The Control Plane Must Be Outside the Agent
From MicroVM isolation to runtime identity and out-of-band enforcement, the industry is moving agent safety out of the agent itself. The next challenge is binding authority to the state transition.
“A sandbox defines where an agent can act. A control plane defines what it is allowed to change.”
The control plane must be outside the agent
Two weeks ago, in our opening analysis of agent runtime boundaries (“MCP Gateways Are Not the Execution Boundary”), we established a foundational premise for production agent infrastructure:
“Tool authorization is not mutation authorization.”
Allowing an agent to call an API endpoint does not mean the system has authorized the downstream state transition that will result. An API gateway can verify a bearer token, validate JSON schemas, and log an HTTP POST. It cannot know whether the agent's reasoning was corrupted by prompt injection, whether an intermediate planning step hallucinated a critical prerequisite, or whether the state of the production database has mutated since the agent formulated its intent.
Between September 18 and September 28, 2026, the systems and infrastructure landscape responded with remarkable clarity. Across major cloud providers, identity networks, hardware vendors, and systems researchers, six independent announcements converged on the same architectural reality:
The control plane must be outside the agent — but authorization must ultimately be bound to the state transition.
This is not a cosmetic change in tooling. It represents the collapse of the early “self-policing agent” hypothesis. In operating systems, we never ask untrusted user-space code to enforce its own memory boundaries; we rely on the hardware MMU and kernel privilege rings. In cloud computing, we never ask guest operating systems to enforce their own tenant isolation; we rely on the hypervisor and the control plane.
Yet for the past eighteen months, much of the industry attempted to secure AI agents by prompting them to behave, inserting “guardrail” models into their context windows, or granting them long-lived API tokens to run wild across SaaS surfaces. The developments of late September 2026 mark the decisive end of that era.
Traceable Workload Identity
SPIFFE/SPIRE workload identities and STS-issued single-hop JWTs preserving actor chains across multi-agent hops.
MicroVM Sandboxes
Self-hosted AI agent sandboxes using Lambda MicroVMs (Firecracker) to isolate tool execution from reasoning.
Runtime Dynamic Identity
11-vendor coalition standardizing first-class agent identities, continuous observation, SSF/CAEP, and task-scoped tokens.
Agent Gateway & Kill-Switch
Enforcement moves directly into the runtime execution path with short-lived tokens and active session revocation.
Semantic-Policy Separation
MetaPermit uses LLMs to extract structured meta-attributes while a fixed deterministic engine enforces policy.
Out-of-Band Hardware Watchdog
OpenShell runtime boundary + Sentry running on BlueField-4 DPUs for hardware-isolated Zero Trust monitoring and quarantine.
AWS: Isolated Execution with Lambda MicroVMs
On September 18, 2026, AWS published an influential reference architecture for running self-hosted AI agent sandboxes with AWS Lambda MicroVMs. The architecture addresses a concrete operational vulnerability: when an agent runs code or invokes tools on behalf of a user, running those tools directly inside the host application environment risks credential leakage, lateral network movement, and host takeover.
AWS solves this by executing agent tool invocations inside ephemeral, isolated Lambda MicroVMs (built on Firecracker). Credentials, egress networking, and cloud IAM roles remain anchored strictly inside the customer's own AWS account. The reasoning runtime communicates with the sandbox across a strictly controlled boundary:
This is a vital engineering primitive. It decouples the agent's reasoning process from the blast radius of arbitrary tool execution. However, from a distributed control-plane perspective, it exposes a critical boundary fallacy:
“A sandbox defines where an agent can act. A control plane defines what it is allowed to change.”
A MicroVM ensures that if an agent executes an infinite fork-bomb or attempts to scan the local host subnet, the kernel container bounds the failure. But if the agent is delegated permission to call an internal database API, running that API call from a pristine MicroVM does nothing to verify whether dropping the customer billing table was the intended, semantically sound, and invariant-preserving state transition.
Containment is not authorization. The pipeline requires explicit progression:
Okta Blueprint Alliance: Identity Becomes Runtime State
Four days later, on September 22, 2026, Okta announced the formation of the Blueprint Alliance, alongside AWS, Google Cloud, CrowdStrike, Databricks, Docker, Salesforce, ServiceNow, Wiz, Proofpoint, and Zscaler.
The explicit focus of the Alliance is to solve what identity architects call the agent identity crisis: treating AI agents as traditional service accounts or standing OAuth clients. When an agent is provisioned with a long-lived credential, it inherits standing privilege that outlasts the context of the user prompt that initiated the task.
