Skip to content

Agentic Covenants

Agentic Sentinels Matrix

If this concern is breached, how do we know?

Filter

Layers, by what they can actually enforce

  • In-agent (forensic only)forensic

    Transcript and tool-call logs from the agent runtime. Forensic value, not real-time. Lethal-trifecta detector at the wrapper layer is the only L1 with detection value.

  • Client-side hooksdeterministic-when-shipped

    auditd, eBPF, hook decision logs, MCP allowlist violation logs. Tamper-evident only if logs ship to a remote sink owned by the operator, not the agent.

  • Server-side enforcementexternal-and-authoritative

    Kubernetes audit logs, CloudTrail, Falco, Hubble, Kyverno PolicyReports, GitHub webhooks. External to the agent's compromise model.

Showing 5 of 15.

  • Identity at Client-side hooks

    PreToolUse hook emits structured identity events; auditd watches agent process startup; Vector/Fluent Bit ships to SIEM.

  • Authorization at Client-side hooks

    Hook decision events (allow/ask/deny/error); auditd watches hook config edits and --no-verify; SIEM rule for multi-deny patterns.

  • Blast radius at Client-side hooks

    bpftrace or Falco userspace catches unsandboxed children, sandbox EPERM events, unexpected network attempts; correlates by session ID.

  • Approval gating at Client-side hooks

    Approval-timing analysis surfaces alert-fatigue (response under 2s across more than 50 approvals); typed-confirmation mismatch events; out-of-band channel decisions joined to session.

  • Supply chain at Client-side hooks

    MCP allowlist violation events; tool-description hash mismatch alerting; lockfile diff in CI logs centralized; pre-commit dependency scan results.