Every AI agent security control is an event in a lifecycle, and a control without an owner and a cadence decays into documentation. The lifecycle has five phases, and their order is an argument: discover, authorize, contain, observe, maintain.
The loop, with owners
| Phase | Owner | Entry criterion | Required evidence | Exit criterion |
|---|---|---|---|---|
| Discover | Security operations | Agent or runtime observed | Process record, artifact hash | Classified and inventoried |
| Authorize | Security architecture | Declared use submitted | Approved declaration, versioned | Assigned to a project boundary |
| Contain | Platform and security | Authorized | Enforced reachability, wrapped assets | Operational, sandboxed by default |
| Observe | SOC and compliance | Governed sessions running | Session and policy evidence | Reviewed on cadence |
| Maintain | Platform owner | In active use | Revalidation record | Renewed, or retired |
The owner column is the point of the table. An enterprise that can name who owns discovery, who reviews declarations, who approves configurations, and who executes containment has adopted open-weight models. One that has the tools but not the loop has installed them. Around the owners sit the consulted and informed parties: the project owner consulted at authorization, the workforce informed of posture, legal and compliance consulted on evidence depth and retention.
Contain means two things
Baseline containment is the agent's normal project-scoped operating state: sandboxed by default, high-value assets wrapped, credentials substituted. Incident containment is the escalation from that state into the session, endpoint, and fleet tiers. The word covers both because the second only works where the first already exists, and the ordering of the loop is the thesis of the whole program in operational form: containment precedes observation because watching an unconstrained agent is incident documentation in advance. A lifecycle that observes first and constrains later learns about its failures only after the consequences arrive.
Cadences and change triggers
Maintain means a defined schedule plus a set of change triggers. On a cadence: declarations re-reviewed on a risk-based cadence, with quarterly as the starting point for high-sensitivity projects; evidence depth and retention reviewed with legal on their own cycle; the inventory reconciled against reality continuously. On a trigger: any model swap repeats artifact verification in full; any configuration change re-baselines the agent against its approved state; any containment event forces a declaration review before reinstatement; and ownership changes, an easily missed trigger, reassign every artifact the departing owner held, because an agent whose owner has left is on its way to becoming an agent nobody owns.
Decommissioning, as a checklist
Agents are decommissioned completely or not at all: identity revoked, credentials and substitutes invalidated, persistent memory deleted per policy with local caches cleared and vector-store entries retired, reachability collapsed, configuration artifacts archived, the disposal itself recorded, and the inventory record marked retired rather than deleted, so the historical evidence stays immutable and a reappearance is detectable as a policy violation. An agent that was turned off but never removed is a dormant, pre-authorized foothold, and nobody is watching it precisely because it was turned off.
Models retire the same way. The registry retains the retired hash, lineage, replacement, and decommission date; verification confirms the old artifact is gone from every host that served it; and the retained hash is what makes any reappearance raise an alert. The model recall playbook is this discipline executed under pressure, which is the strongest argument for practicing it when there is none.
Where the control plane fits
Ensage AI operates the loop as one system: zLink discovery feeding zCenter inventory, enclave assignment as authorization, sandboxed-by-default operation as baseline containment, local evidence as observation, and policy-driven retirement with the record retained.
