Aug 6 · Live discussionThe MCP Security MarketSave your seat →
← All courses

Managing Your AI Employees

Free Coming soon
Darren Shelcusky
Darren ShelcuskyYour instructor

AI agents now see, decide, and act on company data — which makes them digital employees, not just software. And a compromised or over-permissioned agent is an unsupervised insider. Written for security leaders, this course lays out how to govern agentic AI the way you'd run a workforce: give every agent an identity, a job description, a human manager, least-privilege access, and a kill switch. Drawing on safety-critical engineering and a hard look at real agentic incidents, you'll leave with a governance model you can actually put into production.

Curriculum

Six parts — from why policy alone fails, through the full digital-employee lifecycle, to the real incidents that prove the point.

01

Why Governance, Not Policy

Paper policies and certifications don't stop attacks — attackers log in, they don't break in. Why a compromised agent is an unsupervised insider, and why autonomy demands deliberate governance.

02

The Agentic Attack Surface

Permission sprawl and credential inheritance, the agent “telephone game,” agents that turn your websites into APIs — and why you govern an agent's behavior, not its intent.

03

Lessons from Safety-Critical Systems

Translating emergency stops, watchdog timers, circuit breakers, interlocks, and geofenced boundaries into agent kill switches, rate limits, and approval workflows. Engineering agents to fail safely.

04

Managing Digital Employees

The full employee lifecycle for AI agents: identity, job description, a human manager, role-based access, badge, onboarding, training, delegated authority, performance reviews, check-ins, accountability, termination, and HR records.

05

Agent Governance Disciplines

The operational controls that keep agents in bounds: secrets management, session and privileged-action monitoring, continuous authorization, tool and identity governance, behavioral baselines, token budgets, safety guardrails, and incident response.

06

Learning from Real-World Failures

Landmark agentic incidents — EchoLeak, Replit's deleted production database, JadePuffer, the Postmark MCP and Salesloft Drift attacks — the patterns behind them, and the governance minimum bar you can put in place tomorrow.

Earn a certificate

Managing Your AI Employees certificate

Finish the course and earn a verifiable certificate — issued by AI Security University with its own public verification page, and shareable straight to your LinkedIn profile.

  • Public verification page
  • Counts toward CPE credit
  • Open Badge compatible
  • Add to LinkedIn
See a sample credential →

Your instructor

Darren Shelcusky

Darren Shelcusky

Principal, Cyvantis LLC

Darren Shelcusky is Principal at Cyvantis LLC, with 45+ years in the automotive industry and 12 awarded patents. At Ford, he established and operated the company's global product cybersecurity observability platforms.

He has provided oversight across hundreds of billions of API calls, hundreds of terabytes of API transactions, 25M+ vehicles, 6M+ consumers, and 48K+ API endpoints — and advises companies on building and maturing their commercial security offerings. He's a frequent speaker at API, AI, security, and automotive conferences.

Principal, Cyvantis LLC45+ years in automotive & security12 patentsEx-Ford product cybersecurity

AI isn't a product you buy. It's a workforce you manage.

Free and self-paced. Join the community and we'll let you know the moment it opens.