Observe
Public information and low-impact questions.
Draft v0.1 / Open standard
A practical baseline for securing AI agents, models, data, tools, and the decisions they make.
The premise
An AI system is not trusted because it has a valid identity. It is trusted only for this action, against this resource, with this context, under this policy.
01 / The standard
Use the same language whether the request comes from a person, an agent, a workflow, or a supplier.
Permit with scope, lifetime, and audit requirements.
Reduce capability, redact data, or require approval.
Reject the request and record the reason.
Isolate the subject, model, context, or tool.
02 / Risk levels
Public information and low-impact questions.
Internal retrieval and low-impact generation.
Business data changes and external messages.
Financial, medical, production, or release actions.
Irreversible, high-impact, large-scale automation.
03 / Control domains
Unique, short-lived, revocable identities for users, services, and agents.
Every R1+ operation receives a decision enforced at the service boundary.
Least data, tenant isolation, provenance, redaction, and untrusted context.
Version-pinned models with known provenance, evaluation, and capability limits.
Independent authorization, schema validation, quotas, sandboxing, and rollback.
Decisions correlate subject, policy, model, data, tool, and outcome.
04 / Adopt the baseline
You do not need to secure every model on day one. Register the assets, put a decision point in front of one high-value tool, and collect evidence from the first request.
Identity, agent, model, data, and tool.
Subject, action, resource, context, and risk.
Allow, constrain, deny, or quarantine.
Keep evidence that the decision happened.