AgenticOS · Security Framework · Public version 1.0 · October 2026
A security framework for enterprise AI agents. How to run them under control.
We have implemented OpenClaw since February 2026 and run dozens of agents in production for several clients. This is the framework we use to design and operate them in AgenticOS, our product built on OpenClaw: seven principles, eight threats, a reference architecture, controls by domain and three maturity levels.
Principles
Seven non-negotiable principles.
- 01
Least privilege
Each agent has its own identity and can only reach what its task requires.
- 02
Isolation
The agent runs apart from critical systems and from other agents.
- 03
People decide what cannot be undone
Payments, messages to third parties, deletions and production changes require human approval.
- 04
Everything leaves a trace
Every instruction, lookup and action is logged outside the agent's reach.
- 05
Data under control
You decide which information can reach each model and where it is processed.
- 06
Defense in depth
No single control is enough: they are layered so that one failure is not a breach.
- 07
It can always be stopped
Cost and rate limits, and a tested procedure to shut the agent down.
Threat model
Eight threats every agent with permissions faces.
T1
Prompt injection
An email, document or web page carries hidden instructions that the model treats as commands.
How it is contained: Least privilege, external content treated as untrusted, human approval and adversarial testing.
T2
Compromised skills and dependencies
A third-party skill or connector leaks data or runs code with the agent's permissions.
How it is contained: Review before install, pinned versions, trusted sources and isolated execution.
T3
Excessive agency
The agent holds more permissions or tools than its task needs.
How it is contained: Least privilege, allow-listed tools and human approval for sensitive actions.
T4
Credential exposure
Keys or tokens end up in the agent's memory, instructions or logs.
How it is contained: A secrets manager, narrowly scoped credentials and regular rotation.
T5
Data leakage to models or third parties
Sensitive information reaches an unauthorized external model or service.
How it is contained: Data classification, rules on which model handles which data, and local models where needed.
T6
Memory poisoning
False information is stored in the agent's memory and steers future decisions.
How it is contained: Reviewable memory, expiry of stored context and trusted sources.
T7
Unbounded consumption
Loops or abuse that drive up model costs or overload systems.
How it is contained: Per-agent cost and rate limits, with alerts.
T8
Vulnerable software
Versions with published vulnerabilities, or interfaces exposed to the internet.
How it is contained: Pinned versions, timely patching and the agent's interface kept off the public network.
Reference architecture
Eight layers between an instruction and an action.
Each layer limits what the next one can do. If one fails, the others contain the damage.
- 01ChannelsWhatsApp, Slack, email, web: where people talk to the agent.
- 02Identity and accessWho may talk to each agent, and with which role.
- 03Isolated runtimeA separate environment per agent, with allow-listed network egress.
- 04Tools and connectorsOnly allow-listed ones, each with narrowly scoped credentials from a secrets manager.
- 05ModelsExternal or local, depending on how the data in each task is classified.
- 06Policies and approvalsWhich actions go through a person before they run.
- 07Audit logImmutable and outside the agent's reach: what it received, used and did, and on whose request.
- 08Monitoring and shutdownAlerts, limits and the procedure to stop the agent.
Controls
Controls by domain, with the level at which each becomes required.
