AI Agent Security — constrained execution

securityv1

/01 Views

Request and intent boundarysecurity
Tool action authorizationsecurity
Information and memory boundarysecurity
Continuous supervisionsecurity
Delegation governancesecurity
Constrained plan generator → Tool selection brokersecurity
Tool capability gate → Per-action authorization evaluatorsecurity
Intent and injection screening → Untrusted retrieval sanitizationsecurity
Isolated tool executor → Agent action monitorsecurity
Behavior and risk assessment → Human approval gatesecurity
Cancellation and revocation → Isolated tool executorsecurity
Least-privilege delegation limits → Tool selection brokersecurity
Human approval gate → Tool capability gatesecurity

/02 About

Identity-scoped AI agent runtime with untrusted-input isolation, tool-call authorization, human approval, memory protection, action audit and kill-switch.

Purpose: Identity-scoped AI agent runtime with untrusted-input isolation, tool-call authorization, human approval, memory protection, action audit and kill-switch. Architecture scope: independently reconstructed reference responsibilities, operational flows, policy decisions, assurance concerns, exception pathways and security boundaries. Grouped viewpoints describe coherent service or activity sequences. Focused trace views expose inter-domain obligations and information exchanges. Adoption: refine control and data-flow semantics to the enterprise ecosystem; map resource owners, role and workload identities, interfaces, failure policies, information classification, privacy obligations, deployment options and operational evidence. Reference elements alone do not establish an authorization, compliance result, formal proof, cryptographic assurance, or production readiness. Public conceptual basis: https://genai.owasp.org/llm-top-10/. This is an original Arq vendor-neutral interpretation, not an official implementation diagram or an endorsed/certified solution.

Published by Lattix · 20 elements · 23 relationships · validated on publish

/03 Contents

Business Actor
Requesting user
Application Component
Agent request boundary, Intent and injection screening, Constrained plan generator, Tool selection broker, Per-action authorization evaluator, Human approval gate, Isolated tool executor, Untrusted retrieval sanitization, Identity-scoped retrieval, Agent memory policy guard, Agent action monitor, Behavior and risk assessment, Cancellation and revocation, Tool capability gate
Data Store
Protected context and provenance, Tool-use and decision evidence
Role
Delegated access owner
Policy
Least-privilege delegation limits
Application
External tool and resource service