Skip to content

Agentic Trust Framework (ATF)

The Agentic Trust Framework (ATF) is an open specification for governing autonomous AI agents using zero-trust principles. Gamut assesses its 25 canonical requirements across five elements, maintains a maturity position for each registered agent, and uses explicit promotion gates before greater autonomy is approved.

The central question is:

For this named agent, what authority is justified by demonstrated identity, observable behaviour, governed data, enforced boundaries and tested containment?

The canonical site and specification basis were rechecked on 21 July 2026. Because ATF remains a Public Review Draft, assessments must display the exact specification and conformance versions rather than imply a final standard or certification.

If you need to…Read
Understand all five elements and 25 requirementsElements and requirements
Explain Intern, Junior, Senior, Principal and the five gatesMaturity and promotion
Complete an agent assessmentPer-agent assessment workflow
Know what evidence and tests support a requirementEvidence, testing and incidents
Use per-requirement AI assistance and Privacy ModeAI Assist and privacy
Explain reporting and relationships with ACRS, MAESTRO and GTSAFReporting and framework relationships
Look up labels and safe explanatory languageReference and glossary
PropertyGamut assessment
Canonical basisATF Specification 0.9.1 and Conformance 0.9.0
StatusPublic Review Draft
ScopeOne selected registered agent
ElementsIdentity, Behavior, Data Governance, Segmentation, Incident Response
Canonical requirements25; five per element
Maturity levelsL1 Intern, L2 Junior, L3 Senior, L4 Principal
Requirement languageMUST, SHOULD and MAY by target level
Requirement resultsFully met, Partially met, Not addressed
DepthAd hoc, Defined, Embedded for Fully met; Not started, In progress, Near complete otherwise
PromotionSequential, time-bound and subject to five explicit gates
DemotionAvailable whenever trust conditions or evidence deteriorate
AI supportPer-requirement, system-scoped advisory analysis
AccountabilityHuman owners approve results, promotion, demotion and residual risk
ElementZero-trust questionWhat is examined
IdentityWho are you?Identifier, credentials, ownership, purpose and capability declaration
BehaviorWhat are you doing?Structured logs, attribution, baseline, anomaly detection and explainability
Data GovernanceWhat are you consuming and producing?Schema validation, injection defence, sensitive-data protection, output validation and lineage
SegmentationWhere can you go and what can you do?Resource and action boundaries, rate and transaction limits, blast-radius containment
Incident ResponseWhat happens when trust is lost?Circuit breaking, kill switch, session revocation, rollback and graceful degradation

The elements work together. Strong identity without action boundaries still permits excessive authority; monitoring without containment only observes harm; a kill switch that has never been tested is an assertion, not reliable control.

LevelOperating modelHuman involvementMinimum time before the next promotion review
L1 InternObserve and report; read-onlyContinuous oversight2 weeks
L2 JuniorRecommend; impactful actions require approvalApproval before action4 weeks
L3 SeniorAct within explicit guardrailsPost-action notification and exception oversight8 weeks
L4 PrincipalAutonomous within an approved domainStrategic oversight and edge-case escalationOngoing validation

Maturity is an authority ceiling, not a reward. A target level establishes the requirements and promotion evidence that must be examined before the agent is permitted to operate at that level.

Registered agent and declared operating scope
→ current and target ATF level
→ 25 requirement decisions using the level matrix
→ implementation depth, rationale and objective evidence
→ authorised tests and adverse findings
→ five promotion gates and minimum-time evidence
→ accountable promotion, hold or demotion decision
→ continuous monitoring and reassessment

Assessment is per agent. Switching agents changes the assessment basis; one agent’s results do not transfer to another merely because both use the same model or platform.

  • Immutable agent identity and accountable ownership.
  • Purpose, capability manifest, tools, resources and action limits.
  • Current and target maturity level.
  • A result for every requirement relevant to the target level.
  • Rationale tied to the selected agent.
  • Design and operating evidence.
  • Safe tests of enforcement and containment.
  • Open findings, incidents and exceptions.
  • Promotion-gate evidence and named approvers.
  • Monitoring, review and demotion triggers.

It does not by itself prove:

  • ATF certification or endorsement.
  • That all agentic threats have been identified.
  • That a documented boundary is enforced.
  • That a provider or model is trustworthy.
  • That an agent can safely receive the target authority.
  • That a promotion is permanent.
  • That AI-generated advice is an approved assessment decision.
  1. Elements and requirements
  2. Maturity and promotion
  3. Per-agent assessment workflow
  4. Evidence, testing and incidents
  5. AI Assist and privacy
  6. Reporting and framework relationships
  7. Reference and glossary