MAESTRO
MAESTRO (Multi-Agent Environment, Security, Threat, Risk, and Outcome) is a threat-modelling framework designed for the distinctive risks of agentic AI. It examines an AI system layer by layer, then traces threats that propagate across layers, agents and trust boundaries.
Gamut implements the Cloud Security Alliance catalogue published on 6 February 2025 as
CSA-2025-02-06-v1:
- Seven canonical architectural layers.
- A dedicated cross-layer threat section.
- 50 layer-specific threats.
- Five cross-layer threats.
- Eight canonical agentic architecture patterns.
- A six-step assessment method.
- Likelihood × impact risk assessment.
- A unique assessor playbook for every threat.
- System-specific assessment records and workspace roll-up.
- Evidence, tests, findings, treatment and monitoring records.
- Validated, system-scoped AI assistance for each canonical threat.
Start here
Section titled “Start here”| If you need to… | Read |
|---|---|
| Explain what MAESTRO is, how it differs from a control framework and what every label means | Method, concepts and terminology |
| Understand all seven layers and every one of the 55 canonical threats | Layers and threat catalogue |
| Decompose a system and select the right agentic architecture pattern | System decomposition and architecture patterns |
| Complete an assessment and defend the scoring | Assessment workflow and risk scoring |
| Know what evidence to request, how to test safely and how to treat findings | Evidence, testing and treatment |
| Explain what AI Assist reads, produces, secures and cannot decide | AI Assist and security |
| Produce reports and connect MAESTRO to GTSAF, ACRS and ATF | Reporting and governance |
| Follow a complete realistic assessment | Worked example |
| Look up identifiers, scores, labels and formulas | Reference and glossary |
At a glance
Section titled “At a glance”| Property | Gamut implementation |
|---|---|
| Catalogue version | CSA-2025-02-06-v1 |
| Canonical layers | 7 |
| Cross-layer section | 1 |
| Layer-specific threats | 50 |
| Cross-layer threats | 5 |
| Total assessable threats | 55 |
| Stable identifier | MAE-L<layer>-<nn> or MAE-X-<nn> |
| Architecture patterns | 8 |
| Workflow steps | 6 |
| Risk dimensions | Likelihood 1–5 and impact 1–5 |
| Raw risk | Likelihood × impact, from 1 to 25 |
| Severity bands | Low, Moderate, Elevated, High, Critical |
| Layer roll-up | Highest scored threat in the layer |
| System roll-up | Highest scored threat for the selected system |
| Workspace roll-up | Systems assessed, worst case and distribution by worst-case band |
The canonical architecture
Section titled “The canonical architecture”| Section | Canonical name | Threats | Primary subject |
|---|---|---|---|
| Layer 1 | Foundation Models | 7 | Model behaviour, privacy, integrity, extraction and availability |
| Layer 2 | Data Operations | 5 | Data stores, pipelines, RAG, provenance, integrity and availability |
| Layer 3 | Agent Frameworks | 6 | Framework components, APIs, dependencies, validation and control evasion |
| Layer 4 | Deployment & Infrastructure | 6 | Images, orchestration, IaC, compute, networks and lateral movement |
| Layer 5 | Evaluation & Observability | 6 | Metrics, evaluators, telemetry, detection integrity and monitoring confidentiality |
| Layer 6 | Security & Compliance | 7 | The vertical security layer, especially AI agents performing security functions |
| Layer 7 | Agent Ecosystem | 13 | Agents, identities, tools, registries, discovery, markets and business integrations |
| Cross-layer | Cross-Layer Threats | 5 | Attack chains and cascading failures spanning two or more layers |
Layer 6 is vertical: it cuts across the rest of the architecture. The cross-layer section is not an eighth architectural layer; it records threats that exploit relationships between layers.
How MAESTRO operates in Gamut
Section titled “How MAESTRO operates in Gamut”- Select the AI system being assessed, or deliberately use workspace scope.
- Decompose its components, capabilities, tools, goals, constraints and interactions.
- Select the closest canonical architecture pattern.
- Confirm which assets and pathways exist in each layer.
- Tailor each applicable canonical threat into a system-specific scenario.
- Score likelihood and impact.
- Record current controls, treatment owner, target date, monitoring and reassessment triggers.
- Link evidence, tests and findings.
- Model cross-layer attack chains.
- Review the highest risks, generate reporting and obtain the authorised human risk decision.
The assessment record for one threat
Section titled “The assessment record for one threat”A defensible threat record should answer:
- Why is the threat applicable to this system?
- Which actor, capability or failure can initiate it?
- Which assets and trust boundaries form the attack path?
- What is the credible business, safety, privacy or mission outcome?
- What evidence demonstrates the current controls?
- What bounded test was performed, with what pass criteria and safety limits?
- Is the score inherent or residual?
- Who owns treatment, by when?
- Which signals will reveal attempted exploitation or control degradation?
- Which changes require reassessment?
- Which other layers or threats can form a cascade?
Security principles
Section titled “Security principles”MAESTRO in Gamut is designed around:
- Defence in depth: no single control is assumed to break every path.
- Zero trust: identity, workload, data and agent claims are verified at each boundary.
- Least privilege: agents, tools and service identities receive only necessary authority.
- Fail-safe operation: uncertainty or control failure should reduce capability, not silently expand it.
- Evidence over assertion: a confident narrative is not accepted as proof.
- Safe testing: tests are bounded, authorised, reversible and non-destructive.
- Human accountability: AI suggestions cannot approve evidence, accept risk or sign off the assessment.