OWASP Agent Control Standard

Bind a runtime hook to a protected action and deny execution when current grant or policy fails

01 / Source and scope

Who acts, and what changes?

Principal and authority origin

Agent platform and its action middleware. Platform operator policy and task-specific authority.

Consequential action

Call a tool or external API.

02 / Action-time control

Make the requested effect testable.

ACS describes control and observability interfaces; it is not a law or compliance certificate. Bind a runtime hook to a protected action and deny execution when current grant or policy fails.

OriginPlatform operator policy and task-specific authority
RequestCall a tool or external API
DecisionEvaluate and enforce before effect

03 / Evidence and responsibility

Permission, execution, and outcome are separate.

Hook invocation, rule version, decision and downstream result.

ProofGrid may serve as an authority decision layer where integrated; customers must instrument and test every execution path.

Primary source

Check the governing material.

Architecture discussion

Map one consequential action from origin to observed outcome.

Request a Conversation