Skip to content

Agentic Covenants

Agentic Inventory Matrix

What agents exist, what they touch, what threats they face?

Filter

Layers, by what they can actually enforce

  • Self-declaredadvisory

    The agent reports itself. It can be wrong, stale, or absent entirely.

  • Operator-declareddeterministic-when-invoked

    The operator registered it. Accurate only as far as the operator knows.

  • Discovereddeterministic-and-external

    Found independently by scanning the target. Trusts neither of the above.

Showing 15 of 15.

  • Identity at Self-declared

    Agent registers on startup with name, charter ref, owner email, instance ID. Heartbeats. Deregister on shutdown. Dead-mans-switch alerts on heartbeat lapse.

  • Identity at Operator-declared

    Operator-maintained registry; agents.yaml in GitOps; ServiceNow CMDB; internal AI inventory tool. Owner-confirmed. Updated on charter signature.

  • Identity at Discovered

    CloudTrail / GCP Audit Logs of SA and IAM principal usage. K8s controller watching SA+RoleBinding by naming pattern. Reverse-lookup from credential fingerprints in Sentinels.

  • Authorization at Self-declared

    Agent reports allowed-tools list, MCP allowlist hashes, effective scope on registration. Updates on scope change.

  • Authorization at Operator-declared

    Operator records authorized scope in registry, linked to RBAC manifest paths and IAM policy ARNs.

  • Authorization at Discovered

    K8s RBAC API list, AWS IAM Access Analyzer effective permissions, Kyverno PolicyReports of policies actually applied.

  • Blast radius at Self-declared

    Agent reports declared risk tier, damage cap, forbidden operations from its charter. Reports current environment and data class access.

  • Blast radius at Operator-declared

    Operator records blast-radius profile per agent. Worst-case impact statement (revenue, customer, compliance).

  • Blast radius at Discovered

    Threat-modeling output (MAESTRO Layer 7, MITRE ATLAS, lateral-movement path analysis). Behavioral observation of what the agent has touched.

  • Approval gating at Self-declared

    Agent reports last charter signature date, next review due, current charter version on registration. Refuses to start if charter is expired.

  • Approval gating at Operator-declared

    Operator-maintained review calendar. Quarterly attestation. Tracks pending and overdue reviews.

  • Approval gating at Discovered

    Registry of charter files in source control. Last-modified, last-PR-merged. Cross-reference with self-declared and operator-declared.

  • Supply chain at Self-declared

    Agent reports current dependency manifest on registration: foundation model + version, MCP server names + hashes, base image SHA, lockfile fingerprint. Updates on change.

  • Supply chain at Operator-declared

    Operator records authorized-dependency manifest from agent charter. Linked to Covenants L2-C5 and L3-C5 allowlists. Version-controlled audit trail.

  • Supply chain at Discovered

    Image-registry pull events, package-manager logs, runtime introspection of loaded models and connected MCP servers, SBOM scanning. Drift between actual and authorized = alert.