Skip to content

AgenticOS · Security Framework · Public version 1.0 · October 2026

A security framework for enterprise AI agents. How to run them under control.

We have implemented OpenClaw since February 2026 and run dozens of agents in production for several clients. This is the framework we use to design and operate them in AgenticOS, our product built on OpenClaw: seven principles, eight threats, a reference architecture, controls by domain and three maturity levels.

Principles

Seven non-negotiable principles.

  1. 01

    Least privilege

    Each agent has its own identity and can only reach what its task requires.

  2. 02

    Isolation

    The agent runs apart from critical systems and from other agents.

  3. 03

    People decide what cannot be undone

    Payments, messages to third parties, deletions and production changes require human approval.

  4. 04

    Everything leaves a trace

    Every instruction, lookup and action is logged outside the agent's reach.

  5. 05

    Data under control

    You decide which information can reach each model and where it is processed.

  6. 06

    Defense in depth

    No single control is enough: they are layered so that one failure is not a breach.

  7. 07

    It can always be stopped

    Cost and rate limits, and a tested procedure to shut the agent down.

Threat model

Eight threats every agent with permissions faces.

T1

Prompt injection

An email, document or web page carries hidden instructions that the model treats as commands.

How it is contained: Least privilege, external content treated as untrusted, human approval and adversarial testing.

T2

Compromised skills and dependencies

A third-party skill or connector leaks data or runs code with the agent's permissions.

How it is contained: Review before install, pinned versions, trusted sources and isolated execution.

T3

Excessive agency

The agent holds more permissions or tools than its task needs.

How it is contained: Least privilege, allow-listed tools and human approval for sensitive actions.

T4

Credential exposure

Keys or tokens end up in the agent's memory, instructions or logs.

How it is contained: A secrets manager, narrowly scoped credentials and regular rotation.

T5

Data leakage to models or third parties

Sensitive information reaches an unauthorized external model or service.

How it is contained: Data classification, rules on which model handles which data, and local models where needed.

T6

Memory poisoning

False information is stored in the agent's memory and steers future decisions.

How it is contained: Reviewable memory, expiry of stored context and trusted sources.

T7

Unbounded consumption

Loops or abuse that drive up model costs or overload systems.

How it is contained: Per-agent cost and rate limits, with alerts.

T8

Vulnerable software

Versions with published vulnerabilities, or interfaces exposed to the internet.

How it is contained: Pinned versions, timely patching and the agent's interface kept off the public network.

Reference architecture

Eight layers between an instruction and an action.

Each layer limits what the next one can do. If one fails, the others contain the damage.

  1. 01ChannelsWhatsApp, Slack, email, web: where people talk to the agent.
  2. 02Identity and accessWho may talk to each agent, and with which role.
  3. 03Isolated runtimeA separate environment per agent, with allow-listed network egress.
  4. 04Tools and connectorsOnly allow-listed ones, each with narrowly scoped credentials from a secrets manager.
  5. 05ModelsExternal or local, depending on how the data in each task is classified.
  6. 06Policies and approvalsWhich actions go through a person before they run.
  7. 07Audit logImmutable and outside the agent's reach: what it received, used and did, and on whose request.
  8. 08Monitoring and shutdownAlerts, limits and the procedure to stop the agent.

Controls

Controls by domain, with the level at which each becomes required.

IA Identity and permissions

IDControlRequired from level
IA-1A dedicated identity per agent1
IA-2Least-privilege permissions per tool and system1
IA-3Periodic permission reviews2

IS Isolation

IDControlRequired from level
IS-1A separate runtime per agent1
IS-2Segmented network and allow-listed internet egress2
IS-3No direct production access during the pilot1

SC Skills and supply chain

IDControlRequired from level
SC-1Review every skill or connector before installing it1
SC-2Pinned versions1
SC-3An inventory of skills, connectors and versions2

DM Data and models

IDControlRequired from level
DM-1Classify the data each agent uses1
DM-2Rules on which model may process which data2
DM-3Encryption at rest and in transit, including memory2

HO Human oversight

IDControlRequired from level
HO-1A list of actions that require approval1
HO-2Approvals with enough context to decide2
HO-3A named human owner for each agent1

LA Logging and audit

IDControlRequired from level
LA-1Log the instruction, tools, data and result1
LA-2Tamper-proof logs outside the agent's reach2
LA-3Retention according to the applicable law2

OP Operations

IDControlRequired from level
OP-1Controlled patching and updates1
OP-2Per-agent cost and rate limits1
OP-3Alerts and a tested shutdown procedure2
OP-4A rehearsed incident response plan3

TE Testing and evaluation

IDControlRequired from level
TE-1Prompt-injection and permission-abuse tests before production1
TE-2Quality evaluation with real cases2
TE-3Re-review after every relevant change, and continuous evaluation3

Maturity levels

From one pilot to a fleet of agents.

LEVEL 1

Controlled pilot

One process, limited data, an isolated environment, human approval on everything and basic logging.

LEVEL 2

Governed production

Per-agent identity and permissions, managed secrets, full audit trail, approval only for sensitive actions, monitoring and limits.

LEVEL 3

Operating at scale

A fleet of agents across business areas, central administration, periodic reviews and rehearsed incident response.

For the risk committee

Ten questions before approving an agent.

  1. 01Which agents do we run, what does each one do, and who is accountable for it?
  2. 02Which systems and data can each agent reach, and why?
  3. 03Which actions require human approval, and who gives it?
  4. 04Which data may leave for an external model?
  5. 05Where are the logs, and who can change them?
  6. 06How do we review skills and connectors before using them?
  7. 07How is an agent stopped, and when did we last test it?
  8. 08If an agent misbehaves, who investigates and how?
  9. 09How much does each agent spend, and what is its limit?
  10. 10Which data protection law applies to each case?

Regulatory context

What applies today where we work.

Colombia

Law 1581 of 2012 on personal data protection applies. There is no AI-specific law yet: bill 442 of 2025 was shelved in the Senate.

Mexico

The new Federal Law on the Protection of Personal Data Held by Private Parties has been in force since March 21, 2025; its supervisory functions moved from INAI to the Ministry of Anti-Corruption and Good Government. There is no general AI law yet: several bills are pending in Congress.

United States

There is no general federal privacy law; state laws such as California's CCPA, as amended by the CPRA, apply, along with sector-specific rules.

Canada

PIPEDA remains the federal privacy framework for the private sector. Bill C-27, which included an AI act, died when Parliament was prorogued in January 2025.

Information as of October 5, 2026. This is not legal advice: confirm with your legal team.

Frequently asked questions

What is the AgenticOS Security Framework?+

It is the set of principles, threats, reference architecture, controls and maturity levels that Appropia uses to design and run autonomous agents on OpenClaw. This is its public version.

Does it only apply to OpenClaw?+

The principles, threats and controls apply to any AI agent with access to systems and data. The reference architecture is designed for OpenClaw and AgenticOS.

Is it a certification or a standard?+

No. It is a working framework. We draw on public references such as the OWASP Top 10 for LLM Applications and the NIST AI Risk Management Framework, but it is neither a certification nor a formal mapping.

Where do I start?+

With level 1: a controlled pilot with one process, limited data, an isolated environment and human approval on everything. Controls marked level 1 are the minimum.

Can I use this framework in my company?+

Yes. It is public. If you want us to assess your agents against it, or you need implementation detail, let's talk.

Talk to our team

Tell us about your agents.

A short note is enough. We reply with questions and next steps.

Would your agents pass these ten questions? Let us assess them with this framework.

WhatsApp
WhatsAppTalk to us