An agent raises four questions ordinary software does not: whose identity it acts under, which tools it may call, what its memory is allowed to keep, and how far one bad run reaches before something stops it. This reference answers them with twenty-two controls across seven families. Each control names what it requires, where it is enforced, and the one artefact you can point at to show it is real. The OWASP agentic risk IDs sit on every family, so a reviewer gets a published reference rather than your own house opinion.
The first four families bound one agent. These three decide what happens when it talks to other agents, when a single wrong answer becomes a thousand actions, and when somebody has to say afterwards who was answerable for it.
Trust does not transit. An agent accepting a task from another inherits that agent's compromise, so messages are signed and verified with sender identity carried rather than asserted in the payload, hops are capped with the full chain and original principal on every one, and a registry holds every participating agent with its owner, scope and permitted peers. Anything exercising agent patterns the registry does not hold raises an alert.
Cascading failure is the agentic outage: one wrong answer becomes a thousand actions before a person reads the dashboard. Ceilings per run on tool calls, records touched, spend and wall-clock fail closed at the limit. Agents are partitioned so one cannot exhaust another's quota, queue or credential. The kill switch revokes the identity and aborts runs already executing, and it is drilled on a live agent against a clock.
A completion log says what was returned. A plan trace answers why it did that: goal, plan, every decision point, tool call and result on one run ID, with model and prompt versions pinned. The proof is a replay of one named historic run from the trace alone, with a stopwatch on it. Attribution has to survive credential rotation and staff changes, so identifiers are stored rather than the credential.
Goal, constraints and success criteria fixed server-side at dispatch, re-asserted each planning turn, and hashed on the run record. A monitored drift ratio catches the runs that wander off it.
A feature flag blocks new runs and lets dispatched ones finish holding valid credentials. Pair identity revocation at the tool gateway with an abort path the run controller honours mid-plan, then time the drill.
Source, author, session and a type marking the item data rather than instruction, refused at the schema if absent. Three required fields on the write path stop a retrieved instruction becoming a permanent preference.
Value ceilings, record counts, target accounts and destination domains written as policy the gateway evaluates per invocation, with one CI case behind each constraint. Same call, routine or irreversible depending on what is passed.
An identity of its own, argument-level limits on the tools it calls, an objective it cannot be talked out of, memory with an author on every entry, rules for talking to other agents, a bounded run, and a trace you can replay. Seven families, twenty-two controls.
An objective the agent cannot be talked out of, a stop that reaches work already in flight, and memory writes that carry an author. All three are cheap while the orchestrator is being written and expensive once it is live, since each asks it to hold state it never held.
Yes, and it is the common one. One principal across a fleet makes every action attributable to the platform and to nobody, so nothing can be suspended, reviewed or explained per agent. Give each deployed agent a directory identity with a named human owner, registered by the deploy job.
No. The single-agent and multi-agent overlays under COSAiS are still in draft, built on SP 800-53, so expect a second vocabulary later rather than a different set of controls. Cite the OWASP ASI identifiers now and map across when the overlays are published.
No, deliberately. Trust zones, output handling, retrieval permissions and the model supply chain are assumed here rather than repeated, and they sit in our AI security reference. This catalogue only holds what an agent adds: authority, action, objective, memory, peers, radius and the record.
This paper does not say, on purpose. Agentic Systems Under Regulation is the sibling that works out which duties reach an agent and by when, given that no agentic category exists in law. One control here does carry a date: disclosure and doubt, where Article 50 applies from August 2026.
Platform and application security engineers bounding an agent that already exists. It is a lookup document, so open it at a family rather than reading it through, and read it with the orchestrator and the tool gateway in front of you. Each entry names the component that enforces the control.
Drop your details and we'll send Agentic Systems: An Engineering Reference straight to your inbox - no spam, unsubscribe anytime.
Two weeks on one agent already touching production systems: a per-agent principal, an argument-level allowlist on its riskiest tool, a kill switch drilled against the clock, and an architecture note on blast radius. Yours to keep. SECTION 7 - FAQ - 5 to 8 questions
Book an agent control review