The Alliance outlines an interoperable security architecture based on emerging protocols such as the Model Context Protocol (MCP), Open Cybersecurity Schema Framework (OCSF), Shared Signals Framework (SSF), and Continuous Access Evaluation Profile (CAEP). The essential conceptual transformation replaces static IAM with a dynamic runtime lifecycle:
No insight into what the agent is reasoning about between token grant and API use.
Authority decays rapidly; policy reassessment occurs continuously across the workflow.
From a systems perspective, this shift recognizes that agentic authorization suffers from an acute freshness problem. In classical distributed systems, Time-of-Check to Time-of-Use (TOCTOU) bugs occur when state changes between permission evaluation and file mutation. In agentic systems, TOCTOU is amplified: an agent granted permission to update a Kubernetes deployment at t = 0 may experience hallucination, context contamination, or indirect prompt injection at t = 50s, long before the mutation is dispatched.
Okta: Enforcement Enters the Runtime Execution Path
Alongside the Blueprint Alliance, Okta unveiled its product roadmap at Oktane 2026 (AI Innovations at Oktane 2026), announcing an Agent Gateway equipped with runtime policy enforcement, short-lived identity-governed tokens, interaction logging, and an active session kill-switch.
The Agent Gateway is designed to sit directly in the invocation path between an AI agent and external tools. Crucially, it introduces the ability to revoke credentials in-flight and quarantine active agent sessions the moment anomalous behavior is detected.
This is a massive step forward from static perimeter security. Yet it forces an even sharper architectural question: What predicate is the gateway evaluating?
- Evaluates whether the endpoint can be called.
- Ignores who originally authorized the delegation.
- Blind to target system state and pre-conditions.
- Cannot enforce global invariants across multi-tool chains.
- Blind to the blast radius of parameter values.
- Evaluates the exact delta applied to production state.
- Preserves end-to-end cryptographic provenance.
- Verifies preconditions before applying mutations.
- Enforces invariant preservation and blast-radius budgets.
- Requires cryptographic evidence generation upon commit.
Uber: Traceable Execution Identity
To see where this architectural shift originated, one must look four months prior. On May 21, 2026, Uber published a pioneering engineering post titled Solving the Agent Identity Crisis.
Uber confronted the reality of complex internal agent workflows: an on-call engineer initiates an investigation; an orchestration agent analyzes alerts; that agent spawns specialized subagents for log analysis and metric correlation; and those subagents invoke MCP tools to fetch data or modify cluster routing. In such a multi-hop topology, if the leaf tool receives a generic service token, the entire audit trail dissolves.
Uber solved this by integrating SPIFFE/SPIRE workload identities with a central Security Token Service (STS). The STS issues short-lived, single-hop JSON Web Tokens (JWTs) with strict destination-specific audiences, preserving the entire actor delegation chain:
Uber's design solves three critical systems questions:
- Identity Answers:“Who is acting?”Attested cryptographic workload ID.
- Delegation Answers:“For whom?”Unbroken proof of delegation.
- Intent Answers:“What is proposed?”Structured action request.
Yet, as elegant as Uber's workload provenance is, it exposes the missing link in the chain: What state transition has actually been authorized? Knowing that Subagent B is acting on behalf of Engineer A to invoke Tool T does not verify whether the resulting mutation satisfies invariant safety.
MetaPermit: Separate Semantic Interpretation from Enforcement
On September 25, 2026, researchers published an essential systems paper: MetaPermit: Attribute-Based Access Control for AI Agents via Structured Metadata.
The central insight of MetaPermit is a clean architectural separation between semantic reasoning and policy enforcement. In traditional authorization engines (like XACML, OPA/Rego, or Cedar), rules require crisp, typed attributes: resource owners, project tags, tenant IDs, and classification levels. But agent requests arrive as ambiguous natural language instructions.
Instead of asking an LLM to evaluate the access policy directly—which creates non-deterministic, jailbreakable security—MetaPermit uses the LLM strictly as a semantic interpreter. The model extracts structured meta-attributes from the user intent and runtime context. Those attributes are then passed to a fixed, deterministic policy engine that evaluates hard Boolean allow/deny logic:
In empirical evaluations, MetaPermit demonstrated dramatic security improvements: a 31% increase in authorization consistency across ambiguous boundary cases, and zero malicious tool calls executed under indirect prompt injection attack vectors.
The governing architectural principle is clear:
Yet MetaPermit reveals a deeper systems dilemma: predicate poisoning. If the semantic interpreter is wrong—if it misclassifies an administrative destructive action as a read-only query—the deterministic policy engine will make the wrong decision with 100% mathematical determinism.
