Across the chain · Mapped to OpenCRE · Stable permalinks

AgenTrust
Agentic Controls

A checklist of thirty safeguards for AI agents: who the agent is, what it may do, what gets recorded, and how to stop it. Each control is one requirement, linked to the matching entry in OpenCRE, a free public catalog that connects security standards. Every control has a fixed web address, so other standards can cite it without the link breaking.

30 controls · 66 OpenCRE links · 57 Common Requirements
How to read this

The links point outward on purpose

Most of what an AI agent needs is not new. Checking identity, giving only the access a task needs, keeping logs, handling malicious input and limiting how fast things happen are decades old. OpenCRE already links them across security standards such as ASVS, CWE, ISO 27001, NIST 800-53, SAMM and the OWASP AI Exchange. So each control below points to the existing OpenCRE entry, called a Common Requirement, instead of restating it.

Where a control looks new, it is usually an old requirement applied to something new: software acting on its own instead of a person, a permission handed down from another permission, or a computer that the party doing the checking does not control. The OpenCRE links make that visible.

This page maps topics and makes no conformance claim. A link to a Common Requirement says which topic a control belongs to. It is not evidence that anything is built, tested or in use.

The control set

Thirty controls

Each control gives a plain summary first, then the exact requirement text that standards cite. Some controls apply at one specific moment in the agent's work, shown as a tag, for example pre_tool_call (just before a tool runs) or agent_startup (when the agent starts). Fourteen of the thirty have one. The rest apply throughout and carry no tag.

E1 · Identity and authority

AT-01 Agent identity credential

agent_startup

The agent proves who it is with its own credential, separate from the person who started it, before anything decides what it may do.

Requirement: The agent presents a credential bound to its own identity, distinct from the identity of the user who invoked it, before any authorization decision is made on its behalf.

Common Requirements: Authentication Authentication mechanism

Permalink: https://agentrust-io.com/go/agent-identity-credential/

AT-02 Agent key binding and custody

The key an agent signs with is tied to the agent's identity and stored so it cannot be taken and used apart from that identity.

Requirement: The agent's signing key is bound to its declared identity and held so that possession of the key cannot be separated from the identity it asserts.

Common Requirements: Secret storage Do not use static secrets

Permalink: https://agentrust-io.com/go/agent-key-binding/

AT-03 Capability attenuation across the delegation chain

pre_tool_call

An agent handing work to another agent can pass on the same or fewer permissions, never more, and the chain of handoffs has a length limit.

Requirement: A grant passed to a sub-agent is a subset of the grant it derives from. Delegation depth is bounded and no hop may widen scope.

Common Requirements: Minimize permissions Model action privilege minimization

Related specification: cA2A

Permalink: https://agentrust-io.com/go/capability-attenuation/

AT-04 Declared agent purpose and scope

The agent states what it is for and where its task ends, in a form software can check as well as one people can read.

Requirement: The agent declares its purpose and the boundary of its task in a form a policy engine can read, not only a form a person can read.

Common Requirements: Documentation of all components' business or security function AI user transparency

Related specification: Agent Manifest

Permalink: https://agentrust-io.com/go/agent-purpose-declaration/

AT-05 Declared capability manifest

agent_startup

Before it runs, the agent lists the tools and access it may use, and it can never be given more than that list.

Requirement: The agent declares the tools and scopes it may use before it runs, and that declaration is the upper bound on what it can be granted.

Common Requirements: Model action privilege minimization Maintain/manage inventory of third party components

Permalink: https://agentrust-io.com/go/capability-manifest/

E2 · Behaviour and accountability

AT-06 Structured action logging

Every action the agent takes is logged in a fixed format: who acted, what they did, to what, and which decision allowed it.

Requirement: Every action an agent takes is recorded in a structured form carrying the actor, the action, the target, and the decision that permitted it.

Common Requirements: Log relevant Log access control decisions Log events sufficiently to recreate their order

Permalink: https://agentrust-io.com/go/structured-action-logging/

AT-07 Signed, third-party-verifiable evidence record

The action log is signed, so someone who does not trust whoever runs the log can still check who acted and what was decided.

Requirement: The action record is signed so that a party who does not trust the operator of the log can still verify who acted and what was decided.

Common Requirements: Log integrity Audit & accountability

Related specification: TRACE

Permalink: https://agentrust-io.com/go/verifiable-evidence-record/

AT-08 Behavioural baseline for an agent

Before an agent is trusted to work unsupervised, its normal behavior is measured, so unusual behavior can be spotted later.

