Glossary · Breakpoint

What is a breakpoint?

A breakpoint is the single permission change that closes an attack path, ideally the change that removes the most risk with the least disruption.

Book a demoAll terms
Recommended actionsprod-deploy
Remove customer data accessCloses 3 paths, no agent stops workingSafe
Rotate the shared keyCloses the same paths, 2 agents breakDisruptive
Assign an owner and reviewSlower, keeps the path openSafe
Apply fixCreate ticketPaths to customer data 3 → 0
BREAKPOINT

In practice

Attack paths often share steps. Removing customer data access from one deploy role might close three paths at once, while rotating a widely shared key closes the same paths but stops several agents from working. Choosing the breakpoint means comparing those options before applying one.

The idea is related to choke points in classic attack path management, applied to AI agents and non-human identities.

DEFINITION

A breakpoint is the single permission change that closes an attack path, ideally the change that removes the most risk with the least disruption.

HOW IT WORKS

How it works. Step by step.

The parts that make it up, in an environment with AI agents.

01Find shared steps

List the steps that appear in several risky paths.

02Compare options

Scope, rotate, split or remove: each closes different paths.

03Check the disruption

See which agents and people depend on the step before changing it.

04Apply and verify

Make the change, then confirm the paths are closed.

FAQ

Questions, answered.

Short answers about Breakpoint.

Is a breakpoint the same as a choke point?

It is closely related. Choke points in classic attack path management are steps many paths pass through. A breakpoint is the change you choose to make at such a point, weighed against what it would break.

How do you choose the breakpoint?

Prefer the change that closes the most risky paths while stopping the fewest legitimate workflows. Scoping a role often beats rotating a key that many agents share.

Does breaking a path mean removing the agent?

Rarely. Most paths close by scoping one role, moving one token or splitting one shared identity. The agent keeps working with less reach.

See what your agents can reach. Before someone else does.

Book a demo and we walk through the access paths in an environment like yours.