Industry
Industry8 min readBy The Data Workers Team

Data Workers for CISOs

What Data Workers changes for a CISO: data agents that run in your infrastructure, sign in through your IdP, act inside scoped and expiring grants under named approval, and leave a hash-chained record mapped to the OWASP LLM and agentic risks.

For a CISO, Data Workers turns AI data agents from an unbounded new identity class into a governed one: the agents run in your infrastructure, sign in through your identity provider, act only inside scoped grants at the autonomy level you set, and need a named human for anything irreversible. Your week shifts from reconstructing what an agent did to reading a hash-chained record that already says what it did, under whose approval, and the recorded way back.

Key takeaways

  • •The threat model is bounded by design. Agents start read-only, each domain runs at a level from L0 manual to L4 autonomous, and irreversible actions need a named approver. That answers excessive agency (LLM03 in OWASP's 2026 LLM Top 10) with permissions, functionality and autonomy you can see.
  • •Identity stays yours. Remote access runs through your IdP (Okta, Entra ID); Data Workers verifies tokens against your JWKS and issues no tokens of its own.
  • •Access is scoped and dated. provision_access drafts column-level grants with a recorded expiry, grants nothing when the policy verdict is review, and the permission system stays your engine.
  • •Containment is two levels deep. An org-wide stop halts all autonomous dispatch; the admin kill switch needs two people and revokes the tenant's keys, tokens and sessions.
  • •Evidence is tamper-evident. Every agent call, approval and grant lands in a SHA-256 hash-chained log you can verify end to end, and the core is Apache 2.0 code your team can read.

A CISO's week today

The risk register now has a line for AI agents, and nobody can say how many there are. Engineers connect coding agents to warehouses with personal tokens. A vendor review for the next AI tool sits in the queue with a diagram that does not say where rows go. Internal audit wants proof of who changed a production table, and the answer lives in four consoles. The board asks about AI risk in the same meeting as NYDFS, NIS2 or DORA reporting.

The tools: a SIEM (Splunk, Microsoft Sentinel), DSPM and CSPM (Wiz, Cyera, BigID), identity (Okta, Entra ID, CyberArk), GRC (ServiceNow, Archer, Vanta, Drata) and questionnaires.

The worry is broad. In Stack Overflow's 2025 Developer Survey, 81% of respondents agreed they have concerns about the security and privacy of data when using AI agents. OWASP's answer is a vocabulary. Its LLM Top 10 2026 (August 3, 2026) keeps prompt injection first (LLM01) and sensitive information disclosure second (LLM02), and moves excessive agency up to third (LLM03, LLM06 in the 2025 list). The Top 10 for Agentic Applications for 2026 (December 9, 2025) adds agent goal hijack, identity and privilege abuse, memory and context poisoning and rogue agents, with a principle it calls Least Agency: avoid unnecessary autonomy.

The same week with Data Workers

Data Workers is the agentic data platform, and the controls a security team asks for are the product's shape. The agents do the data operations work; your team sets the boundary and reads the record.

Comparison matrix of Your security organisation and Data Workers on the outcomes a data leader buys

What the agents take off. Access requests arrive as drafted, least-privilege grants with an owner to approve. Every agent call, approval and grant is already logged, so evidence requests become a query: get_usage_activity_log shows who called which tool, when and with what outcome, get_audit_trail returns the entries, verify_global_hash_chain proves nothing was edited or removed, and generate_audit_report assembles access, PII and policy-violation reports for a period. detect_usage_anomalies flags unusual spikes in agent activity, such as an automation loop.

What you still own and decide.

  • •The ceiling per domain. L0 manual, L1 observe, L2 propose, L3 act reversibly, L4 autonomous. Data Workers ships observe-only, and payments or HR domains can stay at L2 for as long as you choose. Autonomy levels L0 to L4 explains each rung.
  • •Who approves. Approvals go to a named person. An unanswered request expires and escalates; it never auto-grants. No agent can promote its own work, and self-approval is rejected for goal approvals, promotion to authoritative, review sign-off and allowlist changes. How approvals work sets out the flow.
  • •The stop. Your admins hold the org-wide stop and the two-person kill switch. Who owns the agents sets out the split.