Requirement: Normal behaviour for an agent is characterised before it is trusted with unattended work, so departure from it can be recognised.

Common Requirements: Detect and prevent unusual activity Monitoring

Permalink: https://agentrust-io.com/go/behavioural-baseline/

AT-09 Anomaly detection on agent behaviour

Unusual agent behavior is caught while the agent is running, instead of being pieced together afterwards.

Requirement: Departure from the established baseline is detected during the run rather than reconstructed after it.

Common Requirements: Monitor inference Anomalous AI input handling

Permalink: https://agentrust-io.com/go/agent-anomaly-detection/

AT-10 Policy verdict rationale

post_model_call

Each policy decision records which rule made it and what information it used, so it can be explained without running the agent again.

Requirement: Each policy decision carries the rule that produced it and the inputs it read, so a verdict can be explained without re-running the agent.

Common Requirements: AI user transparency Automated AI oversight

Permalink: https://agentrust-io.com/go/policy-verdict-rationale/

E3 · Data and content

AT-11 Schema validation of agent input

input

Data sent to the agent is checked against an agreed format before the agent uses it.

Requirement: Input reaching the agent is validated against a declared schema before it is used.

Common Requirements: Input validation Enforce JSON schema before processing Enforce schema on type/contents of structured data

Permalink: https://agentrust-io.com/go/input-schema-validation/

AT-12 Prompt injection prevention

input post_model_call

Text the agent reads from documents, websites or tool results is treated as data and can never change the agent's instructions.

Requirement: Instructions arriving inside data are treated as data. Content fetched or returned during a run cannot alter the agent's instructions.

Common Requirements: Direct prompt injection Indirect prompt injection Prompt injection I/O handling Prompt input segregation

Permalink: https://agentrust-io.com/go/prompt-injection-prevention/

AT-13 Personal data protection in agent output

output

Personal data the agent sees or writes is recognized and handled according to its sensitivity, instead of simply being passed along.

Requirement: Personal data in the agent's context and output is identified and handled according to its classification rather than passed through.

Common Requirements: Personal data handling Sensitive AI output handling Data disclosure in model output

Permalink: https://agentrust-io.com/go/output-personal-data/

AT-14 Encoding and injection prevention

output

The agent's output is made safe for whatever system receives it, so it cannot be used to slip commands into that system.

Requirement: Model output is encoded for the interpreter that receives it, so output cannot become an injection in a downstream system.

Common Requirements: Output encoding and injection prevention Encode model output Model output contains conventional injection

Permalink: https://agentrust-io.com/go/output-encoding/

AT-15 Context provenance for agent working memory

The agent records what went into its working memory and where it came from, so tampered information can be traced to its source.

Requirement: What entered the agent's working memory, and from where, is recorded, so a poisoned context can be traced to its source.

Common Requirements: Augmentation data integrity controls Data supply chain management

Permalink: https://agentrust-io.com/go/context-provenance/

E4 · Scope and resources

AT-16 Resource allowlist

pre_tool_call

The data sources and destinations an agent may use are listed in advance, and every call is checked against that list.

Requirement: The data sources and sinks an agent may reach are declared in advance and enforced at the call boundary.

Common Requirements: Whitelist data sources and sinks

Permalink: https://agentrust-io.com/go/resource-allowlist/

AT-17 Tool authorization decision

pre_tool_call

Every tool call is approved or refused by a check outside the AI model, based on the agent's permissions. The model cannot approve itself.

Requirement: Every tool call is an authorization decision made outside the model against the agent's granted scope, not a decision the model makes about itself.

Common Requirements: Model action privilege minimization Strong authorization checking Sanitization and sandboxing

Related specification: cMCP

Permalink: https://agentrust-io.com/go/tool-authorization/

AT-18 Rate limiting on agent actions

There is a limit on how fast an agent can take actions, set separately from how fast it can produce answers.

Requirement: The rate at which an agent may act is bounded independently of the rate at which it may infer.

Common Requirements: Rate limiting against AI input attacks Limit inference resources Denial Of Service protection

Permalink: https://agentrust-io.com/go/agent-rate-limiting/

AT-19 Transaction and spend limits

pre_tool_call

Each agent has limits on the size of a single transaction and on its total spending, checked before each payment goes through.

Requirement: Transaction value and cumulative spend are bounded per run and per agent, and enforced before the call rather than reconciled after it.

Common Requirements: Impact limitation of unwanted model behaviour Enforce additional authorization and segregation of duties

Permalink: https://agentrust-io.com/go/transaction-limits/

AT-20 Blast radius containment for agent execution

The agent runs inside walls that limit how much a hijacked or mistaken run can reach.

