Public research guide

Research Map

A connected path through enterprise-agent architecture, runtime governance, evidence, and executable adversarial evaluation.

Michael K. SalemePublished August 23, 2026Research guide

Core proposition

Authorization is necessary, not sufficient.

Enterprise agent systems need governance that evaluates more than who is authorized. It must also assess how an authorized agent behaves, what evidence supports an action, and how risk compounds across sessions. The work below moves from decision context to enterprise architecture, runtime governance, and executable adversarial evaluation.

Context

Why decision load matters

Decision Load Index

An optional entry point for the human and organizational context. It examines how unresolved decisions, inputs, commitments, and scope create cognitive burden before the discussion turns to autonomous systems.

1. Governance problem

Authorization is not behavior

Constitutional Self-Governance for Autonomous AI Agents

Introduces the WHO versus HOW gap: authentication, access control, and audit logging are necessary, but do not by themselves constrain an agent's decisions under changing conditions.

2. Architecture

Agents are a workforce, not an application feature

Enterprise Agent Architecture

Places autonomous agents within enterprise architecture as actors with delegated authority, capabilities, control-plane dependencies, and governance obligations.

3. Runtime control

Systems must be able to refuse authorized actions

Authorized but Refused

Provides the operational-telemetry layer: governance is credible only when a running system can constrain, record, and explain decisions made under granted authority.

4. Aggregate risk

Individually authorized actions can compound

Authorized but Composed

Explains why per-call approval is insufficient when sequences of individually acceptable actions accumulate across sessions.

5. Monitoring

Behavioral drift can normalize over time

Detecting Normalization of Deviance in Multi-Agent Systems

Extends runtime governance into monitoring: gradual behavioral drift can be missed by stateless or threshold-only monitoring.

6. Evaluation boundary

Identity controls do not test protocol behavior

Beyond Identity Governance

Moves from architecture and monitoring to adversarial evaluation across MCP, A2A, L402, and x402. The question is how an agent system behaves when those protocol boundaries receive hostile traffic.

7. Evidence standard

A receipt must prove what it claims

These works define the evidence layer. Signatures, receipts, and checks do not alone establish that an executed action was authorized or that an artifact supports the claim it makes.

8. Executable implementation

Adversarial evaluation as a practical instrument

Agent Security Harness

The practical evaluation instrument: executable adversarial security tests that operationalize protocol and governance claims.

9. Ecosystem model

Contributions need integrity and trust boundaries

Community-Driven Security for AI Agents

Sets out an approach for accepting adversarial-evaluation contributions while preserving integrity and trust boundaries. The linked version is v1.1, which corrects a CVE misattribution in v1.0.

Supporting research

A bounded evidence pack on observable behavior

AI News Evidence Pack

This evidence pack supports the broader interest in observable behavior and evidence discipline, but is not a prerequisite for the agent-governance path.

Research record

Where each record belongs

  • Zenodo: archival record, DOI source, and version history.
  • ORCID: curated identity and discovery record that links to canonical DOIs.
  • PubPoint: this public reading guide and editorial context.
  • GitHub: the relevant executable implementation and source artifacts.