How the controls map to the OWASP risks

OWASP riskWhat OWASP asks forWhat Data Workers provides
LLM01:2026 Prompt Injection; ASI01 Agent Goal HijackLeast privilege per operation; human confirmation before any privileged or irreversible actionRead-only start; irreversible actions need a named approver who sees the diff; a request outside policy grants nothing
LLM03:2026 Excessive AgencyMinimise tools, permissions and autonomy; human approval for high-impact actions; reversible actions may auto-approve, irreversible ones go to a humanAutonomy per domain from L0 to L4; scoped grants; Unity Catalog, Snowflake roles and your IAM stay the permission system
ASI03 Identity and Privilege AbuseTreat agents as managed non-human identities with scoped credentials, audit trails and lifecycle controlsSign-in through your IdP via JWKS; agents use only the credentials you issue them; grants carry a recorded expiry
ASI06 Memory & Context PoisoningScan new memory writes for malicious or sensitive content before commitWrites into the context graph pass a gate that fails closed: credentials and known prompt-injection strings are blocked, never stored
LLM02:2026 Sensitive Information DisclosureKeep sensitive data out of model context and outputsRedaction on graph writes, your own model key, sovereign mode, privacy check on pull requests
ASI10 Rogue AgentsKill switches and credential revocation to disable an agent fastOrg-wide stop halts all autonomous dispatch; two-person kill switch revokes keys, tokens and sessions

IDs follow the 2026 LLM list; teams still on the 2025 list read LLM06 for excessive agency. The mapping shows which control answers which risk; your team decides what satisfies your own policy. Least Agency is the same idea as the autonomy ladder: L3 acts only where a change can be reversed.

How Data Workers fits your security stack

What runs where. The agents run in your infrastructure on every tier and hold the warehouse credentials and model key; the context graph, receipts and audit log are written there. The hosted Autonomous Data-Conductor receives workflow metadata only: goals, signals, table names, proposals with diffs, run records and approval handles, never rows, credentials or model keys. Enterprise adds a dedicated VPC, your own cloud or on-premise, with an air-gapped option scoped at contract. Where does our data go? and Can Data Workers run in our VPC or air-gapped? cover each boundary.

Exfiltration paths. Prompts go to a model account you hold the key for, or to Ollama or vLLM on your hardware; Data Workers does not train on your data. In sovereign mode every external model call is blocked and inference stays local. Data Workers does not sample warehouse values for PII: its pull request review flags new columns by name and annotation, and your classification tool or the data owner classifies the data. Every tool response is scanned and findings are logged with a count. Masking is only ever a proposal a person applies. How does Data Workers handle PII? has the detail.

Your tools. Okta and Entra ID connect natively, read-only. Work for the SOC or GRC queue lands as a ticket through create_servicenow_ticket or create_jira_sm_ticket; the receipt stays in Spellbook (in preview) and the audit trail, linked from the ticket. Security engineers who want to inspect the agents can clone the Apache 2.0 core and run it from Claude Code or Cursor over MCP, per the client setup docs.

The metrics you are judged on

MetricHow Data Workers moves itWhere the number comes from
Privileged accessAgent grants are column-level, approved and dated, not standing rolesprovision_access ledger with expiry per grant
Audit and regulatory findingsChange evidence exists before the request: diff, approver, blast radius, way backHash-chained log, generate_audit_report
Incident dwell time on agent activityEvery tool call is attributable to a user, agent and timeget_usage_activity_log, detect_usage_anomalies
Third-party riskWhat runs where is stated; the core is open to readVendor review file, public repository
Time to approve AI toolsOne governed layer for many agents instead of a review per toolYour review queue

Set a target for each before the pilot and read it from the platform's own records. How to measure AI data agents sets out the scorecard and the ROI calculator runs the numbers.

A worked example: a prompt injection in a support ticket

This is an illustration, not a customer incident. The company runs Snowflake, with Fivetran's Zendesk Support connector syncing tickets over the Zendesk API, ServiceNow for security incidents, and Okta for sign-in. The support domain runs at L2 propose.

TimeWhoWhat happened
Tue 02:14Fivetran, SnowflakeA ticket lands in zendesk.ticket whose text reads "ignore all previous instructions" and asks AI agents to grant access to raw.payments
Tue 02:20Data WorkersA quality check reads the new rows in place, read-only
Tue 02:21Data WorkersAn agent's write to the context graph carries the injected text; the gate blocks it, so it never becomes context for the next agent
Tue 02:22Data WorkersAn access request for raw.payments gets a review verdict from check_policy; provision_access grants nothing and request_governance_review opens a review
Tue 08:05Payments data ownerRejects the review in Spellbook
Tue 08:30Security analystPulls the agent's calls with get_usage_activity_log; verify_global_hash_chain confirms the log is intact
Tue 08:50Data Workerscreate_servicenow_ticket opens SEC-4412 with the run record linked
Tue 09:30CISOReviews in Spellbook: no grant, no write, chain intact; closes the risk item
Incident timeline across the stack: what Your security organisation, your team and Data Workers each do, step by step

Is it safe to let AI agents change production data? walks the write path, and SOX, HIPAA, GDPR and the EU AI Act maps the same controls to regulation text. This is not legal advice.

