Agentic Sentinels Matrix
If this concern is breached, how do we know?
Filter
Layers, by what they can actually enforce
- In-agent (forensic only) — forensic
Transcript and tool-call logs from the agent runtime. Forensic value, not real-time. Lethal-trifecta detector at the wrapper layer is the only L1 with detection value.
- Client-side hooks — deterministic-when-shipped
auditd, eBPF, hook decision logs, MCP allowlist violation logs. Tamper-evident only if logs ship to a remote sink owned by the operator, not the agent.
- Server-side enforcement — external-and-authoritative
Kubernetes audit logs, CloudTrail, Falco, Hubble, Kyverno PolicyReports, GitHub webhooks. External to the agent's compromise model.
Showing 5 of 15.
Identity at Server-side enforcement
K8s audit log captures every agent SA action; CloudTrail with Object Lock; SIEM rules on out-of-hours, unexpected source IP, identity reuse.
Authorization at Server-side enforcement
RBAC denial events from K8s audit; IAM Access Analyzer findings; Kyverno PolicyReports; OPA decision logs centralized.
Blast radius at Server-side enforcement
Falco runtime rules for shells in agent containers and writes to sensitive paths; Cilium Hubble drops; ResourceQuota near-limit Prometheus alert; VPC Flow Log REJECTs.
Approval gating at Server-side enforcement
GitHub webhook for branch-protection bypass; hourly drift-detection job; deployment-freeze breach alerts; audit on changes to branch protection itself.
Supply chain at Server-side enforcement
Image-pull events with signature verification status; SBOM diff over time per workload; cosign verification failures; egress NetworkPolicy denials to non-allowlisted MCP domains.