Agentic Sentinels Matrix
If this concern is breached, how do we know?
Filter
Layers, by what they can actually enforce
- In-agent (forensic only) — forensic
Transcript and tool-call logs from the agent runtime. Forensic value, not real-time. Lethal-trifecta detector at the wrapper layer is the only L1 with detection value.
- Client-side hooks — deterministic-when-shipped
auditd, eBPF, hook decision logs, MCP allowlist violation logs. Tamper-evident only if logs ship to a remote sink owned by the operator, not the agent.
- Server-side enforcement — external-and-authoritative
Kubernetes audit logs, CloudTrail, Falco, Hubble, Kyverno PolicyReports, GitHub webhooks. External to the agent's compromise model.
Showing 3 of 15.
Blast radius at In-agent (forensic only)
Reasoning trace and tool-call log capture for forensics, plus a lethal-trifecta detector at the wrapper layer that flags when private data, untrusted content, and external communication appear in the same context window. The detector is the only L1 control with real-time detection value, and it runs outside the agent.
Blast radius at Client-side hooks
bpftrace or Falco userspace catches unsandboxed children, sandbox EPERM events, unexpected network attempts; correlates by session ID.
Blast radius at Server-side enforcement
Falco runtime rules for shells in agent containers and writes to sensitive paths; Cilium Hubble drops; ResourceQuota near-limit Prometheus alert; VPC Flow Log REJECTs.