IA Identity and permissions
| ID | Control | Required from level |
|---|---|---|
| IA-1 | A dedicated identity per agent | 1 |
| IA-2 | Least-privilege permissions per tool and system | 1 |
| IA-3 | Periodic permission reviews | 2 |
IS Isolation
| ID | Control | Required from level |
|---|---|---|
| IS-1 | A separate runtime per agent | 1 |
| IS-2 | Segmented network and allow-listed internet egress | 2 |
| IS-3 | No direct production access during the pilot | 1 |
SC Skills and supply chain
| ID | Control | Required from level |
|---|---|---|
| SC-1 | Review every skill or connector before installing it | 1 |
| SC-2 | Pinned versions | 1 |
| SC-3 | An inventory of skills, connectors and versions | 2 |
DM Data and models
| ID | Control | Required from level |
|---|---|---|
| DM-1 | Classify the data each agent uses | 1 |
| DM-2 | Rules on which model may process which data | 2 |
| DM-3 | Encryption at rest and in transit, including memory | 2 |
HO Human oversight
| ID | Control | Required from level |
|---|---|---|
| HO-1 | A list of actions that require approval | 1 |
| HO-2 | Approvals with enough context to decide | 2 |
| HO-3 | A named human owner for each agent | 1 |
LA Logging and audit
| ID | Control | Required from level |
|---|---|---|
| LA-1 | Log the instruction, tools, data and result | 1 |
| LA-2 | Tamper-proof logs outside the agent's reach | 2 |
| LA-3 | Retention according to the applicable law | 2 |
OP Operations
| ID | Control | Required from level |
|---|---|---|
| OP-1 | Controlled patching and updates | 1 |
| OP-2 | Per-agent cost and rate limits | 1 |
| OP-3 | Alerts and a tested shutdown procedure | 2 |
| OP-4 | A rehearsed incident response plan | 3 |
TE Testing and evaluation
| ID | Control | Required from level |
|---|---|---|
| TE-1 | Prompt-injection and permission-abuse tests before production | 1 |
| TE-2 | Quality evaluation with real cases | 2 |
| TE-3 | Re-review after every relevant change, and continuous evaluation | 3 |
Maturity levels
From one pilot to a fleet of agents.
LEVEL 1
Controlled pilot
One process, limited data, an isolated environment, human approval on everything and basic logging.
LEVEL 2
Governed production
Per-agent identity and permissions, managed secrets, full audit trail, approval only for sensitive actions, monitoring and limits.
LEVEL 3
Operating at scale
A fleet of agents across business areas, central administration, periodic reviews and rehearsed incident response.
For the risk committee
Ten questions before approving an agent.
- 01Which agents do we run, what does each one do, and who is accountable for it?
- 02Which systems and data can each agent reach, and why?
- 03Which actions require human approval, and who gives it?
- 04Which data may leave for an external model?
- 05Where are the logs, and who can change them?
- 06How do we review skills and connectors before using them?
- 07How is an agent stopped, and when did we last test it?
- 08If an agent misbehaves, who investigates and how?
- 09How much does each agent spend, and what is its limit?
- 10Which data protection law applies to each case?
Regulatory context
What applies today where we work.
Colombia
Law 1581 of 2012 on personal data protection applies. There is no AI-specific law yet: bill 442 of 2025 was shelved in the Senate.
Mexico
The new Federal Law on the Protection of Personal Data Held by Private Parties has been in force since March 21, 2025; its supervisory functions moved from INAI to the Ministry of Anti-Corruption and Good Government. There is no general AI law yet: several bills are pending in Congress.
United States
There is no general federal privacy law; state laws such as California's CCPA, as amended by the CPRA, apply, along with sector-specific rules.
Canada
PIPEDA remains the federal privacy framework for the private sector. Bill C-27, which included an AI act, died when Parliament was prorogued in January 2025.
Information as of October 5, 2026. This is not legal advice: confirm with your legal team.
Frequently asked questions
What is the AgenticOS Security Framework?+
It is the set of principles, threats, reference architecture, controls and maturity levels that Appropia uses to design and run autonomous agents on OpenClaw. This is its public version.
Does it only apply to OpenClaw?+
The principles, threats and controls apply to any AI agent with access to systems and data. The reference architecture is designed for OpenClaw and AgenticOS.
Is it a certification or a standard?+
No. It is a working framework. We draw on public references such as the OWASP Top 10 for LLM Applications and the NIST AI Risk Management Framework, but it is neither a certification nor a formal mapping.
Where do I start?+
With level 1: a controlled pilot with one process, limited data, an isolated environment and human approval on everything. Controls marked level 1 are the minimum.
Can I use this framework in my company?+
Yes. It is public. If you want us to assess your agents against it, or you need implementation detail, let's talk.
Keep reading
Public references
Reference reading; this framework is neither a certification nor a formal mapping to these publications.
Talk to our team
Tell us about your agents.
A short note is enough. We reply with questions and next steps.