This forms the exact bridge to OpenKedge research: how can semantic claims be independently verified against target system state and pre-conditions before they become authority-bearing inputs?
NVIDIA: Enforcement Moves Outside the Agent Trust Domain
On September 28, 2026, NVIDIA announced the Open Agent Safety Platform, comprising two foundational infrastructure components:
- 1. OpenShell:
A hardened runtime boundary that wraps agent execution with granular call tracing, sandboxed syscall filtering, and runtime policy enforcement.
- 2. NVIDIA Sentry:
An out-of-band monitoring and policy watchdog running directly on BlueField-4 Data Processing Units (DPUs). Sentry observes network packets, telemetry, and agent execution completely outside the host CPU and operating system trust domain, enforcing Zero Trust policy and quarantining compromised agents in milliseconds.
We should be precise: hardware DPUs do not solve semantic authorization. But NVIDIA's architecture establishes an indispensable systems guarantee:
Subject to prompt injection, memory tampering, or rogue sub-process escalation.
Completely outside the host CPU. If the agent is compromised, it cannot tamper with Sentry.
“The control plane must be outside the agent.”
If the agent controls the runtime that enforces its own rules, the security boundary collapses under adversarial pressure. Moving enforcement to an independent trust domain (like a BlueField DPU or an external gateway) guarantees that the policy enforcement point cannot be bypassed from within the reasoning loop.
Yet enforcement independence only solves the containment problem. It guarantees that policies are enforced; it does not guarantee that the policy was passed the correct semantic intent.
Enforcement independence is not semantic authority
When we synthesize these six signals, a rigorous systems architecture emerges. But it also reveals a dangerous conceptual conflation in current industry discourse. Infrastructure engineers must cleanly distinguish between two fundamentally distinct questions:
Addressed by: MicroVMs (AWS), DPU hardware isolation (NVIDIA Sentry), out-of-band kill switches (Okta), and network namespaces. This ensures the agent cannot circumvent the sandbox or forge its workload identity.
Addressed by: Structured intent, deterministic admission, invariant checking, and postcondition verification. This ensures that the state delta applied to production is legitimate, bounded, and invariant-preserving.
Let us map how the recent industry announcements fit into this matrix:
| Signal | Architectural Focus | Solves Bypass? | Solves State Authority? |
|---|---|---|---|
| AWS (MicroVMs) | Execution containment | Yes (Hypervisor) | No (Tool blind) |
| Uber (SPIFFE/STS) | Actor chain provenance | Yes (Cryptographic) | No (Identity only) |
| Okta (Gateway / CAEP) | Runtime identity & kill-switch | Yes (Session level) | Partial (Token scope) |
| MetaPermit | Semantic-policy separation | Partial (Gateway) | Partial (Attributes) |
| NVIDIA (OpenShell/DPU) | Hardware out-of-band enforcement | Yes (DPU ASIC) | No (Network/syscall) |
Every major player is building a piece of the puzzle. But when you assemble all five technologies together, you still do not have a complete system for safe autonomous operations until you introduce the missing primitive: the state-bound execution contract.
The OpenKedge / PDDS Connection
These industry developments are converging on architectural problems we have been exploring independently through OpenKedge and our research on Post-Deterministic Distributed Systems (PDDS).
In our foundational paper, Sovereign Agentic Loops (SAL), we formulated the core execution pipeline required when stochastic reasoning agents interact with consequential distributed infrastructure:
The commercial ecosystem is now supplying increasingly robust, production-grade components for the lower layers of this stack:
- AWS supplies the MicroVM isolation runtime.
- Uber and Okta supply traceable workload identity and dynamic token lifecycle.
- MetaPermit validates the separation of semantic extraction from deterministic policy.
- NVIDIA supplies out-of-band hardware observation and millisecond quarantine.
OpenKedge's research focus sits directly at the synthesis layer: binding these disparate systems into a cohesive protocol where intent, authority, state, execution, and evidence form an unbreakable cryptographic chain.
Through protocols like Cognitive Admission Control (CAC), we model how probabilistic agent intent must be calibrated against system risk before any operational capability is minted. Through our research on Two-Phase Cognitive Commit (TCT), we define how multi-agent mutations can be prepared, invariant-checked against current production state, and atomically committed with immutable evidence receipts.
The missing primitive: the execution contract
If the control plane lives outside the agent, what exactly does it issue?
The industry is currently answering this question with “short-lived tokens” or “scoped API keys.” But as systems engineers know, an API token is a coarse instrument. It says: “Bearer may invoke HTTP POST /v1/clusters.” It cannot specify the permissible blast radius, the state preconditions that must hold, or the postcondition invariants that must be verified before the transaction is finalized.
