Skip to content

Agentic Covenants

Agentic Sentinels Matrix

If this concern is breached, how do we know?

Filter

Layers, by what they can actually enforce

  • In-agent (forensic only)forensic

    Transcript and tool-call logs from the agent runtime. Forensic value, not real-time. Lethal-trifecta detector at the wrapper layer is the only L1 with detection value.

  • Client-side hooksdeterministic-when-shipped

    auditd, eBPF, hook decision logs, MCP allowlist violation logs. Tamper-evident only if logs ship to a remote sink owned by the operator, not the agent.

  • Server-side enforcementexternal-and-authoritative

    Kubernetes audit logs, CloudTrail, Falco, Hubble, Kyverno PolicyReports, GitHub webhooks. External to the agent's compromise model.

Showing 3 of 15.

  • Blast radius at In-agent (forensic only)

    Reasoning trace and tool-call log capture for forensics, plus a lethal-trifecta detector at the wrapper layer that flags when private data, untrusted content, and external communication appear in the same context window. The detector is the only L1 control with real-time detection value, and it runs outside the agent.

  • Blast radius at Client-side hooks

    bpftrace or Falco userspace catches unsandboxed children, sandbox EPERM events, unexpected network attempts; correlates by session ID.

  • Blast radius at Server-side enforcement

    Falco runtime rules for shells in agent containers and writes to sensitive paths; Cilium Hubble drops; ResourceQuota near-limit Prometheus alert; VPC Flow Log REJECTs.