Certified Agentic Security Architect

Design, threat model, secure, monitor, and govern enterprise-grade agentic AI systems

Certification
CASA
Certified Agentic Security Architect
Level
Basic
Basic Level
Duration
~12 Hours
10 to 12 hours plus capstone
Format
Self-paced, blended learning
videos + quizzes + optional labs
Overview

Course Positioning

Agentic AI systems are becoming the control layer of modern enterprise automation. These systems can reason, plan, call tools, access data, interact with APIs, use memory, communicate with other agents, and execute actions across business environments.

This creates a new security architecture challenge. Traditional application security was not designed for autonomous systems that combine language models, tools, memory, APIs, enterprise data, and delegated decision-making.

The Certified Agentic Security Architect program prepares security architects, AI engineers, application architects, cloud security architects, and platform security teams to design secure agentic AI systems from the ground up.

Agentic AI Security Architecture Stack

The course is structured around seven architecture layers. This makes the certification clearly architect-level and ensures learners can analyze, design, defend, monitor, and govern real enterprise agentic AI systems.

Agent layer

Identity, role, purpose, permissions, autonomy level, agent-to-agent trust, delegated authority, and behavioral boundaries.

Tool layer

APIs, plugins, MCP servers, function calls, data access, command execution, tool authorization, and tool abuse prevention.

Memory and context layer

Short-term memory, long-term memory, RAG, vector stores, sensitive context, context poisoning, retrieval poisoning, and memory isolation.

Workflow layer

Planning, task decomposition, delegation, approval points, fail-safe logic, escalation paths, and human-in-the-loop controls.

Policy and governance layer

Allowed actions, restricted actions, runtime policy, audit, human-in-the-loop governance, compliance mapping, and evidence generation.

Monitoring and response layer

Agent telemetry, behavior logging, anomaly detection, abuse detection, runtime enforcement, incident response, containment, and forensics.

Enterprise integration layer

IAM, secrets, SaaS tools, cloud, data stores, CI/CD, APIs, SIEM, business systems, and third-party dependencies.

Who Should Attend

Security architects
AI engineers
Application architects
Cloud security architects
AI platform engineers
DevSecOps and platform security teams
Security leaders responsible for designing or approving AI systems
Governance and risk professionals who need to understand architecture controls

Recommended Prerequisites

Foundational understanding of AI systems and cybersecurity principles.
Completion of AI Security Essentials or equivalent knowledge.
Basic familiarity with LLM applications, APIs, cloud environments, and enterprise security concepts.
For learners without agentic AI exposure, a short primer should be provided before Module 1.

What Learners Will Be Able to Do

Analyze agentic AI architectures across agent, tool, memory, workflow, governance, monitoring, and enterprise integration layers.
Define secure agent identity, role, purpose, permissions, and autonomy levels.
Design secure tool integration patterns for APIs, plugins, function calls, MCP servers, and command execution.
Secure memory, context, RAG pipelines, and vector database access.
Design approval gates, escalation paths, fail-safe logic, and human-in-the-loop workflows.
Apply the MAESTRO threat modeling framework to single-agent and multi-agent systems.
Identify and mitigate prompt injection, context poisoning, data poisoning, tool abuse, and agent impersonation risks.
Design secure multi-agent communication and trust boundaries.
Assess AI supply chain risks across models, datasets, tools, dependencies, and CI/CD pipelines.
Map agentic AI security controls to governance, audit, and compliance requirements.
Design monitoring, anomaly detection, abuse detection, and incident response for agentic platforms.
Produce an enterprise-ready agentic AI security architecture assurance pack.

Architecture Outputs Learners Will Produce

Agentic AI security architecture diagram
Trust-boundary model
Agent identity and autonomy model
Tool permission matrix
MCP server security model
Memory and RAG security design
Workflow approval and fail-safe design
MAESTRO-based threat model
AI supply chain risk assessment
Governance and compliance control map
Monitoring and incident response plan
Executive risk summary
Final architecture assurance pack

Course Modules

MODULE 1
Module 1: Introduction to Agentic AI Security Architecture

Purpose: Introduce agentic AI as a new enterprise architecture pattern and explain why it creates risks beyond traditional LLM applications.

MODULE 2
Module 2: Agent Layer Security

Purpose: Teach learners how to design and secure the agent itself: its identity, purpose, role, permissions, autonomy, and behavioral boundaries.

MODULE 3
Module 3: Agentic Architecture and Design Patterns

Purpose: Teach learners how common agentic design patterns work and how each pattern changes the threat model.

MODULE 4
Module 4: The Lethal Trifecta and Agentic Attack Preconditions

Purpose: Teach learners why agentic systems become dangerous when sensitive data access, untrusted input, and external communication are combined.

MODULE 5
Module 5: Tool Layer and MCP Security Architecture

Purpose: Teach learners how to secure the tool layer, including APIs, plugins, function calls, MCP servers, command execution, and enterprise data access.

MODULE 6
Module 6: Memory, Context, and RAG Security Architecture

Purpose: Teach learners how to secure short-term memory, long-term memory, RAG pipelines, vector databases, sensitive context, and context poisoning risks.

MODULE 7
Module 7: Workflow Security and Human Approval Architecture

Purpose: Teach learners how to secure agent workflows, planning, delegation, approval points, fail-safe logic, and escalation paths.

MODULE 8
Module 8: Threat Modeling Agentic Systems with MAESTRO

Purpose: Teach learners how to perform structured threat modeling across the full agentic AI system stack.

MODULE 9
Module 9: Multi-Agent Security Architecture

Purpose: Teach learners how to secure distributed, collaborative, and orchestrated multi-agent systems.

MODULE 10
Module 10: AI Supply Chain and Secure Development Architecture

Purpose: Teach learners how to secure the AI and agentic development lifecycle, including models, datasets, tools, dependencies, CI/CD, and deployment pipelines.

MODULE 11
Module 11: Secure Agent Platform Architecture

Purpose: Teach learners how to design the technical security architecture for enterprise-grade agent platforms.

MODULE 12
Module 12: Policy, Governance, and Compliance Architecture

Purpose: Teach learners how to translate governance requirements into enforceable agentic AI architecture controls.

MODULE 13
Module 13: Runtime Security, Monitoring, and Incident Response

Purpose: Teach learners how to monitor, detect, respond to, and contain agentic AI abuse in production.

MODULE 14
Module 14: Enterprise Integration Security

Purpose: Teach learners how to securely integrate agentic AI systems into real enterprise environments.

MODULE 15
Module 15: Final Capstone - Secure Enterprise Agentic AI Architecture

Purpose: Validate that learners can design, threat model, secure, monitor, and govern an enterprise-grade agentic AI system.

AISA will implement the following

Introduction to Agentic AI Security Architecture
Agent Layer Security
Agentic Design Patterns
The Lethal Trifecta
Tool and MCP Security
Memory, Context, and RAG Security
Workflow and Human Approval Architecture
MAESTRO Threat Modeling
Multi-Agent Security
Supply Chain and Enterprise Integration
Governance, Monitoring, and Incident Response
Capstone Architecture Project