ai · security · skills

Build the defender’s skills

Build the defender’s skills.

Same map as Maturity. This door is personal craft: gaps, path, proof. Guided by Hermes Agent.

Self-assessed only. Four concrete rungs per control. Nothing is saved. Not certification.

Live mastery check

Run it, don’t just read it.

The operator’s craft: personal mastery on the same map, four rungs per control, fitted skills from your gaps. Pick a seat above, then start or reassess on screen. Self-assessed; nothing saved.

Selected seat

Identity Security practitioner

16 prompts · four rungs per control

The full model · optional

You already have what you need to start. Below is the map behind the seat, read it at whatever depth you want: the road, and the skills your seat builds on it.

The map, once

One straight road: seat to judgment.

You keep the seat you own. Two skill tracks build on top of it, deploy across your AI estate, and climb behind the gate. Read it top to bottom; the page below fills every band for the seat you picked.

01

Your seat today

one of nine practitioner seats. Kept, not replaced

02

Two tracks: the skills you build

Track 1 · Operate AI

shared by every seat

Track 2 · Secure AI

different per seat: your differentiation

03

Across your AI estate

Shared Security Responsibility Model: what you own, share, and inherit

Build this (owned)

you carry the control

Coordinate this (shared)

you hold the seam

Verify the provider (inherited)

the provider owns it; you check

04

Climb, safely

AI Security Maturity Model, L1 to L5

the ladder you climb

The gate

autonomy never outruns maturity

05

The Judgment layer

you, over a fleet of agents: the layer your title rises into

Every rung carries the Triad of Trust: Security · Safety · Privacy.

What reskilling adds

Two tracks on top of what you keep.

Your domain mastery stays. The two tracks are the addition, and together they are the delta: the exact skills to train next.

Track 2 · Security for AI

Defend the AI in your domain: the scarce skill. Different per seat.

Track 1 · AI for security

Operate AI in your own work: operator to manager of agents. Shared by every seat.

Retained · Domain mastery

What you already own. Kept, not replaced.

The delta is your curriculum

Control-mapped skills close the gap; the sections below name them for your seat.

Read it bottom-up: you build on what you already own.

What to learn · Identity Security practitioner

The skills this seat needs next.

The agent had read access. Somehow it wrote to production.

Composition is the blind spot: privileges that are safe apart combine into one that is not.

Start with these skills · gate-holders marked

01 · IAM-03

Inventory every identity, human or not

02 · IAM-04

Separate duties so no identity does it all

03 · IAM-05

Grant AI the least privilege it needs

04 · IAM-06

Provision access deliberately, including for agents

05 · IAM-07

Change and revoke access as fast as roles change

The rung you climb

Identity & Access Management (IAM)

Managing user authentication and authorization for AI applications and services across deployment types (self-hosted, PaaS, API/SaaS), non-human identities for AI agents and services, and customer identity workflows through AI applications. Includes chain of delegation and consent, identity chaining and transitive trust, credential scope, MCP and tool authorization, goal-based authorizations for autonomous agents, and enforcing least privilege.

AI Security Maturity Model rungs. Where the rubric cites the AI Controls Matrix, that is the control spine, not a second questionnaire.

Level 1

Initial

Level 2

Repeatable

Level 3

Defined

Level 4

Capable

Level 5

Efficient

The full rubric, rung by rung →

our model · calibrated to SAE J3016

Plays that climb the rung

  • Access-review assist

    Run periodic access reviews: surface stale and excessive access, chase attestations to completion.

Autonomy must not outrun maturity. The gate holds each rung until its controls are evidenced. Eight gates, three lanes → · What securing AI takes →

Baseline Identity Security

Build one yourself · optional

The stack, if you want to build one.

Multi-agent orchestration is six layers deep, and each layer asks for a competence you can name, practise, and go and read about today. The full reference opens with the daily tools to master as a user, and carries every link.