Requirement: An agent executes inside a boundary that limits what a compromised or mistaken run can reach.

Common Requirements: Sandbox, containerize and/or isolate applications at the network level Impact limitation of unwanted model behaviour

Permalink: https://agentrust-io.com/go/blast-radius-containment/

E5 · Response and recovery

AT-21 Circuit breaker on agent loops

post_tool_call

An agent stuck repeating itself or never finishing is stopped automatically, without bringing down the agents that depend on it.

Requirement: Repeating or non-terminating agent loops are broken automatically, and a broken loop does not cascade into the agents depending on it.

Common Requirements: Impact limitation of unwanted model behaviour Fail securely

Permalink: https://agentrust-io.com/go/agent-circuit-breaker/

AT-22 Terminate a running agent

agent_shutdown

An operator can stop a running agent, and the stop also applies to work the agent has already started.

Requirement: A running agent can be stopped by an operator, and the stop takes effect on work already in flight.

Common Requirements: Human AI oversight Incident response

Permalink: https://agentrust-io.com/go/agent-termination/

AT-23 Agent session revocation

An agent's session and its permissions can be cancelled at once, without waiting for them to expire.

Requirement: An agent's session and the authority attached to it can be revoked without waiting for expiry.

Common Requirements: Minimize session life Enable option to log out from all active session

Permalink: https://agentrust-io.com/go/agent-session-revocation/

AT-24 State rollback after an agent action

Changes an agent made can be found and undone on their own, without restoring the whole system from a backup.

Requirement: State an agent changed can be identified and reversed, distinctly from restoring a backup of the whole system.

Common Requirements: Backup Change management

Permalink: https://agentrust-io.com/go/agent-state-rollback/

AT-25 Graceful degradation on policy engine failure

If the system that enforces the rules goes down, the agent falls back to a defined safe behavior instead of running with no rules.

Requirement: When the policy engine is unavailable the agent degrades to a defined and safe behaviour rather than to an unenforced one.

Common Requirements: Fail securely

Permalink: https://agentrust-io.com/go/graceful-degradation/

A · Attested primitives

AT-26 Runtime attestation evidence

agent_startup

The hardware produces proof of what software is really running, and someone who does not control that hardware checks the proof.

Requirement: Evidence of what is actually executing is produced by the platform at startup and appraised by a relying party that does not control that platform.

Common Requirements: Allow only trusted sources both build time and runtime; therefore perform integrity checks on all resources and code Runtime model integrity controls

Related specification: TRACE

Permalink: https://agentrust-io.com/go/runtime-attestation-evidence/

AT-27 Transparency-log anchoring of evidence

Evidence records are kept in a log that can only be added to, so nobody can quietly rewrite a record later.

Requirement: Evidence records are anchored in an append-only log so a record cannot be rewritten after the fact without detection.

Common Requirements: Log integrity

Related specification: TRACE

Permalink: https://agentrust-io.com/go/evidence-transparency-anchoring/

AT-28 Attested agent-to-agent channel

Before one agent passes permissions to another, it checks what the other agent actually is, beyond checking that the connection is encrypted.

Requirement: An agent-to-agent channel establishes what the peer is, not only that the channel is encrypted, before scope is passed across it.

Common Requirements: Communication authentication Mutually authenticate application components

Related specification: cA2A

Permalink: https://agentrust-io.com/go/attested-a2a-channel/

AT-29 Continuous usage control after grant

Permission is checked again for as long as it lasts, and the conditions attached to it keep applying after it is granted.

Requirement: Authorization is re-evaluated for the life of a grant, and obligations attached to a grant survive the moment it was issued.

Common Requirements: Strong authorization checking Minimize session life

Permalink: https://agentrust-io.com/go/continuous-usage-control/

AT-30 Model weight custody against the hosting operator

A model's weights go only to computers that meet the signed release rules, and any custody claim says which protections it relies on.

Requirement: Model weights are released only to a runtime that satisfies the signed release policy. Custody claims state the required platform protections and residual operator trust; physical ownership of the hardware is outside the base custody guarantee.

Common Requirements: Runtime model confidentiality controls Model hosting supply chain mannagement AI model supply chain management

Related specification: Weight Custody Manifest

Permalink: https://agentrust-io.com/go/model-weight-custody/

Limits

What this page does not do

This page is generated from agentic-controls.json by build-controls.py. Edit the data, not this file.