Public research guide
Research Map
A connected path through enterprise-agent architecture, runtime governance, evidence, and executable adversarial evaluation.
Core proposition
Authorization is necessary, not sufficient.
Enterprise agent systems need governance that evaluates more than who is authorized. It must also assess how an authorized agent behaves, what evidence supports an action, and how risk compounds across sessions. The work below moves from decision context to enterprise architecture, runtime governance, and executable adversarial evaluation.
Context
Why decision load matters
Decision Load Index
An optional entry point for the human and organizational context. It examines how unresolved decisions, inputs, commitments, and scope create cognitive burden before the discussion turns to autonomous systems.
1. Governance problem
Authorization is not behavior
Constitutional Self-Governance for Autonomous AI Agents
Introduces the WHO versus HOW gap: authentication, access control, and audit logging are necessary, but do not by themselves constrain an agent's decisions under changing conditions.
2. Architecture
Agents are a workforce, not an application feature
Enterprise Agent Architecture
Places autonomous agents within enterprise architecture as actors with delegated authority, capabilities, control-plane dependencies, and governance obligations.
3. Runtime control
Systems must be able to refuse authorized actions
Authorized but Refused
Provides the operational-telemetry layer: governance is credible only when a running system can constrain, record, and explain decisions made under granted authority.
4. Aggregate risk
Individually authorized actions can compound
Authorized but Composed
Explains why per-call approval is insufficient when sequences of individually acceptable actions accumulate across sessions.
5. Monitoring
Behavioral drift can normalize over time
Detecting Normalization of Deviance in Multi-Agent Systems
Extends runtime governance into monitoring: gradual behavioral drift can be missed by stateless or threshold-only monitoring.
6. Evaluation boundary
Identity controls do not test protocol behavior
Beyond Identity Governance
Moves from architecture and monitoring to adversarial evaluation across MCP, A2A, L402, and x402. The question is how an agent system behaves when those protocol boundaries receive hostile traffic.
7. Evidence standard
A receipt must prove what it claims
These works define the evidence layer. Signatures, receipts, and checks do not alone establish that an executed action was authorized or that an artifact supports the claim it makes.
8. Executable implementation
Adversarial evaluation as a practical instrument
Agent Security Harness
The practical evaluation instrument: executable adversarial security tests that operationalize protocol and governance claims.
9. Ecosystem model
Contributions need integrity and trust boundaries
Community-Driven Security for AI Agents
Sets out an approach for accepting adversarial-evaluation contributions while preserving integrity and trust boundaries. The linked version is v1.1, which corrects a CVE misattribution in v1.0.
Supporting research
A bounded evidence pack on observable behavior
AI News Evidence Pack
This evidence pack supports the broader interest in observable behavior and evidence discipline, but is not a prerequisite for the agent-governance path.
Research record
Where each record belongs
- Zenodo: archival record, DOI source, and version history.
- ORCID: curated identity and discovery record that links to canonical DOIs.
- PubPoint: this public reading guide and editorial context.
- GitHub: the relevant executable implementation and source artifacts.