Agentic Covenants / Agentic Sentinels Matrix
Identity at Server-side enforcement
This layer is external-and-authoritative.
K8s audit log captures every agent SA action; CloudTrail with Object Lock; SIEM rules on out-of-hours, unexpected source IP, identity reuse.
Maps to
- NIST CSF 2.0
- DE.CM-01, DE.CM-09, DE.AE-02
- Other
- NIST SP 800-92