Build the defender’s skills
Build the defender’s skills.
Same map as Maturity. This door is personal craft: gaps, path, proof. Guided by Hermes Agent.
Self-assessed only. Four concrete rungs per control. Nothing is saved. Not certification.
Live mastery check
Run it, don’t just read it.
The operator’s craft: personal mastery on the same map, four rungs per control, fitted skills from your gaps. Pick a seat above, then start or reassess on screen. Self-assessed; nothing saved.
Selected seat
Identity Security practitioner
16 prompts · four rungs per control
Sample skill readings
See a finished personal reading before you start.
A few finished personal readings. Every seat, plus board and standards lenses, lives in Reports.
Illustrative sample data, never client results. All reports →
The full model · optional
You already have what you need to start. Below is the map behind the seat, read it at whatever depth you want: the road, and the skills your seat builds on it.
The map, once
One straight road: seat to judgment.
You keep the seat you own. Two skill tracks build on top of it, deploy across your AI estate, and climb behind the gate. Read it top to bottom; the page below fills every band for the seat you picked.
Your seat today
one of nine practitioner seats. Kept, not replaced
Two tracks: the skills you build
Track 1 · Operate AI
shared by every seat
Track 2 · Secure AI
different per seat: your differentiation
Across your AI estate
Shared Security Responsibility Model: what you own, share, and inherit
Build this (owned)
you carry the control
Coordinate this (shared)
you hold the seam
Verify the provider (inherited)
the provider owns it; you check
Climb, safely
AI Security Maturity Model, L1 to L5
the ladder you climb
The gate
autonomy never outruns maturity
The Judgment layer
you, over a fleet of agents: the layer your title rises into
Every rung carries the Triad of Trust: Security · Safety · Privacy.
What reskilling adds
Two tracks on top of what you keep.
Your domain mastery stays. The two tracks are the addition, and together they are the delta: the exact skills to train next.
Track 2 · Security for AI
Defend the AI in your domain: the scarce skill. Different per seat.
Track 1 · AI for security
Operate AI in your own work: operator to manager of agents. Shared by every seat.
Retained · Domain mastery
What you already own. Kept, not replaced.
The delta is your curriculum
Control-mapped skills close the gap; the sections below name them for your seat.
Read it bottom-up: you build on what you already own.
What to learn · Identity Security practitioner
The skills this seat needs next.
The agent had read access. Somehow it wrote to production.
Composition is the blind spot: privileges that are safe apart combine into one that is not.
Start with these skills · gate-holders marked
01 · IAM-03
Inventory every identity, human or not
02 · IAM-04
Separate duties so no identity does it all
03 · IAM-05
Grant AI the least privilege it needs
04 · IAM-06
Provision access deliberately, including for agents
05 · IAM-07
Change and revoke access as fast as roles change
The rung you climb
Identity & Access Management (IAM)
Managing user authentication and authorization for AI applications and services across deployment types (self-hosted, PaaS, API/SaaS), non-human identities for AI agents and services, and customer identity workflows through AI applications. Includes chain of delegation and consent, identity chaining and transitive trust, credential scope, MCP and tool authorization, goal-based authorizations for autonomous agents, and enforcing least privilege.
AI Security Maturity Model rungs. Where the rubric cites the AI Controls Matrix, that is the control spine, not a second questionnaire.
Level 1
Initial
Level 2
Repeatable
Level 3
Defined
Level 4
Capable
Level 5
Efficient
The full rubric, rung by rung →
our model · calibrated to SAE J3016
Plays that climb the rung
Access-review assist
Run periodic access reviews: surface stale and excessive access, chase attestations to completion.
Autonomy must not outrun maturity. The gate holds each rung until its controls are evidenced. Eight gates, three lanes → · What securing AI takes →
Build one yourself · optional
The stack, if you want to build one.
Multi-agent orchestration is six layers deep, and each layer asks for a competence you can name, practise, and go and read about today. The full reference opens with the daily tools to master as a user, and carries every link.