Agentic Sentinels Matrix
If this concern is breached, how do we know?
Filter
Layers, by what they can actually enforce
- In-agent (forensic only) — forensic
Transcript and tool-call logs from the agent runtime. Forensic value, not real-time. Lethal-trifecta detector at the wrapper layer is the only L1 with detection value.
- Client-side hooks — deterministic-when-shipped
auditd, eBPF, hook decision logs, MCP allowlist violation logs. Tamper-evident only if logs ship to a remote sink owned by the operator, not the agent.
- Server-side enforcement — external-and-authoritative
Kubernetes audit logs, CloudTrail, Falco, Hubble, Kyverno PolicyReports, GitHub webhooks. External to the agent's compromise model.
Showing 5 of 15.
Identity at In-agent (forensic only)
Tool-call logs include credential fingerprint (hash, never raw token); session correlation.
Authorization at In-agent (forensic only)
Tool descriptions logged with each call (forensic).
Blast radius at In-agent (forensic only)
Reasoning trace and tool-call log capture for forensics, plus a lethal-trifecta detector at the wrapper layer that flags when private data, untrusted content, and external communication appear in the same context window. The detector is the only L1 control with real-time detection value, and it runs outside the agent.
Approval gating at In-agent (forensic only)
Confirmation-prompt usage forensically logged.
Supply chain at In-agent (forensic only)
"Where did this dependency come from" forensically traceable through tool-call log.