The necessary systems primitive is a mutation-specific execution contract.
Notice how the various emerging industry pieces interact cleanly with this contract:
Validates the delegation chain and derives an ephemeral, single-use token tied directly to the SHA-256 hash of the execution contract.
Evaluates the proposed intent and blast radius against organizational risk policy before admitting the contract for execution.
Spawns a clean MicroVM matching the attestation requirements, restricting egress network interfaces strictly to target resources.
Monitors syscalls and packet streams out-of-band; if execution attempts any mutation outside the contract bounds, it revokes the token and quarantines the agent.
“Autonomous infrastructure needs authority bound to state transitions, not standing permission attached to agents.”
The 5-layer agentic control plane stack
We can now formalize the full architecture of the Agentic Control Plane across five distinct, decoupled layers:

Figure 1: Architectural synthesis of the six industry signals, the emerging execution pipeline, and the 5-layer control plane stack published in Edition #2.
Outside the agent is necessary — but not sufficient
The industry's convergence over the past two weeks represents tremendous progress. We are moving systematically from naive prompt-based self-policing toward rigorous distributed systems engineering:
- External workload identity
- External credential lifecycle
- External deterministic policy
- External MicroVM sandboxes
- External session kill-switches
- Independent DPU hardware watchdogs
All of these developments push control outside the agent. They establish that no agent should be its own hypervisor, its own auditor, or its own gatekeeper.
Yet once control is outside the agent, systems architects face the inevitable next question:
If the control plane authorizes a tool, the system remains vulnerable to semantic drift, hallucinated parameters, and unforeseen production blast radii.
If the control plane authorizes a state transition—via an explicit, bounded, invariant-checked execution contract—then autonomous agents can finally operate mission-critical cloud infrastructure with mathematical safety guarantees.
The control plane must be outside the agent — but authorization must be bound to the state transition.
“If autonomous systems are going to operate production infrastructure, should authority belong to the agent, the tool, the session — or the individual state transition?”
- Uber Engineering — “Solving the Agent Identity Crisis”, May 21, 2026. Published architectural blueprint introducing SPIFFE/SPIRE workload identity and short-lived, single-hop JWTs for AI agent delegation. [Uber Blog]
- AWS Architecture Blog — “Running Self-Hosted AI Agent Sandboxes with AWS Lambda MicroVMs”, September 18, 2026. Reference architecture detailing isolated tool execution in Firecracker MicroVMs within customer VPCs. [AWS Blog]
- Okta Newsroom — “Industry Leaders Form the Blueprint Alliance to Advance Secure AI Agent Identity”, September 22, 2026. Coalition with AWS, Google Cloud, CrowdStrike, Databricks, Docker, Salesforce, ServiceNow, Wiz, Proofpoint, and Zscaler. [Press Release]
- Okta Oktane 2026 — “Okta Unveils AI Innovations to Govern and Secure Autonomous Agent Runtimes”, September 22, 2026. Introduces Agent Gateway, runtime policy enforcement, Short-Lived Tokens, and Session Kill-Switches. [Oktane 2026 Announcement]
- MetaPermit Research Team — “MetaPermit: Attribute-Based Access Control for AI Agents via Structured Metadata”, September 25, 2026 (arXiv:2609.31039). Separating semantic interpretation from deterministic policy enforcement. [arXiv:2609.31039]
- NVIDIA Newsroom — “NVIDIA Announces Open Agent Safety Platform with OpenShell and BlueField-4 Sentry Watchdog”, September 28, 2026. Out-of-band Zero Trust agent monitoring, telemetry attestation, and millisecond quarantine on DPUs. [NVIDIA Newsroom]
- OpenKedge Research — “Sovereign Agentic Loops: Decoupling AI Reasoning from Execution in Real-World Systems”, April 2026 (arXiv:2604.22136). Reference execution pipeline for governed agent operations. [arXiv:2604.22136] · [OpenKedge Papers]
- OpenKedge Research — “Cognitive Admission Control: Risk-Conditioned Assurance for Consequential Actions in Agentic Distributed Systems” (arXiv:2609.16313, 2026). [Read on OpenKedge]
- OpenKedge Research — “When AI Agents Commit: The Two-Phase Cognitive Commit Protocol (TCT)” (arXiv:2609.16853, 2026). [Read on OpenKedge]
- OpenKedge Research — “Post-Deterministic Distributed Systems (PDDS)” (arXiv:2606.01722, 2026). [Read Overview]