02 / CONTROL · AI agent security · MCP security · runtime control
Control the action, preserve the proof.
Evaluate instruction, retrieval, identity, purpose, tool, target, data, and sequence context before a consequential agent action, and preserve the reason for investigation and replay.
Join authority, action context, policy, enforcement, and exact replay so a runtime control can be inspected, not merely asserted.
Runtime agent action security
Authorize every consequential agent action with identity, purpose, context, and policy.
Turn an opaque prompt-to-tool sequence into a contextual runtime decision with a reviewable enforcement, exception, and investigation record.
An approved agent reads untrusted content and attempts the wrong action with valid authority.
A service agent can read external documents, retrieve internal records, and use a delegated identity to update a downstream business system.
- Decision
- Allow the legitimate path, reduce scope, hold for human approval, redact, reroute, or block where the insertion point is verified.
- Consequence
- A valid identity and tool can still produce material impact when purpose, target, arguments, and sequence are not evaluated together.
The agent reads an approved request, retrieves the permitted record, and proposes the expected bounded update.
Instructions hidden in retrieved content redirect the same authorized tool toward a different target and a broader change.
Illustrative system and evidence model. It explains the decision structure; it is not a customer environment, product capture, compatibility statement, or measured result.
HOW IT WORKS
Move from system context to control and verification.
Follow the operating path from the initial scope through observation, action, and a verified outcome.
Select a stage to inspect its input, decision, product role, and output. The reference model is published; named interfaces, deployment behavior, efficacy, and availability require representative evidence.
WHERE COSMIPHER FITS
Add connected AI decision context without replacing authoritative controls.
The reference architecture separates evidence sources, the Cosmipher decision boundary, the operating handoff, and the systems that retain authority.
Authoritative system context
Instruction, retrieval, memory, identity, purpose, tool request, target, policy, posture, and sequence evidence visible at the selected boundary
Connected decision evidence
Cosmipher AI Firewall evaluates the proposed action and the safest response supported by the verified insertion point
Decision consumed by the team
Allow, reduce, hold, redact, reroute, block, or escalate record plus investigation and replay evidence
This diagram shows the product relationship. Provider, interface, deployment mode, data path, and available control actions are confirmed for the selected environment.
API gateways and WAF
Requests, routes, authentication, payload patterns, rate limits, and conventional application threats at the gateway boundary.
Agent purpose, delegated authority, retrieved context, tool semantics, multi-step behavior, and the proposed downstream action.
IAM, PAM, and DLP
Identity, entitlement, privileged access, classified data, and policy events in their authoritative domains.
How those controls relate to one agent session, tool request, intended purpose, action sequence, and safer permitted path.
SIEM, SOAR, and observability
Events, alerts, traces, telemetry, correlation, investigations, and response workflows.
The AI interaction, policy rationale, action context, enforcement outcome, and replay case that explain the agent-specific event.
OPERATING OUTCOMES
Pair the technical record with the work it makes possible.
These are intended operating consequences of the reference workflow, not measured performance or risk-reduction claims.
Action-level context
Join the attempted action to the relevant instruction, identity, purpose, data, tool, target, sequence, and posture evidence.
Give the operator the complete action path instead of another isolated alert.Proportionate decision
Choose the safest supported response at the verified control point instead of reducing every risk to allow or block.
Apply the least disruptive response the evaluated boundary can safely support.Safer permitted path
Where policy allows, preserve the legitimate objective through reduced scope, changed destination, redaction, or human approval.
Protect the business task without granting the unsafe action.Evidence for response
Retain the reason, applied policy, resulting action, exception, and replay context required for investigation and improvement.
Reconstruct why the decision happened and test whether the control now holds.START WITH ONE PRODUCT
Deploy the product closest to the immediate risk.
Add other Cosmipher products when the operating scope requires more posture, testing, runtime, or artifact context.
Cosmipher AI Firewall
Evaluates connected runtime context, produces the policy decision, applies verified enforcement, and preserves the action record.
Inspect AI Firewall →ADD ONLY WHEN THE EVIDENCE QUESTION REQUIRES IT
AgentSPM
ConditionalWhen: The runtime decision depends on owner, posture, delegated authority, reachability, or approval context.
Receives: Asset, identity, tool, data, purpose, and posture relationships.
Inspect AgentSPM →Cosmipher AI Security Testing
ConditionalWhen: An unsafe action must be reproduced and replayed against the selected control.
Receives: Attack trace, regression case, and control-verification evidence.
Inspect AI Security Testing →Cosmipher AI Supply Chain Security
ConditionalWhen: The exact model, dataset, prompt, or artifact version changes runtime interpretation.
