Skip to content

Agentic Covenants / Agentic Covenants Matrix

Identity at Client-side hooks

This layer is deterministic-when-invoked.

Per-agent credentials, no shared keys, filesystem ACLs.

How it is still bypassed

  • token theft
  • credential leakage in logs

Maps to

NIST CSF 2.0
PR.AA-01, PR.AA-03
NIST AI RMF
MANAGE 2.4
OWASP LLM
LLM02
OWASP Agentic
ASI03
Other
NIST SP 800-207, NIST SP 800-63

Enforcement

controls/identity/client-side/