
Runtime Authority-Aware Threat Modeling for Agentic AI Systems
A framework for intent, context, authority, tool capability, memory, delegation, and action composition.
I’m Ravindra Annam. For more than 20 years, I’ve worked across application and API security, cloud platforms, threat modeling, DevSecOps, incident response, and data protection. Today I also research how to secure AI agents as they act across those systems.

My career spans secure architecture, product and application security, cloud, web and APIs, and security operations. I connect technical controls with practical decisions that engineering and business teams can use.
My current research examines what changes when AI systems can call tools, access sensitive data, and delegate actions. Through writing, speaking, mentoring, and community review, I share approaches to both established and emerging security challenges.

Application and API security, cloud security, DevSecOps, threat modeling, logging and response, data protection, and agentic AI security.
Research on how untrusted influence can cross into privileged agent behavior, and the controls needed at execution time.

A framework for intent, context, authority, tool capability, memory, delegation, and action composition.
A threat taxonomy and control framework for autonomous agent systems, including the RAAI runtime control loop.
View report ↗Continuous assessment, authorization, action, and audit for systems whose authority changes through a workflow.
Explore framework ↗Tracing attack paths through prompts, context, memory, tools, APIs, permissions, and downstream actions.
Research overview ↗Architecture, runtime protection, monitoring, and governance controls for enterprise AI systems.
Research overview ↗My work spans secure design and engineering for enterprise products, cloud platforms, web and API ecosystems, and the software delivery lifecycle.
Secure architecture reviews, threat modeling, web and API risk, vulnerability prevention, and practical controls built into product development.
Security design for AWS and Azure environments, cloud-native services, identities, workloads, and the connections between enterprise systems.
Embedding security into delivery through SAST, DAST, software composition analysis, container testing, risk-based triage, remediation, and verification.
Mapping how attackers reach assets and abuse trust boundaries, then translating findings into design decisions teams can implement.
Designing useful logging and telemetry, detecting abnormal behavior, investigating incidents, containing impact, and strengthening controls after recovery.
Protecting sensitive data with classification, data loss prevention, least-privilege access, and encryption at rest and in transit across applications and cloud services.
Research and practitioner writing on the decisions security teams face as AI agents enter production.
Accepted for publication and scheduled for October 8, 2026. A practitioner approach to agent behavior, tools, authority, and runtime controls.
Why attribution and task context have to travel with an agent’s actions.
A response playbook for containment, blast radius, investigation, and recovery.
Enterprise controls for AI systems operating inside real workflows.
Sessions for engineers and security leaders on agent attacks, runtime controls, and practical security architecture.
[re]aligned, the online extension of CanSecWest. An accepted presentation on tracing, limiting, and revoking delegated authority across agent workflows.
Event ↗University of Texas at Dallas · Richardson, Texas
Official event ↗ISC2 Think Tank · Speaker and panelist
Session details ↗Agent identity and authorization · Prompt injection and tool abuse · AI incident response · Threat modeling autonomous systems.
Discuss a session ↗Technical evaluation and community work across research, professional content, awards, standards comments, and open-source security practice.
Industry judge for AI and cybersecurity work.
View event ↗Article Reviewer, 2026–2027, and reviewer for the 2027 Global Achievement Awards and Hall of Fame.
View contributions ↗Journal of Cybersecurity Education, Research and Practice reviewer; contributions to OWASP generative AI security initiatives.
View contributions ↗Completed formal reviews for the workshop on reliable evaluation for language models.
Review activity completedContributed delegated-authority invariants, an independent resolution-semantics runner, and adversarial test cases across A2A and ERDL work. Related conformance tests were merged.
View merged work ↗Submitted comments on draft cybersecurity and AI guidance, including NIST IR 8613. Comments are under consideration.
Public-comment contributionFor cybersecurity and AI security research, speaking, technical discussion, or professional service, connect with me on LinkedIn. Follow The Security Frontier for commentary on AI security and enterprise cyber risk.