OSuite OSuite.ai
Sign in Request access
← All research
Framework · Research manuscript · June 27, 2026 · 12 min read

Agent Runtime Exposure Graph

A graph model for making agent blast radius visible across runtimes, tools, actions, systems, policy boundaries, leases, and proof evidence.

O
OSuite Research
Runtime Security
At a glance
AREG turns agent, runtime, action, and system relationships into a runtime security map.
The graph helps teams see blast radius, boundary drift, unverified runtimes, reusable approvals, and evidence gaps before agent adoption spreads.
AREG makes incident review and deployment readiness depend on connected runtime facts instead of disconnected logs.
SignalRuntime action
AnalysisCAVA object
AuthorityPCAA binding
ClosureProof bundle

AREG, short for Agent Runtime Exposure Graph, is the runtime security map behind OSuite.

Decision records are useful, but isolated records do not answer the question security leaders ask during rollout and incident review: if this agent goes wrong, where can the damage travel?

AREG connects agents, runtime lanes, tools, systems, actions, policy boundaries, approval leases, proof receipts, and closure events into one graph.

Protocol edges and governance gaps

Agent protocols make runtime edges more visible: an MCP call, A2A handoff, ACP message, workflow event, or managed connector invocation can tell the graph how work moved. That is valuable evidence, but it is not the same as governance closure.

AREG treats protocol records as graph edges whose assurance depends on the surrounding control path. If a protocol lane lacks dissent preservation, human escalation, approval binding, proof receipts, or exception ownership, the graph should show that as an evidence gap rather than hiding it behind a green integration status.

What the graph connects

Node or edgeProduct meaning
agentThe autonomous or semi-autonomous actor requesting work.
runtime laneThe place where action enters OSuite, such as hook, MCP, SDK, workflow, or gateway.
actionThe canonical action object produced by CAVA.
target systemThe repository, SaaS object, API, table, customer record, account, or endpoint affected.
boundaryProduction, customer data, external communication, money, network, privilege, or policy boundary.
leaseThe BAF Action Gate Lease that allows or rejects reuse.
proof receiptThe replayable evidence that closes the decision.

Why it matters

Agent security is not only about whether one action was allowed. It is about exposure shape.

One agent may be harmless because it only reads internal drafts. Another may be dangerous because it can write to production, send external messages, and trigger downstream workflows. AREG makes that difference visible.

This lets OSuite answer practical questions:

  • Which agents touch production-adjacent systems?
  • Which actions cross external or customer-data boundaries?
  • Which runtime lanes are unsigned or unverified?
  • Which approval leases are expired, reusable, or missing proof?
  • Which systems would be affected if an agent session is compromised?

How it fits OSuite

CAVA gives OSuite a governable action. PCAA gives the action an authority model. BAF makes approval bounded. AREG shows how the governed action sits inside the customer's runtime environment.

The result is not another dashboard for curiosity. It is a map for readiness, blast radius, and incident evidence.

Customers experience AREG as the Agent Runtime Security page: runtime map, exposure vectors, top blast-radius agents, firewall lanes, readiness score, and evidence bundle paths.

More research
Paper

PCAA: Proof-Carrying Agent Actions

June 24, 2026
Framework

CAVA: Canonical Action Verification and Attestation

July 16, 2026

Approve high-risk AI work before it runs.

Request enterprise access and send your first governed decision today.

Request enterprise access Read the docs