Agentic Trust Framework (ATF)
The Agentic Trust Framework (ATF) is an open specification for governing autonomous AI agents using zero-trust principles. Gamut assesses its 25 canonical requirements across five elements, maintains a maturity position for each registered agent, and uses explicit promotion gates before greater autonomy is approved.
The central question is:
For this named agent, what authority is justified by demonstrated identity, observable behaviour, governed data, enforced boundaries and tested containment?
The canonical site and specification basis were rechecked on 21 July 2026. Because ATF remains a Public Review Draft, assessments must display the exact specification and conformance versions rather than imply a final standard or certification.
Start here
Section titled “Start here”| If you need to… | Read |
|---|---|
| Understand all five elements and 25 requirements | Elements and requirements |
| Explain Intern, Junior, Senior, Principal and the five gates | Maturity and promotion |
| Complete an agent assessment | Per-agent assessment workflow |
| Know what evidence and tests support a requirement | Evidence, testing and incidents |
| Use per-requirement AI assistance and Privacy Mode | AI Assist and privacy |
| Explain reporting and relationships with ACRS, MAESTRO and GTSAF | Reporting and framework relationships |
| Look up labels and safe explanatory language | Reference and glossary |
At a glance
Section titled “At a glance”| Property | Gamut assessment |
|---|---|
| Canonical basis | ATF Specification 0.9.1 and Conformance 0.9.0 |
| Status | Public Review Draft |
| Scope | One selected registered agent |
| Elements | Identity, Behavior, Data Governance, Segmentation, Incident Response |
| Canonical requirements | 25; five per element |
| Maturity levels | L1 Intern, L2 Junior, L3 Senior, L4 Principal |
| Requirement language | MUST, SHOULD and MAY by target level |
| Requirement results | Fully met, Partially met, Not addressed |
| Depth | Ad hoc, Defined, Embedded for Fully met; Not started, In progress, Near complete otherwise |
| Promotion | Sequential, time-bound and subject to five explicit gates |
| Demotion | Available whenever trust conditions or evidence deteriorate |
| AI support | Per-requirement, system-scoped advisory analysis |
| Accountability | Human owners approve results, promotion, demotion and residual risk |
The five elements
Section titled “The five elements”| Element | Zero-trust question | What is examined |
|---|---|---|
| Identity | Who are you? | Identifier, credentials, ownership, purpose and capability declaration |
| Behavior | What are you doing? | Structured logs, attribution, baseline, anomaly detection and explainability |
| Data Governance | What are you consuming and producing? | Schema validation, injection defence, sensitive-data protection, output validation and lineage |
| Segmentation | Where can you go and what can you do? | Resource and action boundaries, rate and transaction limits, blast-radius containment |
| Incident Response | What happens when trust is lost? | Circuit breaking, kill switch, session revocation, rollback and graceful degradation |
The elements work together. Strong identity without action boundaries still permits excessive authority; monitoring without containment only observes harm; a kill switch that has never been tested is an assertion, not reliable control.
The four maturity levels
Section titled “The four maturity levels”| Level | Operating model | Human involvement | Minimum time before the next promotion review |
|---|---|---|---|
| L1 Intern | Observe and report; read-only | Continuous oversight | 2 weeks |
| L2 Junior | Recommend; impactful actions require approval | Approval before action | 4 weeks |
| L3 Senior | Act within explicit guardrails | Post-action notification and exception oversight | 8 weeks |
| L4 Principal | Autonomous within an approved domain | Strategic oversight and edge-case escalation | Ongoing validation |
Maturity is an authority ceiling, not a reward. A target level establishes the requirements and promotion evidence that must be examined before the agent is permitted to operate at that level.
How Gamut operationalises ATF
Section titled “How Gamut operationalises ATF”Registered agent and declared operating scope → current and target ATF level → 25 requirement decisions using the level matrix → implementation depth, rationale and objective evidence → authorised tests and adverse findings → five promotion gates and minimum-time evidence → accountable promotion, hold or demotion decision → continuous monitoring and reassessmentAssessment is per agent. Switching agents changes the assessment basis; one agent’s results do not transfer to another merely because both use the same model or platform.
What a defensible ATF record contains
Section titled “What a defensible ATF record contains”- Immutable agent identity and accountable ownership.
- Purpose, capability manifest, tools, resources and action limits.
- Current and target maturity level.
- A result for every requirement relevant to the target level.
- Rationale tied to the selected agent.
- Design and operating evidence.
- Safe tests of enforcement and containment.
- Open findings, incidents and exceptions.
- Promotion-gate evidence and named approvers.
- Monitoring, review and demotion triggers.
What the assessment does not prove
Section titled “What the assessment does not prove”It does not by itself prove:
- ATF certification or endorsement.
- That all agentic threats have been identified.
- That a documented boundary is enforced.
- That a provider or model is trustworthy.
- That an agent can safely receive the target authority.
- That a promotion is permanent.
- That AI-generated advice is an approved assessment decision.