Agentic Covenants

Identify (ID) · Authorization

Authorization at the Discovered layer

external · Outside the agent entirely

What agents exist, what they touch, what threats they face?

What this cell does

K8s RBAC API list, AWS IAM Access Analyzer effective permissions, Kyverno PolicyReports of policies actually applied.

Artifacts (1)

record.yamlview on GitHub
# ABOUTME: What the discovered layer records for the authorization concern, and which mismatch rules consume it.
# ABOUTME: Read by scripts/reconcile_inventory.py to compare the three layers against each other.

cell:
  id: authorization.server-side
  concern: authorization
  layer: server-side
  authority: discovered
  records: "Effective permissions resolved from the platform: bound RBAC, attached IAM policies."

fields:
  - authorization_runtime.rbac_role_ref
  - authorization_runtime.iam_policy_arns

feeds_rules:
  - scope_drift
  - shadow_agent

Cell notes

Inventory, Authorization / Discovered

What this cell records. The runtime-effective permissions, regardless of declared scope.

Sources

  • - kubectl auth can-i --list --as=system:serviceaccount:agent-X:claude-code for every agent SA.
  • - aws accessanalyzer list-findings for unused permissions per principal.
  • - kubectl get policyreports -A for which Kyverno policies are actually applying to which agents.

Cross-layer

Discovered effective permissions > operator-declared scope = scope creep. Audit and either tighten or amend the charter.

Citation

NIST CSF 2.0 ID.RA-09, ID.RA-01. NIST AI RMF MAP 5.1. NIST SP 800-207.

Crosswalk

NIST CSF 2 0ID.RA-09, ID.RA-01
NIST AI RMFMAP 5.1
CSA MAESTROLayer 4, Layer 6
OTHERNIST SP 800-207