| ZT Pillar | Traditional Control | Where It Breaks for Agents | Agentic ZT Control |
|---|---|---|---|
| Identity | MFA, SSO, RBAC for human users | Agents are ephemeral, can clone and impersonate, have no password, and produce behaviors that may deviate from their declared purpose even with valid credentials | SPIFFE/SVID attestation, OAuth 2.0 Token Exchange (RFC 8693), DIDs and Verifiable Credentials, agent registries with job-description-level detail, behavioral identity as a third verification layer |
| Device | EDR, patch compliance, device trust scoring | The agent "device" includes model weights, tool schemas, and MCP server definitions that can be poisoned through semantic manipulation invisible to conventional scanners | Container attestation, supply chain integrity for tool definitions and MCP packages, workload isolation, cryptographic signing of tool definitions and version pinning |
| Network | Microsegmentation, ZTNA | Agent-to-agent traffic, MCP trust boundaries, and token forwarding create a new east-west network plane that existing microsegmentation policies were not designed to govern | mTLS everywhere, agent gateways as Policy Enforcement Points, Token Isolation Pattern for structural credential non-portability, OAuth 2.0 Token Exchange at each delegation hop |
| Application / Workload | API gateway, WAF, secure SDLC | LLMs are non-deterministic. Indirect prompt injection overrides system prompts. Emergent offensive reasoning produces unauthorized behavior from a legitimately authorized agent. | Policy-as-code enforcement outside the LLM reasoning loop (OPA, Cedar), runtime behavioral guardrails, behavioral monitoring against the declared Agent Persona spec, behavioral identity as the primary detection layer for emergent offensive reasoning |
| Data | DLP, encryption, data classification | Agents accumulate, synthesize, and act on data through multiple memory and storage mechanisms. Agents do not merely access data. They reason over it, and can be manipulated into exfiltrating it through semantically authorized actions. | ABAC at the retrieval layer (not just at the knowledge base container level), PHI sanitization before data enters agent context windows, data lineage tracking across multi-agent chains, memory isolation and integrity verification |
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
These cookies are used for managing login functionality on this website.
Google Tag Manager simplifies the management of marketing tags on your website without code changes.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
Clarity is a web analytics service that tracks and reports website traffic.
Service URL: clarity.microsoft.com (opens in a new window)