A note on the Coalition for Secure AI's agentic workstream (Workstream 4) and which AAES design decisions its publications informed. CoSAI publishes guidance, not assessments; this page is a design-input map, not an alignment claim.
These pages describe the product. They are not a certification or a legal opinion.
Reading this note
The workstream's own publications are authoritative for their content; dates are cited because the workstream is active and later revisions may change recommendations. AAES uses these publications as design inputs. Nothing here implies CoSAI review or endorsement of AAES.
Instrument identity
- Title
- CoSAI Workstream 4 (agentic security): the CoSAI Principles, the MCP security taxonomy (January 2026), and the agentic identity-and-access-management paper (March 2026)
- Issuing body
- Coalition for Secure AI (CoSAI), an OASIS Open Project
- Instrument type
- Vendor-neutral architecture guidance (not a standard, not a certification program)
- Official sources
- Coalition for Secure AI, the CoSAI OASIS repositories, and the Workstream 4 mailing list (public archives).
Question
Which AAES design decisions did the workstream's publications bear on, and can a reviewer inspect the results?
The MCP security taxonomy (January 2026) bears on bypass prevention on every in-scope path (AARM R1.02) and least privilege at the tool boundary (R7); the agentic IAM paper (March 2026) bears on identity binding (R6) and the delegation-chain narrowing rules (R6.06); the CoSAI Principles line up with the scope discipline AARM's S.01 asks for. For procurement teams, these are the architecture references AAES's connector and delegation designs can be discussed against.
Selected contribution
The following controls sit beside the workstream's published themes. Their scope is the action layer, not the workstream's catalog as a whole.
| WS4 publication theme | What a reviewer can examine in AAES | Boundary |
|---|---|---|
| MCP security taxonomy (January 2026) | The connector enforcement contract: an MCP-facing connector must declare its custody model, and a pass-through capability is refused at the connector gate rather than silently governed. Least privilege at the tool boundary: agents only see permitted capabilities. | The contract governs connectors registered with AAES. Activity outside AAES is visible only where telemetry is supplied. |
| Agentic identity and access management (March 2026) | Identity binding: every registered agent has at least one accountable human manager. Delegation chains: per-hop narrowing is verified, so a delegated grant can only shrink in scope, never widen. | Recorded identity and delegation shape do not establish that an underlying human decision was correct. |
| CoSAI Principles (scope discipline) | The internal claim document names its exclusions prominently — alternate credential paths, pass-through custody, and the open organizational gates — rather than claiming broad coverage. | The claim document is internal and unsubmitted; it is a claim document, not a conformance claim. |
Preconditions and gaps
- Guidance can be revised. When the agentic IAM paper is finalized, AAES will review its delegation-depth checks against the recommendations and record any differences.
- Design input is not review. CoSAI has not reviewed AAES, and these mappings are AAES's own reading.
- Credential-path control is required. Activity outside AAES is visible only where telemetry is supplied. Observation is not enforcement.
- No production adoption as of this review. Clients operate their own deployments; AAES does not offer a hosted deployment.
For implementation and testing details beyond this note, use Security and implementation posture and the evaluation page. Results from a client's test tenant are produced during a scoped evaluation.
Client responsibility
The organization makes its own architecture decisions. The workstream's publications are design inputs to that work, not obligations AAES discharges for the client. The client remains the regulated entity.
Identify the credential path, actions, and evidence questions to examine in a client test tenant.
