Loading...
Companion explanation; not a fifth CoSAI operating model.
SRF v1.0 still has four models. Autonomy classifies how independently an
agent may act; it does not move the accountable persona. For Agent-PaaS
and IaaS especially, ask where authorization is actually enforced, not
only where the agent executes.
Proposed for the next SRF paper →
Enforcement planes. North-south is agent to model
provider (often L5 policy and spend). East-west is agent to agent
(Agent-PaaS identity and delegation). Agent-to-tool is MCP or other
tools (L3). On Agent-PaaS the provider typically owns the orchestration
runtime that can halt a swarm; the customer owns agent definitions and
which tools are granted. On IaaS the customer owns nearly the entire
enforcement path. On AI-SaaS the provider owns most runtime
enforcement; the customer still owns L1 outcomes.
See enforcement plane.