Every unveils "How to Secure an AI Employee" guide for Claudie
Serge Bulaev
Every released a preview of its guide "How to Secure an AI Employee," which explains how they manage security for their AI assistant, Claudie. The guide suggests that agent security should be updated over time as new risks appear, rather than set once and left alone. It offers a four-layer framework to help teams see what an AI can access, limit that access, monitor its actions, and quickly react to problems. The preview says more detailed advice and tools are available to subscribers, and that Claudie's security is adjusted regularly to match new threats. The guide may help teams better balance the risks and benefits of giving AI agents access to their systems.

Every has released a public preview of its new guide, "How to Secure an AI Employee," which details the security framework for its AI chief of staff, Claudie. Authored by Nityesh Agarwal and Claude, the guide explains their process of starting with broad access and then strategically reducing permissions as risks became clear. While the full guide is for subscribers, the free preview offers key lessons on managing AI agent security.
The preview introduces a four-layer security model and provides a ready-to-use prompt for auditing AI agent permissions. It champions an iterative approach to security, treating it as an ongoing process, not a static checklist. This philosophy aligns with emerging industry standards, such as Anthropic's Zero Trust for AI agents guidance.
Why Every wrote the guide
Every created the guide to share its firsthand experience securing an AI agent whose responsibilities expanded over time. As Claudie's role grew from project manager to chief of staff, the team had to continuously adapt its security, documenting the process to help others manage similar AI integrations.
Co-author Nityesh Agarwal notes that as Claudie's duties expanded to include scheduling and research, each new capability introduced new security vulnerabilities. The team adopts a dynamic security posture, "tightening Claudie's security week by week" to address emerging threats. This strategy reflects a broader industry consensus to manage every AI agent as a privileged identity, a practice also endorsed by Microsoft in its Four priorities for AI-powered identity and network access security.
Four-layer starter framework
While the complete model is behind a paywall, the preview outlines the goals for each of the four security layers:
- Identify: Map all data, tools, and memories the agent can access.
- Limit: Enforce least-privilege permissions and use time-boxed access tokens.
- Monitor: Track all agent activity through detailed logs and establish human review checkpoints.
- Contain: Create protocols to rapidly revoke credentials and isolate the agent during an incident.
This framework aligns with current best practices that call for unique agent identities, sandboxed environments, and short-lived credentials. The full guide also provides a prompt to help security teams quickly audit an agent's current access levels.
Iteration over perfection
Every emphasizes that its security framework is not final but a living document. The authors plan to continuously update Claudie's controls with advanced defenses like output filtering as new attack methods emerge. This approach acknowledges that AI agent behavior can be unpredictable, making dynamic runtime governance more effective than static, one-time security configurations.
Access for members
Subscribers to Every gain access to the complete guide, which includes:
- A detailed diagram of the four-layer framework with configuration examples.
- A threat matrix that maps common attacks to specific controls.
- The full, audited prompt template for security assessments.
These are presented as practical tools, not just theory. The guide argues that for teams deploying AI agents, the best practice is to start with broad permissions, monitor activity, and then systematically prune access to achieve a clear understanding of the risk-to-benefit ratio.
Currently, Claudie handles scheduling, inbox triage, and research synthesis within a tightly controlled scope of workspace and API access. Every plans to publish future articles detailing the evolution of these security scopes in response to the changing threat landscape and industry best practices.