
The Standard for Governing AI Agents.
Five questions every agent must answer. Four levels of autonomy it has to earn. ATF turns Zero Trust into controls you can ship, and audits can pass.
This is what most companies look like today. Most can't fill it in at all. The free assessment takes about 15 minutes.
What the Framework Is
ATF is an open specification for governing AI agents with Zero Trust principles. It gives you a practical, implementable way to deploy autonomous agents that deliver value and pass a security audit. Traditional frameworks were built for human users and static systems. Agents are different.
They act on their own
Decisions get made without a human in the loop.
They learn and drift
Behavior changes over time, so trust can't be one-time.
They hold real access
Credentials, data, and permissions to live systems.
They talk to each other
Creating authorization chains no one mapped.
The Five Core Elements
Zero Trust, applied across five dimensions. Each is a question every agent must answer for, continuously. Not once at deployment.
The Agent Maturity Model
Autonomy is earned, not granted. An agent moves up only after it proves it can be trusted at the level below, and it can be moved back down.
Intern
Junior
Senior
Principal
Agents earn promotion through demonstrated reliability: sustained accuracy, a clean incident record, a passed security audit, and explicit governance sign-off. They can also be demoted if incidents occur at their current level. Trust is checked continuously, never assumed.
The tools already shipped. The governance didn't.
How ATF Fits the Other Frameworks
ATF doesn't compete with what you already run. It operationalizes it, turning threat models and principles into the controls that implement them.
| Framework | How ATF relates |
|---|---|
| MAESTRO | Models threats across 7 layers. ATF supplies the governance controls that address them. |
| OWASP Top 10 for Agentic Apps | Names the threats. ATF supplies the controls to mitigate them. |
| NIST 800-207 | Defines Zero Trust principles. ATF applies them specifically to AI agents. |
| AWS Agentic Scoping Matrix | ATF's four maturity levels map directly to AWS Scopes 1–4. |
Start Here
The specification is open and free. Read it, assess where you stand, and go deeper when you're ready.
Read the Specification
The complete ATF spec: requirements and implementation guidance, maintained openly on GitHub.
View on GitHub →Read the CSA Overview
A comprehensive overview published on the Cloud Security Alliance blog.
Read the post →Get the Book
Agentic AI + Zero Trust. The full guide for business leaders, foreword by John Kindervag.
Find it on Amazon →Origins
ATF builds on Agentic AI + Zero Trust: A Guide for Business Leaders (September 2025), with a foreword by John Kindervag, the creator of Zero Trust. It is published as an open specification so any team can adopt, implement, and audit against it.