Research

Watch · narrated whiteboard episodesL3

Multi-Agent Trust and Security Models

A single agent has one identity and one perimeter; a mesh of agents that call, delegate to, and depend on one another has neither. This series builds trust and security models for multi-agent systems from the ground up: why agent meshes break the perimeter and single-identity assumptions that security was built on, how to reason about trust with capability-based, reputation-based, and zero-trust models specialized to meshes, how trust propagates through delegation and where transitive trust turns into confused-deputy attacks at scale, how agents make verifiable claims to one another through attestation and signed provenance, and how it all assembles into a reference architecture of trust brokers, policy meshes, and failure containment. Grounded in NIST SP 800-207 Zero Trust, the NIST AI RMF, the OWASP Agentic Security Initiative and LLM Top 10, MITRE ATLAS, the SPIFFE workload-identity specification, the OAuth 2.0 Token Exchange RFC, object-capability security, and the peer-reviewed literature on reputation systems and zero-knowledge proofs.

Murali Chillakuru·5 episodes
  1. 11 min Episode 1The Multi-Agent Trust Problem: Why Agent Meshes Break Perimeter and Single-Identity AssumptionsA moderator and a principal engineer work through why a mesh of agents is not a bigger single agent, and what security assumptions quietly stop working.
  2. 10 min Episode 2Trust Models for Agents: Capability-Based, Reputation-Based, and Zero-Trust for MeshesA moderator and a principal engineer compare three trust paradigms for agent meshes and show why a durable design layers all three rather than picking one.
  3. 9 min Episode 3Delegation and Transitive Trust: Trust Propagation, Confused-Deputy at Scale, and Chain-Length LimitsA moderator and a principal engineer trace how authority propagates along a delegation chain and derive the three invariants that keep it safe.
  4. 9 min Episode 4Verifiable Inter-Agent Claims: Attestation and Signed Provenance Between AgentsA moderator and a principal engineer show how to replace bare assertions between agents with evidence a receiver can check for itself.
  5. 10 min Episode 5A Reference Architecture: Trust Brokers, Policy Meshes, and Failure ContainmentA moderator and a principal engineer assemble the mesh trust mechanisms into a concrete architecture and trace one request through it, twice.