Agentic Covenants

Identify (ID) · Authorization

Authorization at the Self-declared layer

advisory · Bypassable by language alone

What agents exist, what they touch, what threats they face?

What this cell does

Agent reports allowed-tools list, MCP allowlist hashes, effective scope on registration. Updates on scope change.

Artifacts (1)

record.yamlview on GitHub
# ABOUTME: What the self-declared layer records for the authorization concern, and which mismatch rules consume it.
# ABOUTME: Read by scripts/reconcile_inventory.py to compare the three layers against each other.

cell:
  id: authorization.in-agent
  concern: authorization
  layer: in-agent
  authority: self-declared
  records: "The agent reports the scope it believes it holds: tools, MCP servers, environments."

fields:
  - authorization_runtime.rbac_role_ref
  - authorized_scope.tools_allowlist

feeds_rules:
  - scope_drift

Cell notes

Inventory, Authorization / Self-declared

What this cell records. The agent's report of its current effective scope at startup and on scope changes.

Fields

  • - tools_allowlist[]
  • - mcp_servers_allowlist[] (with hashes)
  • - rbac_role_ref
  • - iam_role_arn
  • - effective_scope_at_startup (snapshot of permissions reported by the agent runtime)

The agent's wrapper sends this on each registration. If the agent's runtime cannot enumerate its own scope (some MCP-only agents cannot), this cell becomes a manifest reference rather than a live snapshot.

Cross-layer

Should match operator-declared scope (charter authoritative). Drift = Sentinels alert.

Citation

NIST CSF 2.0 ID.AM-02. NIST AI RMF MAP 4.1. CSA MAESTRO Layer 7.

Crosswalk

NIST CSF 2 0ID.AM-02
NIST AI RMFMAP 4.1
CSA MAESTROLayer 7