Agentic Covenants

Detect (DE) · Authorization

Authorization at the In-agent (forensic only) layer

advisory · Bypassable by language alone

If this concern is breached, how do we know?

What this cell does

Tool descriptions logged with each call (forensic).

Deliberately empty

This cell has no artifact, and that is the argument rather than a gap. At this layer, for this concern, nothing is enforced. Populating it with an enforcement claim would invert what the framework is saying.

Cell notes

Sentinels, Authorization / In-agent

Control. Tool descriptions logged with each call (forensic).

Strength. Forensic only.

Tooling

  • - Whatever logs your agent runtime emits per tool call. For Claude Code, see ~/.claude/sessions/.

Files in this directory

(None. The capture is a property of the agent runtime; the shipping is handled by ../../identity/in-agent/ship-sessions.sh.)

Verification

Find a known tool call in the shipped session log and confirm its description was captured.

Common mistakes

  • - Trusting tool descriptions in the session log to be authoritative for what the tool will actually do. Tool-description rug-pull (see ../../supply-chain/) means the description at call time may differ from the description at approval time.

Citation

NIST CSF 2.0 DE.CM-09.

Crosswalk

NIST CSF 2 0DE.CM-09