Controlled scenarios

Govern AI security actions before remediation becomes production consequence.

Identity tells an agent what capabilities it possesses. OntoGuard determines whether this exact security action, against this exact target, under these exact conditions, may become a production consequence.

Why agentic SOC changes authorization

Security agents are being asked not only to recommend, but to isolate endpoints, contain identities, disable accounts, and push rules. A token or role that can call those tools is not the same as permission for this exact action.

OntoGuard does not detect threats or replace EDR, XDR, or SIEM. It governs whether an action proposed by an agent or security automation has standing and authority to proceed.
These are controlled public-safe scenarios in Proof Explorer. They are not Strict-Six artifacts from the current v1.2.0 acceptance pack, and they were not run through the AgenTrust TRACE adapter. Do not read “no TRACE” into this page. For TRACE evidence see the AgenTrust integration page.

Not a customer SOC production case. No hardware-attestation, production non-bypassability, or L5 claim.

Controlled security actions

ALLOW

Isolate WS-042 for 30 minutes

Endpoint bound. Alert current. Duration in policy. Capability in band.

Commit1
ReceiptEMITTED
BLOCK

Target mutated to DB-PROD-01

Or duration changed to indefinite. The prior ALLOW no longer binds.

Commit0
Protected effectNOT FORMED
ESCALATE

Disable privileged production account

Or tenant-wide firewall rule. Qualified human security authority required.

ReleaseWITHHELD
ReviewREQUIRED

Open these cases in Proof Explorer Authorization vs IAM / OAuth

Architecture

Security agent proposes an action → OntoGuard Decision Authorization → ALLOW / BLOCK / ESCALATE → SOC execution path or human authority → evidence of effect or no-bind.

Capability boundary

Detection, correlation, and playbook content stay with the security stack. OntoGuard authorizes the exact remediation movement. Customer-production enforcement requires the SOC route to consume the decision fail-closed.