Agentic Covenants

Agentic Inventory Matrix

NIST CSF 2.0 · Identify (ID) · 5 concerns × 3 layers

What agents exist, what they touch, what threats they face?
ConcernSelf-declaredadvisoryOperator-declareddeterministicDiscoveredexternal
IdentityWhich agents exist, with what credentials, mapped to which charter, owned by which named human.2 artifactsAgent registers on startup with name, charter ref, owner email, instance ID. Heartbeats. Deregister on shutdown. Dead-mans-switch alerts on heartbeat lapse.1 artifactOperator-maintained registry; agents.yaml in GitOps; ServiceNow CMDB; internal AI inventory tool. Owner-confirmed. Updated on charter signature.3 artifactsCloudTrail / GCP Audit Logs of SA and IAM principal usage. K8s controller watching SA+RoleBinding by naming pattern. Reverse-lookup from credential fingerprints in Sentinels.
AuthorizationWhat scope each agent has. What RBAC roles or IAM principals it uses. What could it touch.1 artifactAgent reports allowed-tools list, MCP allowlist hashes, effective scope on registration. Updates on scope change.1 artifactOperator records authorized scope in registry, linked to RBAC manifest paths and IAM policy ARNs.1 artifactK8s RBAC API list, AWS IAM Access Analyzer effective permissions, Kyverno PolicyReports of policies actually applied.
Blast radiusWorst-case damage if compromised. Environments. Data classes. Revenue or customer impact.1 artifactAgent reports declared risk tier, damage cap, forbidden operations from its charter. Reports current environment and data class access.1 artifactOperator records blast-radius profile per agent. Worst-case impact statement (revenue, customer, compliance).1 artifactThreat-modeling output (MAESTRO Layer 7, MITRE ATLAS, lateral-movement path analysis). Behavioral observation of what the agent has touched.
Approval gatingWho approved, when last reviewed, when next review due, when retirement fires.1 artifactAgent reports last charter signature date, next review due, current charter version on registration. Refuses to start if charter is expired.1 artifactOperator-maintained review calendar. Quarterly attestation. Tracks pending and overdue reviews.1 artifactRegistry of charter files in source control. Last-modified, last-PR-merged. Cross-reference with self-declared and operator-declared.
Supply chainFoundation model, MCP servers, base images, tool versions, dependency tree.1 artifactAgent reports current dependency manifest on registration: foundation model + version, MCP server names + hashes, base image SHA, lockfile fingerprint. Updates on change.1 artifactOperator records authorized-dependency manifest from agent charter. Linked to Covenants L2-C5 and L3-C5 allowlists. Version-controlled audit trail.1 artifactImage-registry pull events, package-manager logs, runtime introspection of loaded models and connected MCP servers, SBOM scanning. Drift between actual and authorized = alert.

Walk a row left to right and ask one question at each layer: if the agent decides to violate this concern, what stops it here? All three populated is defense in depth. Only the in-agent cell populated is an audit finding, because the model can be talked out of it.