Skip to content

02 / CONTROL · AI agent security · MCP security · runtime control

Control the action, preserve the proof.

Evaluate instruction, retrieval, identity, purpose, tool, target, data, and sequence context before a consequential agent action, and preserve the reason for investigation and replay.

Join authority, action context, policy, enforcement, and exact replay so a runtime control can be inspected, not merely asserted.

Runtime agent action security

Authorize every consequential agent action with identity, purpose, context, and policy.

Turn an opaque prompt-to-tool sequence into a contextual runtime decision with a reviewable enforcement, exception, and investigation record.

BEFOREThe agent's instruction, identity, retrieved context, tool arguments, policy, and downstream result are separated across systems and logs.
DECISION CHANGERuntime decision and replay record
ACCOUNTABLE SPONSORCISO or product security leader
OPERATING OWNERSecurity engineering or AI platform operations
CONTRIBUTORSApplication owner, IAM, data security, platform engineering, and SOC
EVIDENCE CONSUMERSSOC, incident response, system owner, and security leadership
ILLUSTRATIVE SCENARIO MODEL
AI agent security · MCP security · runtime control
HIGH-CONSEQUENCE SCENARIO

An approved agent reads untrusted content and attempts the wrong action with valid authority.

A service agent can read external documents, retrieve internal records, and use a delegated identity to update a downstream business system.

Decision
Allow the legitimate path, reduce scope, hold for human approval, redact, reroute, or block where the insertion point is verified.
Consequence
A valid identity and tool can still produce material impact when purpose, target, arguments, and sequence are not evaluated together.
CONTEXT ASSEMBLED
InstructionIdentityPurposeRetrievalToolTarget
ACTION DECISIONUpdate downstream record?Target changed · arguments exceed reviewed scope
LEGITIMATE PATHBounded updatePreserve the approved business task
SELECTED RESPONSEHOLD · HUMAN APPROVALPresent the safer permitted path
UNSAFE PATHBroader targetStop where control is verified
REPLAYRepeat the exact action against the selected control
LEGITIMATE PATH

The agent reads an approved request, retrieves the permitted record, and proposes the expected bounded update.

RISK PATH

Instructions hidden in retrieved content redirect the same authorized tool toward a different target and a broader change.

Illustrative system and evidence model. It explains the decision structure; it is not a customer environment, product capture, compatibility statement, or measured result.

HOW IT WORKS

Move from system context to control and verification.

Follow the operating path from the initial scope through observation, action, and a verified outcome.

Illustrative solution workflow
Reference model · technology support verified for each scope
INPUT EVIDENCE

Instruction, retrieved content, memory, response, session, tool request, result, and sequence evidence.

AI Firewall
DECISION 01Context assembled
Assemble the action context

What is the agent attempting, and which context can be observed at the selected control point?

DECISION OUTPUT

A normalized interaction and proposed-action record.

Evidence moves to stage 02.

Select a stage to inspect its input, decision, product role, and output. The reference model is published; named interfaces, deployment behavior, efficacy, and availability require representative evidence.

WHERE COSMIPHER FITS

Add connected AI decision context without replacing authoritative controls.

The reference architecture separates evidence sources, the Cosmipher decision boundary, the operating handoff, and the systems that retain authority.

REFERENCE ARCHITECTURE
TOPOLOGY AND SUPPORT VERIFIED FOR EACH SCOPE
01 / EVIDENCE SOURCES

Authoritative system context

Instruction, retrieval, memory, identity, purpose, tool request, target, policy, posture, and sequence evidence visible at the selected boundary

02 / COSMIPHER BOUNDARY

Connected decision evidence

Cosmipher AI Firewall evaluates the proposed action and the safest response supported by the verified insertion point

03 / OPERATING HANDOFF

Decision consumed by the team

Allow, reduce, hold, redact, reroute, block, or escalate record plus investigation and replay evidence

AUTHORITY RETAINED

IAM, DLP, API gateways, application controls, and security operations remain authoritative in their domains

This diagram shows the product relationship. Provider, interface, deployment mode, data path, and available control actions are confirmed for the selected environment.

