Whitepaper

Securing Agentic AI

Governing What the System Does, Not What It Says

Your agent is perfectly sandboxed. It can still delete the production database, because deleting the database is something it was permitted to do. This is a reference architecture for bounding what agents are allowed to do — written for FedRAMP, CJIS, and CMMC boundaries.

What’s inside

  • A threat model spanning goal hijack, indirect injection, memory and vector-store poisoning, tool supply chain, and the internal trust trap in multi-agent systems
  • Authorization verified at the tool boundary, by a component the agent cannot influence
  • Delegation that narrows and never widens, using token exchange with attenuation
  • An evaluation methodology with numeric promotion gates and adaptive adversaries
  • A continuous authorization (cATO) mapping for systems that change with every model update
  • A control crosswalk to NIST SP 800-53 Rev 5 and ISO/IEC 42001

Prefer the short version first? Read The Authorization Blast Radius.

Get the whitepaper

We use this to know who’s reading and to follow up once if it looks relevant. No list, no sharing, no tracking pixels. Email ryan@gooptimal.io and we’ll delete it.