Supplier Risk Agent
ATC-AGT-0004218
72
high risk
Identity
Who owns it, and what it is for
- Declared purpose
- Analyze supplier financial risk and raise alerts for procurement managers.
- Business owner
- Dominique Bexley · Procurement
- Technical owner
- Anders Kohl · Platform Engineering
- Provider and model
- Anthropic · claude-sonnet-4-5
- Framework
- LangChain
- Environment
- production
- Data classes reached
- Internal, Confidential, Financial data
- Last activity
- 4 minutes ago
Risk
Why the score is 72
Every point is accounted for. Remove a factor and the score moves by exactly that much.
- +20
Data
Reads confidential supplier financials
- +12
Action
Can create records that trigger downstream workflow
- +10
Tool
Calls an external credit API
- +12
Dependency
One of three MCP servers changed permissions after approval
- +8
External exposure
Reaches a third-party service outside the tenant
- +10
Compliance
Access review overdue by 24 days
- 72Total
Access
What it may do, action by action
Permissions are held at the level of the action, so reading a record and changing its banking details are separate grants that can be decided separately.
- read_supplierQeluntraL0 ReadGranted
- create_supplier_alertQeluntraL2 Execute, low riskGranted
- modify_supplierQeluntraL3 SensitiveWithheld
- change_bank_detailsQeluntraL4 CriticalWithheld
- approve_purchase_orderQeluntraL4 CriticalWithheld
Dependencies
MCP servers it is bound to
- approved
Finance MCP
Internal · Finance Platform
read_ledgerread_invoice - drifted
Credit Data MCP
Third party · unverified
lookup_credit_ratingexport_reportAdded export_report after approval. Reauthorization required.
- approved
Microsoft MCP
Microsoft
search_files
Execution identity
What it authenticates as
An agent does not reach anything by itself. It runs as a machine identity, and that identity is what actually holds the credential — so the agent's permissions are only ever a subset of what this can do.
- Qeluntra Supplier Workload18
ATC-MID-0000412 · Microsoft Entra ID
Managed identity
Supply chain
Bill of materials
What this agent is assembled from. It is also the answer to the blast-radius question when one of these is compromised.
Model
Framework
Tools
MCP servers
Databases
Packages
Runtime
Decisions taken on its behalf
Every governed action produces one of these, and each records the rule that decided it.
- 14:02:11read_suppliersupplier:48120Allowed
rule: procurement.read.suppliers
- 14:02:14lookup_credit_ratingmcp:credit-dataAllowed
rule: mcp.approved-tools
- 14:02:31create_supplier_alertsupplier:48120Allowed
rule: procurement.write.alerts
- 14:07:52change_bank_detailssupplier:48120Denied
rule: purpose.scope · level-4
- 14:08:03export_reportmcp:credit-dataHeld
rule: mcp.drift.hold