AI agents can reach and move data on a person’s behalf. The same automated action may be routine in one context and a warning sign in another. For partners, Incydr and Agent Risk Center give a concrete way to discuss agent security through the familiar lens of human insider risk.
Why an agent action needs human context
Picture two employees whose AI agents each pull a large report from a customer relationship management system. One is carrying out a routine task and has no signs of risky data movement. The other has recently sent sensitive files to a personal destination and is preparing to leave the business. The agent’s activity looks similar; the context around the person does not.
Treating both events alike can create unnecessary friction for normal work or miss a warning that deserves attention. Mimecast’s approach connects agent activity to the person behind it, so security teams can assess behaviour and decide whether to allow, warn, hold or investigate. A raw event count says little about intent. Behaviour around the action gives security teams a better basis for deciding what to do.
Mimecast groups agent risk in three familiar categories: accidental, compromised and malicious. An employee might accidentally give an agent access to data it does not need. A threat actor could compromise an agent and use it to reach valuable information. A malicious insider could direct an agent to collect or expose sensitive data. Each call for a different response. A blanket block may not be the right answer.
How Incydr and Agent Risk Center fit together
Incydr provides a human-risk view of data activity. Agent Risk Center extends that view to AI tools and agents, linking agent activity to the person who deployed it. Teams can then review an agent event alongside wider insider-risk signals instead of investigating it on its own.
Agent Risk Center is in early access. The early-access offer includes a unified inventory of agents, AI tools and MCP connections, a link between each agent and the person who deployed it, department-level visibility, the AI Rulebook for acceptable-use policies, and adaptive controls that can nudge, warn or block based on risk. For a customer, the practical job is to see what is in use, link each agent to its owner and choose a response that fits the risk.
Partners can move beyond a yes-or-no question about AI approval and ask how customers will govern actual use. Customers can explore how to make sanctioned use workable while improving visibility of unsanctioned tools, connections and activity. Because Agent Risk Center is in early access, confirm current availability and feature scope with Mimecast before setting customer expectations.
Questions MSPs can take to customers
Start with the customer’s current environment and the decisions they need to make. These questions can help uncover whether there is a real agent-governance conversation:
- Can you see which AI tools, agents and MCP connections are active in your environment?
- Do you know who deployed each agent and what information it can reach?
- How do you distinguish routine agent activity from activity that needs investigation?
- If the risk changes, can you respond with a warning, a block or a closer review?
Listen for uncertainty about ownership, visibility or policy. Existing employee, endpoint or cloud controls may leave a practical question unanswered: how does the customer account for AI agents acting on people’s behalf? That opens a conversation about human behaviour and agent activity together.
Recent AI adoption, questions about acceptable-use policy, an upcoming restructure or concern about sensitive data leaving the business can all prompt the conversation. Keep it grounded in the customer’s own environment: which data matters, which tools are in use, and what would make an event worth investigating?
Make agent risk a practical customer conversation
AI agent security does not need to begin with a sweeping prediction about automation. Start with a clear operational question: can the customer tell the difference between an agent carrying out expected work and one acting in a risky context? Incydr and Agent Risk Center give partners a way to explore that question with customers, connect it to insider-risk discussions they already understand, and identify where further product detail is needed.
To find out more, contact the Mimecast Team at Infinigate Cloud at mimecast@infinigate.cloud