Delegate — agentic threat model
Delegate presents a high-risk profile due to its deep integration into sales, support, and product tools and its access to all customer data, though its 'Human In the Loop' feature provides a critical safety valve against fully autonomous damage.
OWASP AIVSS score rationale
| Autonomy of Action | 0.60 | |
| Goal-Driven Planning | 0.70 | |
| Self-Modification | 0.10 | |
| Dynamic Tool Use | 0.80 | |
| Persistent Memory | 0.60 | |
| Contextual Awareness | 0.80 | |
| Dynamic Identity | 0.30 | |
| Multi-Agent Interactions | 0.20 | |
| Non-Determinism | 0.60 | |
| Opacity & Reflexivity | 0.50 |
Scored with the canonical OWASP AIVSS formula (AIVSS calculator reference); agentic risk factors estimated from the agent’s described capabilities.
MAESTRO 7-layer threat model
Per-layer threats for this agent. Layers tagged “not certain from listing” are general, caveated commentary where the public description didn’t pin that layer.
Not certain from the listing — likely utilizes commercial LLMs for customer communication and proprietary ML models for churn prediction. Primary threats include prompt injection leading to unauthorized tool execution or misaligned customer interactions.
Not certain from the listing — ingests and analyzes 'all your customer data' from sales, support, and product tools. This creates a highly attractive target for data exfiltration, and poses a risk of data poisoning if malicious customer inputs are ingested into its analysis pipeline.
Not certain from the listing — orchestrates multi-step workflows to predict, prioritize, and execute customer success actions. Insecure tool integration with connected sales and support platforms could allow an attacker to trigger unauthorized actions.
Not certain from the listing — hosted as a closed-source SaaS. The primary infrastructure risk is the secure storage and handling of API credentials/tokens for the integrated third-party sales, support, and product tools.
Features 'Agent Analytics' and 'Human In the Loop' capabilities, which provide explicit mechanisms for monitoring agent decisions and requiring human approval before executing critical customer-facing actions.
Not certain from the listing — handles highly sensitive customer and sales data across multiple enterprise systems, but the listing does not specify compliance certifications (such as SOC2 or GDPR alignment) or authorization policies.
Not certain from the listing — operates as a horizontal agent interacting with external APIs of sales, support, and product tools. Risks include cascading failures or API rate-limiting if downstream systems experience disruptions.
MAESTRO — the 7-layer agentic threat-modeling framework (Cloud Security Alliance / Ken Huang).