Security Design for Generated Experiences

Security Design for Generated Experiences

Why security must move beyond access control to govern execution itself

When our founders broke down the structural problems inside enterprise security, they arrived at one conclusion: the interaction model enterprise security relied on had shifted.

Enterprise security systems were built around deterministic workflows, explicit navigation, and direct human execution. But generated experiences behave differently. Interfaces are becoming orchestration layers. The gap between intent and execution is compressing. Systems act on users' behalf rather than simply respond to them. Security largely is not participating in that shift.

Most of the industry approaches security as infrastructure layered onto experience after the interaction patterns have already been designed. We believe that approach will fail inside generated experiences, where operational scope expands faster than traditional interaction patterns can expose it.

That conclusion shaped how we built the company. It pushed us to invest deeply in design, interaction thinking, and behavioral systems rather than treating security primarily as policy and control infrastructure. This is the first of three posts exploring the foundational thinking behind that approach.

A generated experience is software assembled in the moment from what a person asks for. The user expresses intent, and the experience is composed in response. Beneath it runs the underlying agentic system: the orchestration and execution that fulfills that intent, retrieving data, reasoning across tools, and acting in ways the user never sees step by step. The experience is the shift people feel. The system underneath is where the work, and the operational risk, lives.

Two terms carry the argument from here. Operational scope is the context and access a system is given to act on a request: the data it can read, the tools it can call, the systems it can reach. Operational consequence is what results when it acts across that scope. In hand-operated software, a person sets scope as they go, each file opened, each step traversed, and consequence stays roughly in view because they built up to it. In a generated experience, the system underneath sets scope on the user's behalf, and the consequence can land before the user senses how far the system reached.

Enterprise security assumes users understand operational consequences because they perform each step by hand.

Permissions constrain movement through known paths. Authentication appears before access. Governance attaches itself to stable control points because the systems underneath them behave predictably. Enterprise workflows expose boundaries gradually through navigation itself.

Generated experiences weaken that visibility. The shift is not primarily about chat interfaces or automation. It is a deeper change in how interaction behaves once interfaces become orchestration layers.

For example, a customer recently shared this prompt:

"I want to negotiate my salary with my boss. What should I expect for my level? How should I approach this?"

The interaction felt small. The operational consequence was not. The system responded by retrieving compensation data from a copied organizational file with broader access than intended, exposing salary information well beyond the user's expected scope.

Generated experiences can expand scope before users fully perceive it.

image (3)
Figure 1: Scope Builds Through Navigation, Expands Through Orchestration

This is what we mean when we say productivity itself is becoming the attack surface.

In navigation-based systems, the attack surface is the artifacts. Files, endpoints, accounts, network paths. Security wraps itself around those artifacts because users have to traverse them to do anything.

In generated experiences, a new surface opens in the act of working itself. A single prompt can trigger retrieval across multiple systems, reasoning over data the user has never seen, and action taken in their name. That gap, between what a user asks for and what the system does to deliver it, compresses to almost nothing. Operational scope expands faster than interfaces can expose it.

Interruption alone no longer communicates consequence effectively. Excessive friction breaks orchestration flow, but invisible governance creates a different risk: users lose the ability to understand what systems are doing for them as execution becomes increasingly abstracted.

Generated experiences force security to govern execution

Most conversations around AI governance remain incomplete. They focus on capability, safety, or policy while treating interaction design as secondary infrastructure. The challenge is not simply preventing misuse. It is designing environments where the actions taken on a user's behalf stay visible as the systems underneath become more autonomous.

image (4)
Figure 2. Compression of Intent and Execution

Security has struggled to live naturally inside the enterprise experience.

Most security systems exist as overlays attached to workflows rather than properties embedded within them. Perimeter security surrounds networks. Endpoint security surrounds devices. Identity systems are gateways users pass through before work begins.

Security's design philosophy has long been to stay out of the way. Even the most successful security experiences largely succeed by reducing disruption. SSO reduced repeated authentication. Biometric login removed procedural friction. Adaptive MFA applied interruption more selectively. Even with simplification, the pattern remains the same. Governance appears as something users have to get through.

Generated experiences create a rare opportunity to rethink the relationship between security and the people moving through it, before new interaction patterns harden. Right now, people are actively learning how to work with systems that retrieve context, reason across tools, and act for them. The interaction patterns forming around those systems will settle quickly.

The same risk exists now. If orchestration becomes the dominant interaction model while governance remains detached infrastructure, organizations will recreate the same adversarial patterns around systems that are far more dynamic and far less visible.

The opportunity is not to make security hidden or invisible. It is to design systems where operational consequence remains tangible even as execution becomes increasingly abstracted. Governance needs to understand intent in order to be effective. That requires governance to behave less like interruption and more like what we will come to call environmental signaling. Systems will need ways to signal when their reach is changing, adjust what they do on a user's behalf to fit the situation, and help users understand the actions they no longer perform by hand.

These interaction patterns are being defined right now. The organizations shaping them are also shaping how people work alongside systems acting for them.

To learn more about Ent, our vision for security in generated experiences, and the ideas shaping our work, visit ent.ai and follow us on X and LinkedIn.