Evidence library · Communities and Working groups

CoSAI Workstream 4 — Agentic Security

Vendor-neutral architecture guidance for securing agentic systems, from an OASIS Open Project.CoSAI does not certify anything, so there is no conformance language to overclaim. These are design inputs.

Last reviewed:

A note on the Coalition for Secure AI's agentic workstream (Workstream 4) and which AAES design decisions its publications informed. CoSAI publishes guidance, not assessments; this page is a design-input map, not an alignment claim.

These pages describe the product. They are not a certification or a legal opinion.

Reading this note

The workstream's own publications are authoritative for their content; dates are cited because the workstream is active and later revisions may change recommendations. AAES uses these publications as design inputs. Nothing here implies CoSAI review or endorsement of AAES.

Instrument identity

Title
CoSAI Workstream 4 (agentic security): the CoSAI Principles, the MCP security taxonomy (January 2026), and the agentic identity-and-access-management paper (March 2026)
Issuing body
Coalition for Secure AI (CoSAI), an OASIS Open Project
Instrument type
Vendor-neutral architecture guidance (not a standard, not a certification program)
Official sources
Coalition for Secure AI, the CoSAI OASIS repositories, and the Workstream 4 mailing list (public archives).

Question

Which AAES design decisions did the workstream's publications bear on, and can a reviewer inspect the results?

The MCP security taxonomy (January 2026) bears on bypass prevention on every in-scope path (AARM R1.02) and least privilege at the tool boundary (R7); the agentic IAM paper (March 2026) bears on identity binding (R6) and the delegation-chain narrowing rules (R6.06); the CoSAI Principles line up with the scope discipline AARM's S.01 asks for. For procurement teams, these are the architecture references AAES's connector and delegation designs can be discussed against.

Selected contribution

The following controls sit beside the workstream's published themes. Their scope is the action layer, not the workstream's catalog as a whole.

Selected CoSAI WS4 themes and AAES control boundaries
WS4 publication themeWhat a reviewer can examine in AAESBoundary
MCP security taxonomy (January 2026)The connector enforcement contract: an MCP-facing connector must declare its custody model, and a pass-through capability is refused at the connector gate rather than silently governed. Least privilege at the tool boundary: agents only see permitted capabilities.The contract governs connectors registered with AAES. Activity outside AAES is visible only where telemetry is supplied.
Agentic identity and access management (March 2026)Identity binding: every registered agent has at least one accountable human manager. Delegation chains: per-hop narrowing is verified, so a delegated grant can only shrink in scope, never widen.Recorded identity and delegation shape do not establish that an underlying human decision was correct.
CoSAI Principles (scope discipline)The internal claim document names its exclusions prominently — alternate credential paths, pass-through custody, and the open organizational gates — rather than claiming broad coverage.The claim document is internal and unsubmitted; it is a claim document, not a conformance claim.

Preconditions and gaps

  • Guidance can be revised. When the agentic IAM paper is finalized, AAES will review its delegation-depth checks against the recommendations and record any differences.
  • Design input is not review. CoSAI has not reviewed AAES, and these mappings are AAES's own reading.
  • Credential-path control is required. Activity outside AAES is visible only where telemetry is supplied. Observation is not enforcement.
  • No production adoption as of this review. Clients operate their own deployments; AAES does not offer a hosted deployment.

For implementation and testing details beyond this note, use Security and implementation posture and the evaluation page. Results from a client's test tenant are produced during a scoped evaluation.

Client responsibility

The organization makes its own architecture decisions. The workstream's publications are design inputs to that work, not obligations AAES discharges for the client. The client remains the regulated entity.

Identify the credential path, actions, and evidence questions to examine in a client test tenant.

Scope an evaluation