Agentic security platforms are arriving. ECS-hosted investigation agents that invoke Bedrock models, write case artifacts to S3, mount shared session state via EFS, and expose interactive shells through ALBs. The architecture is sound. The security configuration surface is enormous. Most of it isn't covered by existing benchmarks because the benchmarks were written before agents existed.

I audited a published deployment architecture for an ECS-hosted agentic SOC platform. An AI incident response system where autonomous agents triage alerts, investigate incidents, and produce case reports. 24 configuration properties matter for security. I checked each against the control catalog.

19 were already covered. 5 weren't. The 5 gaps reveal a pattern worth understanding even if you never deploy this specific architecture.

The Architecture

The architecture has four layers, each with its own security surface: