Mumbai, June 3 : Workday DevCon – Workday, Inc , the enterprise AI platform for HR, finance, and IT, today announced Agent Passport, which tests and verifies every AI agent, Workday-built or third-party, before it goes into production, and continuously monitors it after. Every attestation is tied to a public industry standard, such as OWASP LLM Top 10, NIST AI RMF, and MITRE ATLAS, so security teams have a signed, auditable record of what each agent has been tested for and who did the testing.
Agent Passport gives companies a verified record that every agent has been tested against the most serious risks before it goes into production, including prompt injection, jailbreak and goal hijacking, system prompt extraction, leaks of employee data, and unsafe outputs. Each test result is tied to a public standard and signed by the partner that performed it, so the record is independent, auditable, and comparable across agents from any vendor.
When an agent attempts to execute a task, Agent Passport will monitor in real time and either allow, block, or route the action accordingly. If a problem is discovered, a single revocation can automatically stop, limit, or otherwise restrict affected agents based on company policy.
“AI agents are now doing the most sensitive work in the enterprise, from onboarding employees to processing payments, and one insecure agent can leak employee data, break compliance, and put the company on the front page for the wrong reasons,” said Dean Arnold, vice president, AI Platform, Workday. “Agent Passport gives companies confidence that every agent has been independently tested and verified, and the power to shut any of them down across the business the moment something changes.”
A Shared Standard, Built with Industry Leaders
Most platforms that offer agent security testing do it themselves, which means customers receive a “safe” label from the same vendor that built the agent. Workday has built extensive trust with customers with its broad portfolio of AI solutions for HR and finance. The company is building on that trust through open standards and partnership with leading vendors in agentic security and regulatory compliance, so the testing is independent and open, and the results are comparable across agents from any vendor.
Each agent’s record has three layers. The first covers the broad areas of trust that Workday defines and keeps current, such as protection against attacks, safe behavior at runtime, and human oversight. The second is a set of specific, testable claims tied to public standards, like resistance to known attack techniques. The third is the signed results from the partner that performed the testing, issued by verified, trusted attestors starting with Cisco.
Because every check is tied to a public standard, security teams can compare agents from different vendors on the same terms for the first time. If two agents carry the same check from two different partners, companies know they were held to the same bar.
Independent Attestations from Industry Leaders in Agentic Security
Cisco is the launch partner for Agent Passport, bringing Cisco AI Defense to independently test AI agents running in Workday against leading security standards before deployment and continuously protect them at runtime against prompt injection, data leakage, jailbreaks and unsafe actions.
Cisco AI Defense confirms the agent resists attempts to override its instructions, keeps its own instructions from being exposed, protects sensitive employee information from leaking, and blocks harmful or policy-violating responses before they reach a user. These validations are important for any agent, but are non-negotiable for agents operating on payroll, benefits, and financial data.
“Agents are going to be everywhere in the enterprise, and that only works if security teams have a clear, signed record of what each one has been tested for,” said DJ Sampath, senior vice president and general manager, AI Software and Platform, Cisco. “Cisco AI Defense was built for exactly this kind of validation, and we’re excited to partner with Workday to secure the agentic workforce.”
