Agentic Covenants / Agentic Covenants Matrix
Authorization at Server-side enforcement
This layer is deterministic-and-external.
Scoped RBAC Roles, IAM with explicit ARN, Kyverno or OPA admission, namespace scoping.
How it is still bypassed
- escalate/bind/impersonate in RBAC
- subresource access not denied
- admission webhook fail-open
Maps to
- NIST CSF 2.0
- PR.AA-05, PR.PS-01, PR.PS-05
- NIST AI RMF
- MANAGE 2.4, MANAGE 4.1
- OWASP LLM
- LLM05, LLM06
- OWASP Agentic
- ASI02, ASI03, ASI05
- Other
- NIST SP 800-207, CIS Kubernetes Benchmark