01
Runtime
Strong
Sandboxing, action interception, tool and MCP security, runtime policy, secret and data protection.
Covered
- A check before each tool call in coding agents, validated end to end in Claude Code
- A model proxy, an MCP gateway and a stdio MCP proxy
- An egress proxy that enforces egress rules on real connections
- On-device DLP: secrets and PII masked or blocked
- Placeholder credentials (opt-in): the agent holds a stand-in, not the real key
- Sandbox network policy generated from the same rules for Windows MXC, macOS Seatbelt and an open-source agent sandbox
Where it stops
- No sandbox of its own: it is governance, and its hook fails open if it crashes or times out
02
Accountability
Strong
Audit trail, attribution, behaviour monitoring, incident response.
Covered
- Hash-chained evidence logs: a deleted, reordered or edited record breaks the chain
- A content-free session ledger and exposure ledger on the device
- Events attributed to a keyed actor hash
- A keyed session hash on alerts from a known agent session, so they group together
- Learned-drift and session-risk detection, and a runaway-loop breaker
- Session kill: end the running agent, not just the one call
Where it stops
- No incident-response tool integrations; events stream to a SIEM over OpenTelemetry
03
Governance
Strong
Orchestration governance, policy as code, approvals and escalation, compliance.
Covered
- A signed policy, fleet-wide or per device
- Justify and sign-off: hold a risky act for a signed justification
- The entitlement envelope: an agent's authorized tools, paths and MCP servers, applied to its sub-agents too
- Every rule mapped to the OWASP LLM Top 10, MITRE ATLAS, the OWASP Top 10 for Agentic Applications and the OWASP MCP Top 10 (beta)
Where it stops
- Blocking, sign-off and session kill apply on enrolled devices; an unenrolled device coaches only
04
Access
Partial
Authentication, authorization, credential management, agent-to-agent trust.
Covered
- Tool authorization: MCP allow-lists, server approval and tool-argument checks
- Egress rules per binary, host, port, method and path
- Placeholder credentials, swapped for the real secret only on its own route
Where it stops
- No agent authentication
- No trust between agents beyond recording delegation and scanning the delegated prompt
05
Identity
Partial
Agent and sub-agent identity, lifecycle, provenance, delegation.
Covered
- A keyed actor hash per user and machine
- Workload identity on server-side alerts: container, pod, namespace and node
- Sub-agent spawns recorded
Where it stops
- No per-agent identity registry or lifecycle
- No delegation chain an agent can present