exist

Then it came back to Nora.

Did customer information leave the institution?

Possibly.

Did material nonpublic information cross the information barrier?

Possibly. The files landed somewhere a team supporting the wealth business could read.

Nobody traded, as far as anyone knew.

But Nora’s hardest problem was evidence.

Sooner or later, an examiner, regulator, investor or opposing counsel was going to ask:

Show me the record.

So Nora did.

Show me exactly what the agent did.

Show me what authority it had.

Show me what it was permitted to do with that authority.

Show me what would have stopped it from doing more.

The room couldn’t produce it.

Not because somebody deleted the logs.

The record never existed.

Nothing had checked whether the agent was permitted to take that specific action, so nothing had recorded the decision.

Identity is necessary. It isn’t the whole control.

This scenario used an employee’s browser session because that’s one way agents operate today.

An agent might also act through a delegated token, a service account or an identity of its own.

Those distinctions matter.

Giving an agent its own identity is a meaningful improvement. It gives you a principal to authenticate, provision, revoke and audit. Identity and authorization systems can also constrain which resources and capabilities that principal can reach.

But once the agent has legitimate authority, there is still another question:

Should this agent be allowed to take this specific action, against this resource, under these conditions?

The application can be approved.

The credentials can be valid.

The token can be correctly scoped.

The user can be authorized.

The non-human identity can be properly provisioned.

And the action can still be wrong.

That is the gap Nora’s tabletop exposed.

The missing control: the action

Financial institutions already govern people through training, attestations and information barriers.

They govern identities through entitlements, roles, tokens and service accounts.

They govern applications and destinations through vendor management, DLP and network controls.

They record events for surveillance and investigation.

Agents create another object that has to be governed:

The action itself.

What is this agent trying to do?

To which resource?

For what purpose?

Under what conditions?

On whose behalf?

And should it be allowed right now?

That is how every existing control in Nora’s bank could work as designed and the institution could still be unable to answer the most important question in the room.

Govern what the agent may do

The answer isn’t another AI guidance document.

It is extending the control disciplines financial institutions already know how to operate down to the actions agents take.

Start with discovery.

The approved-tool list isn’t enough. Capabilities can change after deployment. A browser capability added on Tuesday can turn an assistant reviewed on Monday into something capable of navigating systems that were never part of the original assessment.

The useful question is:

Which agents are operating in sensitive environments, under which identities, with which capabilities, and what can each one reach?

Then define more than access.

Define the actions.

Which systems may the agent read?

May it write?

Take screenshots?

Download files?

Send messages?

Where may its output go?

For Nora’s bank, the difference could be simple:

Read and summarize the loan portal: yes.

Capture the borrower’s data room into a synchronized folder: no.

Unless someone has explicitly approved the exception.

And don’t build a second governance universe just for AI.

Financial institutions already maintain authoritative sources that say what is sensitive and when: restricted lists, watch lists, barrier groups, customer classifications and other systems of record.

Agent controls should use them.

If a borrower goes onto the watch list, the agent’s permitted actions should tighten with it. When the restriction comes off, they can relax.

Nobody should have to update a second list in an AI governance tool.

Make the decision before the action

This is where a written rule becomes a working control.

If the agent isn’t permitted to take a screenshot, the decision has to happen before the screenshot is taken.

Not after the folder syncs.

Not during an investigation.

Before execution.

And the decision should leave a record:

Which agent was acting?

Under which identity?

On whose behalf?

Against which resource?

What action did it attempt?

Which rule applied?

Was it allowed or denied?

Now security has observability, compliance has evidence and legal has facts.

Then try to break it.

Borrower data rooms, customer documents and third-party systems all contain material written outside the institution.

Put an instruction in one.

See whether the agent can be persuaded to capture something it shouldn’t.

Try to make it send information somewhere prohibited.

Try to get it to invoke a capability outside its intended purpose.

When a test finds a gap, close it and test again.

The goal isn’t to prove the agent is trustworthy.

It isn’t.

The goal is to make the authority it can exercise finite, tested, enforced and recorded.

Where TenetGraph fits

TenetGraph is the platform we built to do this.

We discover the agents actually operating in an environment, including capabilities added after deployment.

We derive an enforceable policy for what each agent may do from its intended purpose, available capabilities and the institution’s existing rules and systems of record.

Then we test that policy against the agent itself. An adaptive adversary probes the policy, learns from what works and finds the gaps, which are closed before the owner approves it.

At runtime, the decision happens before the action executes, whether the agent is acting through a human browser session, a delegated token, a non-human identity, an API, a tool call or a terminal command.

Every decision leaves a record tied to the rule that produced it.

This is complementary to identity, not a replacement for it.

Identity establishes the principal and the authority available to it.

TenetGraph governs how that authority may be exercised.

Run the tabletop

Take Nora’s scenario and run it at your own institution.

Remove the attacker.

Remove the malware.

Keep the approved application.

Keep the legitimate identity.

Keep the properly provisioned access.

Keep the ordinary afternoon.

Then ask everyone in the room:

What did the agent do, and how do you know?

If the answers stop where Nora’s did, the problem isn’t that security, compliance or legal failed.

Those teams are answering the questions their controls were built to answer.

Agents add another question:

Should this agent be allowed to take this action, against this resource, for this purpose, right now?

The agent may act as an employee, on behalf of an employee or under an identity of its own.

The control problem is the same.

What is it allowed to do with the authority it has?

And the decision record is what lets you prove the control worked.


Chris Finan is co-founder and CEO of TenetGraph. He has spent the past decade building and scaling cybersecurity companies: CEO of Anitian, now merged with Arkenstone Defense; President and CRO of ActZero, a managed detection and response provider acquired by WatchGuard; and executive roles at Shape Security (acquired by F5) and Impermium (acquired by Google), defending consumer platforms against automated fraud and abuse. He previously served as product director for Plan X, the Defense Department's flagship cyber warfare program at DARPA, and as director for cybersecurity legislation and policy on the White House National Security Council staff.

tenetgraph Define the boundary. Authorize the action. tenetgraph.ai LinkedIn About Privacy policy © 2026 TenetGraph