4 min readAI Agents · Cybersecurity
How do you test whether you can revoke an AI agent's session?
By Josh Woodruff, Founder & CEO, MassiveScale.AI | Founding Chair, Agentic Trust Framework at the CSAI Foundation

TL;DR: Run four checks. List every active agent session in under a minute. Start an agent on a task in a test setting and revoke its session midway. It should take zero more actions. Leave a session open past its time limit and confirm it ends by itself. Then find all of that in the log.
A session is the stretch of time an agent stays signed in and working. Think of a visitor badge. It's good from the moment you hand it over until someone takes it back.
Most teams know how to hand out the badge. Fewer have tried taking one back while the visitor is still walking the halls.
Why does session control need its own test?
Because revoking a login and stopping a session aren't the same thing.
You can cancel an agent's key and find the agent still working. Its current session was already open. Until that session ends, the agent keeps going.
That's the hole this test looks for. A stop you issue should stop the next action, and you should see it happen.
How does the assessment score this?
Question 4 of the free assessment asks how you track and control AI agent sessions. It belongs to Identity Management, the first of the five ATF elements. Each answer does differently on the four checks.
Answer | What it says | How the checks go |
|---|---|---|
A | We don't track agent sessions at all. | You can't list them, so you can't revoke one. |
B | We log basic activity but don't have session controls. | You can see a session after the fact. You can't end it. |
C | We track sessions with timestamps and can see who's active. | The list check passes. The revoke check doesn't. |
D | We enforce session limits and can revoke sessions right away. | All four checks pass when a person acts. |
E | Full session management with time limits, plus revocation the moment a problem is detected. | The session ends before a person gets involved. |
How do you run the four checks?
Use a test setting and a harmless task.
Check 1: the list.
Start a timer and ask for every agent session that's active right now.
Stop the timer when you have the list.
Pass is under one minute, with the agent's name on each session.
Check 2: the revoke.
Give a test agent a task with at least ten steps.
Revoke its session around step five.
Count how many more steps it finishes.
Note how long the revoke took to bite.
Pass is zero. One more step is a warning. If it finishes the task, the revoke did nothing.
Check 3: the time limit.
Find the stated limit for a session, such as eight hours.
Leave a test session open past it.
Try an action.
Confirm the session shows as ended.
Pass is a refusal. A session with no limit is a badge that never gets collected.
Check 4: the record.
Open the log. Find the revoke from check 2 and the timeout from check 3. Each entry should name the agent and the time. The revoke should also name the person who did it.
Pass is both entries found. A stop nobody can prove later won't help you in a review.
What do you fix first when a check fails?
Go in order. Each check depends on the one before it.
If the list check fails, start there. You can't end a session you can't find.
If the revoke check fails, look at how often your systems re-check a session. Many only check at sign-in. Ask for a check on each action, or at least every few minutes.
If the time limit check fails, set one. Pick a limit just long enough for the longest job the agent really runs.
If the record check fails, turn on logging for session events before anything else changes.
Session control is the fine-grained stop. The full stop for a whole agent is a separate drill, in testing whether your AI agent kill switch works.
Frequently asked questions
Isn't revoking the key enough?
Not by itself. A key controls new sign-ins. An open session can outlive it. Short-lived keys shrink that window, which I cover in how to score how your AI agents log in.
How short should a session limit be?
As short as the agent's real work allows. If its longest job takes twenty minutes, an eight-hour session is mostly spare time for an attacker.
Who should be able to revoke a session?
The agent's owner and the on-call security person. Two roles is enough. Make sure both have tried it.
How often should I rerun the checks?
Every quarter. Rerun them after any change to your sign-in system.
Key takeaways
Revoking a key and ending a session are different actions.
Check 1: list all active agent sessions in under a minute.
Check 2: revoke mid-task and count the steps that follow. The bar is zero.
Check 3: confirm old sessions end by themselves.
Check 4: find the revoke and the timeout in the log.
Question 4 is one of 30 in the free assessment. It takes about ten minutes and scores you on all five ATF elements.
Handing out the badge is the easy half. Try taking one back while the agent is still working.