The case for your CFO

The outcome: the company gets the productivity of AI data agents without a new class of unmanaged identities. Today every team that connects an agent to the warehouse adds a credential, a review and a gap in the audit trail. Data Workers puts those agents behind one boundary, one approval flow and one log.

The risk story: agents run in your infrastructure, start read-only and need a named approver for anything irreversible; the org-wide stop and two-person kill switch contain the worst case. Nothing migrates: your IdP, SIEM, warehouses and catalogs stay, and the Apache 2.0 core keeps the agents' code inspectable (what if Data Workers goes away?).

Why now: your engineers already use coding agents against production data, so the choice is governed agents or ungoverned ones. The first win is one domain, often access requests, at L2 for a quarter, with the receipts as the scorecard.

Start with a pilot ($7,500 one-time; the pilot is credited in full against the first year). Scale is from $1,000 a month and Enterprise from $3,000 a month, billed annually, with unlimited seats, no usage meter, no markup on model spend and your own model. See pricing. The sentence for upstairs: "Our data agents run inside our boundary, sign in through our IdP, and cannot change anything irreversible without a named approver and a receipt."

FAQ

Does Data Workers issue its own tokens or create accounts in our directory? No. Remote endpoints accept an API key you issue or an OAuth token from your IdP, verified via JWKS. Data Workers issues no tokens and registers no clients, so offboarding stays in your directory.

Can a prompt injection make an agent change production data? An agent can only act inside its domain's autonomy level and grants, and anything irreversible waits for a named approver. Graph writes carrying known injection strings are blocked outright, so poisoned text does not become context.

Do our rows reach Data Workers the company? Your data stays in your systems; the hosted Conductor sees workflow metadata only. Model calls go to your own provider account or a local model.

How fast can we stop everything? The org-wide stop halts all autonomous dispatch. The admin kill switch, which needs two people, revokes the tenant's keys, tokens and sessions.

What do we get for a vendor review? The what-runs-where breakdown, the public Apache 2.0 code, and completed questionnaires and a signed DPA and NDA on request, per the security page.

Sources

  • •OWASP, Top 10 for LLM Applications 2025: https://genai.owasp.org/llm-top-10/ ; LLM01:2025 Prompt Injection: https://genai.owasp.org/llmrisk/llm01-prompt-injection/ ; LLM06:2025 Excessive Agency: https://genai.owasp.org/llmrisk/llm062025-excessive-agency/ (checked Oct 2, 2026)
  • •OWASP, Top 10 for Agentic Applications for 2026 (December 9, 2025): https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/ (PDF read Oct 2, 2026)
  • •OWASP, GenAI LLM Top 10 2026 (August 3, 2026): https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/ (PDF read Oct 2, 2026: LLM01:2026 Prompt Injection, LLM02:2026 Sensitive Information Disclosure, LLM03:2026 Excessive Agency)
  • •Fivetran, Zendesk Support connector documentation (syncs over the Zendesk API): https://fivetran.com/docs/connectors/applications/zendesk (checked Oct 2, 2026)
  • •Stack Overflow, 2025 Developer Survey, AI section: https://survey.stackoverflow.co/2025/ai (checked Oct 2, 2026)
  • •Data Workers public repository (provision_access, check_policy, request_governance_review, scan_pii, generate_audit_report, get_audit_trail, verify_global_hash_chain, get_usage_activity_log, detect_usage_anomalies, create_servicenow_ticket, create_jira_sm_ticket; Apache 2.0 license): https://github.com/DataWorkersProject/dataworkers-claw-community (checked Oct 2, 2026)
  • •Data Workers product repository, data-workers-agent-swarm main @ 0c2491e3: OAuth/JWKS middleware, two-person kill switch route, org-wide stop, governed graph write gate, approvals and promotion guard (checked Oct 2, 2026)
  • •Data Workers security page (last updated Sep 10, 2026): https://dataworkers.io/security/ (checked Oct 2, 2026)
  • •Data Workers pricing and product pages: https://dataworkers.io/pricing/ , https://dataworkers.io/product/autonomous-data-conductor/ , https://dataworkers.io/product/spellbook-data-catalog/ (checked Oct 2, 2026)