diff --git a/docs/superpowers/plans/2026-09-18-agent-baseline-research-note.md b/docs/superpowers/plans/2026-09-18-agent-baseline-research-note.md new file mode 100644 index 0000000..4d0a0bf --- /dev/null +++ b/docs/superpowers/plans/2026-09-18-agent-baseline-research-note.md @@ -0,0 +1,27 @@ +# Agent Baseline Research Note Implementation Plan + +> **For agentic workers:** Execute this plan inline with validation checkpoints. + +**Goal:** Add and publish a sourced research note on Agent Baseline's six security outcomes and 35 controls. + +**Architecture:** Present Agent Baseline as an outcome/control/evidence framework, then map Discover, Constrain, Authorize, Observe, Validate, and Respond to CF platform primitives and agent-specific gaps. + +**Tech Stack:** Markdown, YAML frontmatter, Devbox, Git, GitHub CLI. + +--- + +### Task 1: Write `research/agent-baseline.md` + +- [ ] Add frontmatter with title `Agent Baseline: Six Security Outcomes for Enterprise AI Agents`, author `Ruben Koster (@rkoster)`, date `2026-09-18`, tags `[authorization, sandboxing, observability-governance, ecosystem-survey]`, `cf_areas: [uaa, capi, diego, loggregator]`, `status: draft`, provisional ratings, and Agent Baseline website/source/white-paper links. +- [ ] Explain the threat model: runtime-programmable agents with access to data, tools, and systems, where mistaken or malicious instructions can cause actions before human intervention. +- [ ] Describe all six outcomes and the evidence-oriented nature of the 35 controls. +- [ ] Map Discover and Constrain to CF inventory, lifecycle, isolation, networking, and credential capabilities. +- [ ] Map Authorize and Observe to UAA/workload identity, policy, action attribution, Loggregator, and audit/provenance. +- [ ] Map Validate and Respond to build/release admission, evaluation, drift checks, revocation, quarantine, evidence preservation, and incident response. +- [ ] State that Agent Baseline is a working draft for public comment, not a finalized standard, and add open questions about control ownership, evidence, tenancy, and platform gaps. + +### Task 2: Validate and publish + +- [ ] Run `devbox run validate`, `devbox run test`, and `git diff --check`. +- [ ] Stage only the note and approved spec/plan, commit `docs: add Agent Baseline research note`, push `research/agent-baseline`, and open a checklist-complete PR targeting `main`. +- [ ] Verify PR metadata and CI with `gh pr view`. diff --git a/docs/superpowers/specs/2026-09-18-agent-baseline-research-note-design.md b/docs/superpowers/specs/2026-09-18-agent-baseline-research-note-design.md new file mode 100644 index 0000000..a3eaa55 --- /dev/null +++ b/docs/superpowers/specs/2026-09-18-agent-baseline-research-note-design.md @@ -0,0 +1,29 @@ +# Agent Baseline Research Note Design + +## Goal + +Add a sourced research note on Agent Baseline as an open draft security framework for enterprise +AI agents. + +## Scope + +The note will explain the six outcomes: Discover, Constrain, Authorize, Observe, Validate, and +Respond, along with the 35 controls and evidence-oriented framing. It will treat the project as +a working draft for public comment, not a finalized standard. + +The Cloud Foundry analysis will map the outcomes to CAPI/Diego inventory and lifecycle, UAA and +workload identity, sandbox/network policy, authorization, Loggregator/audit, build and release +validation, revocation, quarantine, and incident response. It will identify where CF supplies +primitives and where agent-specific controls remain missing. + +## Structure and evidence + +Create `research/agent-baseline.md` with the required four sections and frontmatter. Use the +Agent Baseline website, controls, white paper, source repository, and public-comment status. +Clearly distinguish framework requirements from existing CF capabilities and label mappings as +analysis or open questions. + +## Validation + +Run Devbox validation and tests, inspect whitespace/staged files, commit the note and plan on +`research/agent-baseline`, push, and open a PR targeting `main` without unrelated artifacts. diff --git a/generated/research-map.html b/generated/research-map.html index 75016a8..0aacdfd 100644 --- a/generated/research-map.html +++ b/generated/research-map.html @@ -23,9 +23,6 @@

Focus use cases

Attested Workload Authority and Mediated Tool AccessExchange platform-attested workload identity for scoped authority while credentials and outbound tool access remain mediated by the platform.Strategic decision: Decide whether CF should become the portable trust and policy layer between agent workloads and the tools they invoke.
Gap, experiments, and evidence
Current CF gap
CF issues workload identity certificates but does not exchange them for scoped tool authority, keep third-party credentials out of workloads, mediate off-platform access, or record delegation-aware audit events.
Candidate POC
Exchange a Diego instance identity certificate for a short-lived scoped token, invoke one allowed tool through a credential proxy and egress mediator, deny another, and emit attributable audit events.
Candidate RFC scope
Define workload token exchange, authority and delegation claims, credential brokering, outbound mediation and policy enforcement, audit events, revocation, and integration boundaries for UAA, routing, and service brokers.
-
Gap, experiments, and evidence
Current CF gap
CF can stage apps and run ephemeral tasks but cannot cheaply compose a reusable environment with per-session workspace state, select stronger isolation, constrain session networking, or resume the session lifecycle.
Candidate POC
Start two isolated sessions from one content-addressed staged environment, attach separate mutable workspaces, apply per-session egress policy, stop one session, and resume it on fresh compute.
Candidate RFC scope
Define environment and workspace references, session identity and lifecycle, isolation classes, network policy, workspace persistence and cleanup, scheduling, quotas, and compatibility with existing CF staging and task APIs.

ResearchIdea

Platform Impact x Maturity

Emerging < Maturity > EstablishedLocal concern < Platform Impact > Platform-wide concern
Unplaced notes (0)
-
-