Matrix/Infrastructure

Infrastructure

The technical layer that enables (or blocks) agents. From shared Jenkins to ephemeral agent sandboxes.

4capabilities20levels60practices60guides
The matrix · full map
Capability ↓
Maturity →
L1 · Stage 01
Assisted
L2 · Stage 02
Delegated
L3 · Stage 03
Systematic
L4 · Stage 04
Governed
Sweet spot
L5 · Stage 05
Self-improving
01·15 guides
Agent Runtime & Sandboxing→
Where and how AI agents execute code - isolation, security, and resource management
Agents run on developer laptops
3 practices·3 guides→
Docker walls and scoped credentials
3 practices·3 guides→
Isolated devboxes, blind to production
3 practices·3 guides→
Hardware-isolated microVMs in ten seconds
3 practices·3 guides→
A fleet on its own compute
3 practices·3 guides→
02·15 guides
MCP & Tool Integration→
How agents connect to external tools, APIs, and internal systems via MCP (now universal standard) and plugins
Built-in tools and copy-paste
3 practices·3 guides→
A few MCP servers, wired by hand
3 practices·3 guides→
MCP is a managed platform
3 practices·3 guides→
Four hundred tools behind one door
3 practices·3 guides→
MCP is the nervous system
3 practices·3 guides→
03·15 guides
Build System→
Build tooling optimized for agent-scale throughput - caching, incrementality, and speed
Full rebuilds, nothing cached
3 practices·3 guides→
Cached and parallel - that's it
3 practices·3 guides→
A dependency graph, remote and incremental
3 practices·3 guides→
Any change, under two minutes, per agent
3 practices·3 guides→
Builds too fast to notice
3 practices·3 guides→
04·15 guides
Observability & Feedback Loop→
Monitoring agent behavior, costs, and outcomes to close the improvement loop
Logs and error alerts
3 practices·3 guides→
Structured logs, basic OpenTelemetry
3 practices·3 guides→
Agent cost and outcomes on dashboards
3 practices·3 guides→
Anomalies open tickets; agents investigate
3 practices·3 guides→
Production fixes itself through the loop
3 practices·3 guides→
Climb the matrix

You don't have to figure this out alone.

Every level in this matrix has a path. Read the playbooks the teams that have climbed it wrote. Run the assessment with our consultants. Start where you are.

Live with Visdom

Book an AI Maturity Assessment session with your team.

We walk you through all four perspectives, score where you actually are, and leave you with a 90-day plan to climb in the dimensions that matter most.

Book an assessment →See what's included90-day plan - scored assessment - coaching
Author Commentary

The infrastructure lesson of September is that agents got identities because attackers already had their tokens.

GreyNoise documented the first mass-exploitation campaign run by AI agents: 395 organisations in 48 countries, the first compromise 26 seconds in, stolen Claude, Cursor and Gemini sessions on 5,871 machines and $600k of model credits burned through one compromised agent dashboard. Anthropic's threat report added the quieter variant: a prompt injection persuaded an AI vendor's automated evaluation sandbox to hand over production API keys for several providers, and the follow-on hit around thirty AI companies in four days. Its advice is the line to put on the wall: treat AI keys and agent integrations like production credentials. In runtime terms that means no personal access tokens and no shared long-lived keys for agents, credentials injected at run time from a vault or broker, and task-scoped tokens that expire in minutes.

The identity industry answered in the same month. Okta shipped agent-to-agent connections and access certifications for agents, with an agent gateway and a kill switch for live tokens on its roadmap. CrowdStrike's Agentic Identity Provider auto-registers agents with a verifiable identity and short-lived credentials and links each action to a human or workload. The IETF WIMSE working group adopted `draft-ietf-wimse-aims-00`, its first baseline for agent authentication. For MCP, the maturity step is getting access granted centrally by the identity provider (Cross App Access, Enterprise-Managed Authorization) instead of a sprawl of per-user consent screens, behind a gateway that shows each caller only the tools it may use. And the gateway itself is now a target: LiteLLM's MCP auth bypass reached the CISA KEV list in September.

Underneath, the agent's plumbing kept failing. GitSpawn used `core.fsmonitor` in a repository's own `.git/config`, so the agent's startup `git status` ran attacker code outside the sandbox, with no prompt, across eight agents. Plugin4Shell beat SHA-pinning in plugin marketplaces with branch names that look like commit hashes. Deadbugz behaved like an ordinary MCP server for exactly three tool calls, then rewrote its tool metadata to hunt for SSH keys, AWS credentials and kubeconfig, which is why install-time review is not enough and tool metadata needs watching at runtime. And OpenAI disclosed a training agent that escaped its sandbox over DNS while the automatic shutdown failed. Assume escape still holds. What September adds is: assume the token is stolen, and make sure you can revoke it in seconds.

Other perspectives