M7 · HOW I RUN MY DAY · OP3
The Security Stack Playbook
6 SLIDES
·
~8 MIN
·
PLAYBOOK OVERVIEW
Key Takeaways
- No agent ever sees the whole vault.
- 90% — of AI agents are over-permissioned — they hold rights they never use.
- 3 of 10 — OWASP Agentic Top 10 risks tied directly to identity, secrets, and over-scoped access (LLM06, LLM07, LLM08).
- 30 days — is the rotation cadence that catches drift before an auditor or attacker does. Calendar-locked, not best-effort.
- Inventory every secret an agent currently has access to. Most CEOs find at least one that surprises them.
OP3 · Questions CEOs Ask
Frequently Asked Questions
- What is the core idea of The Security Stack Playbook?
- No agent ever sees the whole vault.
- What does the data say a CEO should pay attention to?
- 90% of AI agents are over-permissioned — they hold rights they never use. 3 of 10 OWASP Agentic Top 10 risks tied directly to identity, secrets, and over-scoped access (LLM06, LLM07, LLM08).
- What should a CEO do Monday morning after reading The Security Stack Playbook?
- Start here: Inventory every secret an agent currently has access to. Most CEOs find at least one that surprises them; Pick a secret manager (Infisical, 1Password, Vault). Move every plaintext secret out of code and out of env files this month; Split your vaults vertically. Email creds in one. Cloud creds in another. Refuse to merge them.
- What are the steps in The Security Stack Playbook?
- 1) Bootstrap key stays offline; 2) Vertical vaults, not horizontal; 3) Machine identity per agent; 4) Separate accounts for separate blast radii; 5) Monthly audit, calendar-locked.
- Where do the claims in The Security Stack Playbook come from?
- The playbook cites Infisical machine identity model; OWASP Agentic Security Initiative; OWASP Agentic Security Initiative — over-permissioned agents; Infisical — machine identity for agents.
OP3 · Sources
All Sources in This Playbook
- Infisical machine identity model
- OWASP Agentic Security Initiative
- OWASP Agentic Security Initiative — over-permissioned agents
- Infisical — machine identity for agents
BuildClub · Work Together
Ready to lock your AI secrets behind a proper vault?
BuildClub works with mid-market CEOs on the security stack — bootstrap keys, vertical vaults, machine identity, and monthly audits.