Agentic Trust Framework
Published through
Stewarded byCSAI Foundation
LicenseCC BY 4.0

The Standard for Governing AI Agents.

Five questions every agent must answer. Four levels of autonomy it has to earn. ATF turns Zero Trust into controls you can ship, and audits can pass.

The Five Core Elements · current posture, most companies
01
Identity
Who are you?
Governed
02
Behavior
What are you doing?
Partial
03
Data
In and out?
Ungoverned
04
Segmentation
Where can you go?
Unknown
05
Response
If you go rogue?
Partial

This is what most companies look like today. Most can't fill it in at all. The free assessment takes about 15 minutes.

§ 1

What the Framework Is

ATF is an open specification for governing AI agents with Zero Trust principles. It gives you a practical, implementable way to deploy autonomous agents that deliver value and pass a security audit. Traditional frameworks were built for human users and static systems. Agents are different.

They act on their own

Decisions get made without a human in the loop.

They learn and drift

Behavior changes over time, so trust can't be one-time.

They hold real access

Credentials, data, and permissions to live systems.

They talk to each other

Creating authorization chains no one mapped.

§ 2

The Five Core Elements

Zero Trust, applied across five dimensions. Each is a question every agent must answer for, continuously. Not once at deployment.

01
Who are you?
Identity
Every agent carries a verifiable, attested identity. You know exactly which agent did what, and you can prove it.
ATF-ID
02
What are you doing?
Behavior
You know what normal looks like, so you spot what isn't: anomalies, drift, intent that doesn't match the task. At 2 a.m. too.
ATF-BEH
03
What are you eating and serving?
Data Governance
You control what data goes into your agents and what comes out: PII protected, secrets caught, outputs validated.
ATF-DAT
04
Where can you go?
Segmentation
Agents reach only the systems they need. One compromised agent can't roam the building. The blast radius is bounded.
ATF-SEG
05
What if you go rogue?
Incident Response
You can stop one agent without stopping the business. Containment in seconds, by revoking its identity. Not in a meeting.
ATF-RES
§ 3

The Agent Maturity Model

Autonomy is earned, not granted. An agent moves up only after it proves it can be trusted at the level below, and it can be moved back down.

01
Intern
Observe + report
02
Junior
Recommend + approve
03
Senior
Act + notify
04
Principal
Autonomous in bounds
Level 1

Intern

Observe + Report
Autonomy
Read-only
Oversight
Continuous
Example
Monitors security logs, flags suspicious patterns for an analyst.
Level 2

Junior

Recommend + Human Approves
Autonomy
Suggestions only
Oversight
Approval for every action
Example
Drafts customer responses for a human to review before sending.
Level 3

Senior

Act + Notify
Autonomy
Acts within guardrails
Oversight
Post-action notification
Example
Auto-scales infrastructure on load, notifies the ops team of changes.
Level 4

Principal

Autonomous Within Bounds
Autonomy
Self-directed in domain
Oversight
Strategic + edge-case escalation
Example
Triages and contains incidents within playbooks, escalates novel threats.
Continuous verification

Agents earn promotion through demonstrated reliability: sustained accuracy, a clean incident record, a passed security audit, and explicit governance sign-off. They can also be demoted if incidents occur at their current level. Trust is checked continuously, never assumed.

Why It Matters Now

The tools already shipped. The governance didn't.

86%
of AI agents ship without security approval.
Source: Gravitee, Feb 2026
26%
of companies have any AI governance policy at all.
Source: CSA survey, RSAC 2026
5 · 4
five core elements, four maturity levels: the whole standard.
ATF v1 · CC BY 4.0
§ 4

How ATF Fits the Other Frameworks

ATF doesn't compete with what you already run. It operationalizes it, turning threat models and principles into the controls that implement them.

FrameworkHow ATF relates
MAESTROModels threats across 7 layers. ATF supplies the governance controls that address them.
OWASP Top 10 for Agentic AppsNames the threats. ATF supplies the controls to mitigate them.
NIST 800-207Defines Zero Trust principles. ATF applies them specifically to AI agents.
AWS Agentic Scoping MatrixATF's four maturity levels map directly to AWS Scopes 1–4.
§ 5

Start Here

The specification is open and free. Read it, assess where you stand, and go deeper when you're ready.

01 · Spec

Read the Specification

The complete ATF spec: requirements and implementation guidance, maintained openly on GitHub.

View on GitHub →
02 · Overview

Read the CSA Overview

A comprehensive overview published on the Cloud Security Alliance blog.

Read the post →
03 · Book

Get the Book

Agentic AI + Zero Trust. The full guide for business leaders, foreword by John Kindervag.

Find it on Amazon →
§ 6

Origins

ATF builds on Agentic AI + Zero Trust: A Guide for Business Leaders (September 2025), with a foreword by John Kindervag, the creator of Zero Trust. It is published as an open specification so any team can adopt, implement, and audit against it.

Author · Josh Woodruff
Organization · MassiveScale.AI
Steward · CSAI Foundation
License · Creative Commons Attribution 4.0 (CC BY 4.0)