One Bad Prompt Took Down a Company’s Salesforce: RSA’s Jim Taylor on Agent ID and Taming the 4,000 Shadow AI Agents Hiding in Your Enterprise
Not a pilot. RSA just shipped an agent security platform because one bad prompt took down a company's entire Salesforce. Discover, Secure, and Govern hit GA November 16.

Why it matters
RSA Agent ID addresses a concrete gap in enterprise agent governance: discovery of shadow agents (4,000 per enterprise cited), inline policy enforcement on tool calls, and regulatory mapping. For regulated industries deploying agents at scale, this is actionable infrastructure—but the 'one prompt' anecdote lacks specifics, and no independent testing or deployment outcomes are disclosed.
The key facts
7 to knowRSA Agent ID ships November 16, 2026 (Discover and Secure modules)
Three modules: Discover (sanctioned and shadow agents, MCP servers), Secure (inline gateway checking tool calls against policy), Govern (10 regulatory frameworks mapping)
Target verticals: finance, government, healthcare, critical infrastructure
Anecdote: 'one bad prompt took down a company's Salesforce' — no additional context on root cause, blast radius, or mitigation
Enterprise shadow agent estimate: 4,000 per organization (source not disclosed; vendor claim not independently verified)
No pricing, regional availability, or integration scope disclosed
No customer deployment data or measured outcomes provided
Go to the source
MarkTechPostmarktechpost.com
Publisher excerpt: RSA launched Agent ID at The AI Conference in San Francisco. It's an agentic identity security platform for finance, government, healthcare, and critical infrastructure. It has 3 modules. Discover finds sanctioned and shadow agents and MCP servers. Secure is an inline gateway that checks every tool…