API gateways and WAF

WHAT IT ALREADY SEES

Requests, routes, authentication, payload patterns, rate limits, and conventional application threats at the gateway boundary.

COSMIPHER ADDS

Agent purpose, delegated authority, retrieved context, tool semantics, multi-step behavior, and the proposed downstream action.

IAM, PAM, and DLP

WHAT IT ALREADY SEES

Identity, entitlement, privileged access, classified data, and policy events in their authoritative domains.

COSMIPHER ADDS

How those controls relate to one agent session, tool request, intended purpose, action sequence, and safer permitted path.

SIEM, SOAR, and observability

WHAT IT ALREADY SEES

Events, alerts, traces, telemetry, correlation, investigations, and response workflows.

COSMIPHER ADDS

The AI interaction, policy rationale, action context, enforcement outcome, and replay case that explain the agent-specific event.

OPERATING OUTCOMES

Pair the technical record with the work it makes possible.

These are intended operating consequences of the reference workflow, not measured performance or risk-reduction claims.

01

Action-level context

Join the attempted action to the relevant instruction, identity, purpose, data, tool, target, sequence, and posture evidence.

Give the operator the complete action path instead of another isolated alert.
02

Proportionate decision

Choose the safest supported response at the verified control point instead of reducing every risk to allow or block.

Apply the least disruptive response the evaluated boundary can safely support.
03

Safer permitted path

Where policy allows, preserve the legitimate objective through reduced scope, changed destination, redaction, or human approval.

Protect the business task without granting the unsafe action.
04

Evidence for response

Retain the reason, applied policy, resulting action, exception, and replay context required for investigation and improvement.

Reconstruct why the decision happened and test whether the control now holds.

START WITH ONE PRODUCT

Deploy the product closest to the immediate risk.

Add other Cosmipher products when the operating scope requires more posture, testing, runtime, or artifact context.

START HERE

Cosmipher AI Firewall

Evaluates connected runtime context, produces the policy decision, applies verified enforcement, and preserves the action record.

Inspect AI Firewall →

ADD ONLY WHEN THE EVIDENCE QUESTION REQUIRES IT

01

AgentSPM

Conditional

When: The runtime decision depends on owner, posture, delegated authority, reachability, or approval context.

Receives: Asset, identity, tool, data, purpose, and posture relationships.

Inspect AgentSPM →
02

Cosmipher AI Security Testing

Conditional

When: An unsafe action must be reproduced and replayed against the selected control.

Receives: Attack trace, regression case, and control-verification evidence.

Inspect AI Security Testing →
03

Cosmipher AI Supply Chain Security

Conditional

When: The exact model, dataset, prompt, or artifact version changes runtime interpretation.

Receives: Version identity, provenance, composition, and inherited-risk evidence.

Inspect AI Supply Chain Security →

REPRESENTATIVE OUTPUT

See how the result is structured and handed to the operating team.

The example uses non-customer data to show the information structure. It is not a live customer environment or a measured outcome.

ILLUSTRATIVE OUTPUT STRUCTURE
NOT A PRODUCT CAPTURE OR CUSTOMER RECORD
DECISION ARTIFACT

Runtime decision and replay record

Illustrative structure for the evidence connecting an attempted agent action to its authority, policy decision, response, and replay result.

CURRENT DECISIONHOLD · HUMAN APPROVAL
01Action pathRecorded
Retrieved document → delegated identity → update tool → downstream record
02Decision contextReview
Purpose matches · target changed · arguments exceed reviewed scope
03Selected responseRecorded
Hold action and present the bounded legitimate alternative
04Control proofOpen
Insertion point, timeout, failure mode, and permitted path require replay
05Replay conditionRecorded
Repeat the same action against the selected policy and exact environment
COMPLETE EVALUATION DELIVERABLES

Every item remains connected to its source, scope, owner, version, limitations, and permitted conclusion.

