Hey all,
I saw another post here recently from a startup looking for a CISO advisor and thought we’d ask as well.
We’re a startup in SF building around a problem I’m guessing more teams are starting to run into: employees want AI tools like Claude, ChatGPT, Cursor, etc. to actually do things in company systems, while security needs some control/visibility over what those agents can access and do.
We’ve built quite a bit around this problem, but there’s a big difference between “we think our security model makes sense” and having someone who has actually been responsible for approving this stuff tell us where it falls apart.
So I’m looking for a CISO, current or former, who’d be open to advising us from time to time. Finance/fintech or SaaS would be especially helpful.
A lot of what I want help with is pretty straightforward: What are we overlooking? What would kill this in a security review? What would you need visibility into? Where would you draw hard lines around what an AI agent can and can’t do?
Not looking for someone to rubber stamp what we’ve built. Quite the opposite.
If advising sounds interesting, feel free to DM me.
Otherwise, I’d be really curious what people about below:
If an employee wanted to let an AI agent access and take actions in Sharepoint, Google Workspace, Jira, Slack, Salesforce, or other company systems, what would you need in place before approving it?