Research
Technical notes for evaluating AI agent security.
Public research for security and platform teams comparing runtime controls for AI coding agents, productivity agents, and MCP tool use. Each brief includes a technical model, concrete evaluation criteria, and the signals a buyer should expect to inspect in a real deployment.
Cowork action lattice
identity
host
repo
tool
Evidence overlay
agent intent layer
t+00
prompt
t+01
tool
t+02
process
endpoint behavior layer
exec
open
connect
MCP control path
policy gateway
Destructive-action chain
content
model
action
block
Decision lattice
identity
host
repo
tool
Pre-execution gateway
policy gateway
Intent overlay timeline
agent intent layer
t+00
prompt
t+01
tool
t+02
process
endpoint behavior layer
exec
open
connect
Injection kill chain
content
model
action
block
Coverage control board
inventory
ring 1
audit
ring 2
warn
ring 3
block
ring 4
Resolver graph
pack resolver
Identity delta loop
normalizer
Enforcement impact ramp
policy impact preview
Evidence envelope
correlation
idaction
+1policy
+2evidence
+3