Search the Atlas

Search risks, controls, and glossary terms

AgenticGovernance & Oversight

Governance evasion and alert saturation detection

Control objective

Governance evasion and alert saturation detection guards the monitoring system itself from being defeated. Sophisticated misuse often hides not in one loud event but in many tiny actions spread thinly over time ('low-and-slow'), or by flooding analysts with so many alerts that the real signal is buried (alert saturation) - both classic ways to slip past bank controls. This control ensures the oversight layer stays effective by deduplicating and prioritising alerts so reviewers see what matters, and by running longitudinal analysis that stitches together small, individually-innocuous actions into a detectable pattern. To implement, instrument alert pipelines with deduplication and risk-based prioritisation, run scheduled low-and-slow correlation analysis across long time windows, monitor alert volume and acknowledgement rates for saturation, and log alert-handling metrics as evidence that governance is not being overwhelmed or evaded. No numeric formula is specified. The threshold is operational: alert deduplication and prioritisation must be live, the low-and-slow longitudinal analysis must be running, and saturation must be actively monitored. If any of these is not operating - dedup off, longitudinal analysis not run, or saturation unmonitored - the control is in breach and oversight effectiveness must be restored before relying on the alerts.

Implementation notes

Alert deduplication and prioritisation to prevent saturation attacks. Longitudinal behavioural analysis for low-and-slow evasion. Cross-agent session linking. Population-level anomaly detection for distributed evasion patterns.

Risks mitigated

2