Receives: Version identity, provenance, composition, and inherited-risk evidence.
Inspect AI Supply Chain Security →REPRESENTATIVE OUTPUT
See how the result is structured and handed to the operating team.
The example uses non-customer data to show the information structure. It is not a live customer environment or a measured outcome.
Runtime decision and replay record
Illustrative structure for the evidence connecting an attempted agent action to its authority, policy decision, response, and replay result.
- 01Action pathRecorded
- Retrieved document → delegated identity → update tool → downstream record
- 02Decision contextReview
- Purpose matches · target changed · arguments exceed reviewed scope
- 03Selected responseRecorded
- Hold action and present the bounded legitimate alternative
- 04Control proofOpen
- Insertion point, timeout, failure mode, and permitted path require replay
- 05Replay conditionRecorded
- Repeat the same action against the selected policy and exact environment
Every item remains connected to its source, scope, owner, version, limitations, and permitted conclusion.
Consequential action path
The instruction-to-action sequence, identities, tools, data, destinations, dependencies, and observed control points.
Decision-context record
The context available at the boundary, the applicable policy, the reason for the decision, and the safer permitted path.
Enforcement feasibility
Which actions can be observed or controlled at the selected insertion point, with failure and recovery questions still requiring verification.
Investigation timeline
A connected record of the event, decision, response, exception, and resulting system behavior.
Replay and residual risk
The exact scenario used to verify the control, the observed result, and what remains outside the evaluated boundary.
SCOPED EVALUATION
Validate the solution against one consequential system.
Scope, authorization, environment, information handling, stop conditions, and permitted activity are agreed before evaluation.
- 01Trace
Choose one consequential action path
Define the agent, identity, instruction sources, tools, target, data, control point, expected legitimate path, and stop conditions.
OUTPUTAuthorized runtime-path scope - 02Observe
Establish available decision context
Determine which inputs, messages, identities, arguments, results, sequences, and outcome signals are observable at the selected boundary.
OUTPUTContext and control-point map - 03Exercise
Test the unsafe and permitted paths
Run an agreed scenario to inspect the proposed decision, enforcement behavior, fallback path, evidence, and operator handoff.
OUTPUTDecision and enforcement evidence - 04Verify
Replay and record the boundary
Re-run the exact scenario against the selected control and document the conclusion, limitations, residual risk, and next decision.
OUTPUTRuntime decision and replay record
The record states the boundary, evidence, result, owner, limitations, residual conditions, and the change that invalidates or reopens the conclusion.
Discuss this evaluation →DEPLOYMENT VALIDATION
Confirm technical fit for the selected environment.
Review the interfaces, deployment behavior, supported actions, and proof required before implementation.
Decision model
The context-to-action and replay sequence shown on this page is the public reference workflow.
Insertion point and enforcement
Interfaces, observable context, supported responses, timeout, failure, rollback, and degraded behavior must be confirmed.
Performance and efficacy
Latency, throughput, bypass resistance, false decisions, and control results require representative measurement.
Control requires a verified insertion point
A policy can affect an action only where the selected integration can observe and safely influence that action before impact.
Observable context defines the decision
Identity, tool, sequence, data, and outcome claims are limited to the context that the selected interface actually exposes.
Runtime does not imply a performance result
Latency, throughput, concurrency, streaming, timeout, and degraded-mode behavior require reproducible measurement in the proposed environment.
Detection is not infallible
Evaluation must address bypass, ambiguity, false decisions, policy conflict, failure behavior, and the legitimate path that remains available.
TECHNICAL FAQ
Clarify scope, deployment, and operating fit.
How is this different from a prompt filter?
The decision model includes content plus identity, purpose, permission, session, retrieval, memory, tool arguments, destination, sequence, posture, and the proposed action. Exact context remains interface-dependent.
Does this replace IAM, DLP, API gateways, or security operations?
No. Those systems remain authoritative for their domains. Cosmipher adds AI- and agent-specific context and connects its decision evidence to the existing control and response stack.
Can every agent action be blocked?
No general enforcement claim is made. The available actions depend on the verified insertion point, interface semantics, application behavior, timeout and failure handling, and safe rollback path.
Can the solution begin in observe-only mode?
The evaluation can begin by establishing visibility and decision quality before selected controls are exercised. Actual rollout modes and operating behavior must be verified for the proposed environment.
What is the smallest useful evaluation?
One consequential tool or system action with a legitimate business path, an agreed unsafe scenario, an observable control point, and clear stop conditions.
START WITH SECURE OPERATIONS