01

Consequential action path

The instruction-to-action sequence, identities, tools, data, destinations, dependencies, and observed control points.

02

Decision-context record

The context available at the boundary, the applicable policy, the reason for the decision, and the safer permitted path.

03

Enforcement feasibility

Which actions can be observed or controlled at the selected insertion point, with failure and recovery questions still requiring verification.

04

Investigation timeline

A connected record of the event, decision, response, exception, and resulting system behavior.

05

Replay and residual risk

The exact scenario used to verify the control, the observed result, and what remains outside the evaluated boundary.

SCOPED EVALUATION

Validate the solution against one consequential system.

Scope, authorization, environment, information handling, stop conditions, and permitted activity are agreed before evaluation.

  1. 01Trace

    Choose one consequential action path

    Define the agent, identity, instruction sources, tools, target, data, control point, expected legitimate path, and stop conditions.

    OUTPUTAuthorized runtime-path scope
  2. 02Observe

    Establish available decision context

    Determine which inputs, messages, identities, arguments, results, sequences, and outcome signals are observable at the selected boundary.

    OUTPUTContext and control-point map
  3. 03Exercise

    Test the unsafe and permitted paths

    Run an agreed scenario to inspect the proposed decision, enforcement behavior, fallback path, evidence, and operator handoff.

    OUTPUTDecision and enforcement evidence
  4. 04Verify

    Replay and record the boundary

    Re-run the exact scenario against the selected control and document the conclusion, limitations, residual risk, and next decision.

    OUTPUTRuntime decision and replay record
EVALUATION EXITRuntime decision and replay record

The record states the boundary, evidence, result, owner, limitations, residual conditions, and the change that invalidates or reopens the conclusion.

Discuss this evaluation →

DEPLOYMENT VALIDATION

Confirm technical fit for the selected environment.

Review the interfaces, deployment behavior, supported actions, and proof required before implementation.

Published

Decision model

The context-to-action and replay sequence shown on this page is the public reference workflow.

Verify for scope

Insertion point and enforcement

Interfaces, observable context, supported responses, timeout, failure, rollback, and degraded behavior must be confirmed.

Evidence required

Performance and efficacy

Latency, throughput, bypass resistance, false decisions, and control results require representative measurement.

01

Control requires a verified insertion point

A policy can affect an action only where the selected integration can observe and safely influence that action before impact.

02

Observable context defines the decision

Identity, tool, sequence, data, and outcome claims are limited to the context that the selected interface actually exposes.

03

Runtime does not imply a performance result

Latency, throughput, concurrency, streaming, timeout, and degraded-mode behavior require reproducible measurement in the proposed environment.

04

Detection is not infallible

Evaluation must address bypass, ambiguity, false decisions, policy conflict, failure behavior, and the legitimate path that remains available.

TECHNICAL FAQ

Clarify scope, deployment, and operating fit.

How is this different from a prompt filter?

The decision model includes content plus identity, purpose, permission, session, retrieval, memory, tool arguments, destination, sequence, posture, and the proposed action. Exact context remains interface-dependent.

Does this replace IAM, DLP, API gateways, or security operations?

No. Those systems remain authoritative for their domains. Cosmipher adds AI- and agent-specific context and connects its decision evidence to the existing control and response stack.

Can every agent action be blocked?

No general enforcement claim is made. The available actions depend on the verified insertion point, interface semantics, application behavior, timeout and failure handling, and safe rollback path.

Can the solution begin in observe-only mode?

The evaluation can begin by establishing visibility and decision quality before selected controls are exercised. Actual rollout modes and operating behavior must be verified for the proposed environment.

What is the smallest useful evaluation?

One consequential tool or system action with a legitimate business path, an agreed unsafe scenario, an observable control point, and clear stop conditions.

START WITH SECURE OPERATIONS

Join authority, action context, policy, enforcement, and exact replay so a runtime control can be inspected, not merely asserted.