OSuite OSuite.ai
Sign in Request access
← All research
Research direction · Productized · July 3, 2026 · 10 min read

Runtime Exposure Management

The customer-facing operating layer that turns governed agent actions into exposure inventory, remediation backlog, dependency risk, snapshots, and security evidence.

O
OSuite Research
Runtime Security
At a glance
Runtime Exposure Management is the operating surface that makes PCAA, CAVA, BAF, AREG, policy profiles, and Decision Score legible to security teams.
The research direction adapts exposure-management practice to agent actions: what can act, what it can reach, what approval binds, and what proof remains.
In OSuite, the output is not a dashboard for curiosity. It is a backlog, score, runtime map, dependency view, and exportable evidence path.
SignalRuntime action
AnalysisCAVA object
AuthorityPCAA binding
ClosureProof bundle

Runtime Exposure Management is the layer where OSuite research becomes operational for customers.

PCAA, CAVA, BAF, AREG, policy profiles, and Decision Score each close a specific control failure. But a buyer does not experience those primitives as papers. A buyer experiences them as a question: are our agents becoming safer to run, or are we adding automation faster than we can govern it?

Runtime Exposure Management turns the governed action stream into an operating surface for that question.

Why exposure is the right frame

An agent inventory tells a security team which tools exist. It does not tell them what those agents can reach, what authority they use, which business systems they touch, which approvals can be reused, which evidence is missing, or where failure would travel.

That is why exposure is more useful than generic governance language. Exposure forces the system to answer what is reachable, what is allowed, what is bounded, and what can be proven.

What OSuite measures

Runtime Exposure Management connects several product surfaces:

SurfaceBuyer question
Runtime inventoryWhich agents, hooks, MCP servers, SDKs, workflows, and gateways are active?
Exposure scoreIs runtime risk improving or drifting?
Exposure backlogWhat should the team fix, accept, or resolve first?
Dependency riskWhich providers, tools, systems, and evidence stores sit in the action path?
Bounded approval postureAre high-risk actions protected by narrow leases, or by reusable approval?
Runtime mapWhere can agent consequence travel across systems and boundaries?
Evidence exportCan the team reconstruct what happened after review, audit, or incident response?

Relationship to the research stack

The OSuite chain is intentionally layered.

PCAA decides who has final governance authority. CAVA turns agent activity into a governable action object. Policy profile and Decision Score decide whether that object should run, wait, escalate, or stop. BAF turns approval into a bounded action lease. AREG maps the agent, runtime, action, system, boundary, and evidence relationship.

Runtime Exposure Management is the operating layer above that chain. It does not replace the primitives. It makes them visible as security work.

Product implication

The important artifact is not a beautiful graph. It is a defensible workflow.

A security team should be able to see which runtime lanes are unverified, which agents have the largest blast radius, which approvals are unbound, which dependencies weaken evidence durability, which backlog items have owners, and whether the environment is safer than last week.

That is what turns OSuite from an AI governance dashboard into a governed action layer for enterprise agents.

More research
Paper

PCAA: Proof-Carrying Agent Actions

June 24, 2026
Framework

CAVA: Canonical Action Verification and Attestation

July 16, 2026

Approve high-risk AI work before it runs.

Request enterprise access and send your first governed decision today.

Request enterprise access Read the docs