
6/10/2026
What this post added
This post details the practical application of the AWARE framework for AI agent governance, emphasizing the collaboration between CIOs and CISOs. It highlights how Cvent used the framework to achieve security buy-in for over 6,000 AI agents by inverting the typical enterprise sequence: encouraging broad creation early while implementing foundational security controls. Key strategies include introducing ROI gates for new agent projects, a sandbox-first deployment model, and leveraging platforms like Glean with built-in fine-grained security controls. The post argues that getting CISO approval involves demonstrating a clear understanding of who is acting, their context, guardrails, risk spikes, and traceability, rather than eliminating all risk.