Get a Demo

    The AI Agent Lifecycle: Discover, Authorize, Contain, Observe, Maintain

    Every AI agent security control is an event in a lifecycle, and a control without an owner and a cadence decays into documentation. The lifecycle has five phases, and their order is an argument: discover, authorize, contain, observe, maintain.

    The loop, with owners

    Phase Owner Entry criterion Required evidence Exit criterion
    Discover Security operations Agent or runtime observed Process record, artifact hash Classified and inventoried
    Authorize Security architecture Declared use submitted Approved declaration, versioned Assigned to a project boundary
    Contain Platform and security Authorized Enforced reachability, wrapped assets Operational, sandboxed by default
    Observe SOC and compliance Governed sessions running Session and policy evidence Reviewed on cadence
    Maintain Platform owner In active use Revalidation record Renewed, or retired

    The owner column is the point of the table. An enterprise that can name who owns discovery, who reviews declarations, who approves configurations, and who executes containment has adopted open-weight models. One that has the tools but not the loop has installed them. Around the owners sit the consulted and informed parties: the project owner consulted at authorization, the workforce informed of posture, legal and compliance consulted on evidence depth and retention.

    Contain means two things

    Baseline containment is the agent's normal project-scoped operating state: sandboxed by default, high-value assets wrapped, credentials substituted. Incident containment is the escalation from that state into the session, endpoint, and fleet tiers. The word covers both because the second only works where the first already exists, and the ordering of the loop is the thesis of the whole program in operational form: containment precedes observation because watching an unconstrained agent is incident documentation in advance. A lifecycle that observes first and constrains later learns about its failures only after the consequences arrive.

    Cadences and change triggers

    Maintain means a defined schedule plus a set of change triggers. On a cadence: declarations re-reviewed on a risk-based cadence, with quarterly as the starting point for high-sensitivity projects; evidence depth and retention reviewed with legal on their own cycle; the inventory reconciled against reality continuously. On a trigger: any model swap repeats artifact verification in full; any configuration change re-baselines the agent against its approved state; any containment event forces a declaration review before reinstatement; and ownership changes, an easily missed trigger, reassign every artifact the departing owner held, because an agent whose owner has left is on its way to becoming an agent nobody owns.

    Decommissioning, as a checklist

    Agents are decommissioned completely or not at all: identity revoked, credentials and substitutes invalidated, persistent memory deleted per policy with local caches cleared and vector-store entries retired, reachability collapsed, configuration artifacts archived, the disposal itself recorded, and the inventory record marked retired rather than deleted, so the historical evidence stays immutable and a reappearance is detectable as a policy violation. An agent that was turned off but never removed is a dormant, pre-authorized foothold, and nobody is watching it precisely because it was turned off.

    Models retire the same way. The registry retains the retired hash, lineage, replacement, and decommission date; verification confirms the old artifact is gone from every host that served it; and the retained hash is what makes any reappearance raise an alert. The model recall playbook is this discipline executed under pressure, which is the strongest argument for practicing it when there is none.

    Where the control plane fits

    Ensage AI operates the loop as one system: zLink discovery feeding zCenter inventory, enclave assignment as authorization, sandboxed-by-default operation as baseline containment, local evidence as observation, and policy-driven retirement with the record retained.


    Related

    See for yourself why major enterprises are rewriting their infrastructure playbooks.

    Get a Demo >