KTP/
github ↗
created 24 August 2026 · last modified 24 August 2026
the rollout

From visibility to enforcement to governance, in five phases.

You don't need to solve all 1,612 risks. You need to control the ~337 where AI systems can actually act. If you do nothing else: centralize tool access, enforce policy there, log everything.

§01phase timeline

Phase 1: Visibility

2 to 4 weeks
  • Instrument agent actions across runtimes and orchestrators.
  • Log every tool call with subject, verb, object, channel, and context.
  • Stream telemetry into Splunk as a system of record.
outcome
You can see what's happening.

Phase 2: Soft controls

4 to 8 weeks
  • Detect risky patterns against the ten enforcement buckets.
  • Simulate policy decisions in shadow mode.
  • No blocking yet. Every decision is logged, not enforced.
outcome
You know what would have been blocked.

Phase 3: Guardrails

8 to 12 weeks
  • Enforce constraints at the tool gateway and data boundary.
  • Block obvious bad actions: out-of-scope queries, unknown destinations, over-scoped delegation.
  • Introduce escalation paths for ambiguous calls.
outcome
High-confidence risks are stopped.

Phase 4: Full enforcement

Ongoing
  • Inline veto at every enforcement surface.
  • Dynamic policy decisions that read identity, intent, context, resource, and trajectory.
  • Automated containment on rule trigger: revoke tokens, isolate runtime, halt chains.
  • Trajectory evaluation across action sequences, not only single events.
  • Induced-action evaluation when an agent routes consequence through a human.
outcome
Motion-layer risk is governed at machine speed.
phase 4 hardening

Phase 4 includes the hardening pass. Agent security is not only permission management. It is sequence governance. A chain of allowed verbs can still produce an unsafe outcome, and an agent that routes the final action through a human is still acting. Both must be evaluated.

Phase 5: Appropriateness governance

Ongoing, after Phase 4
  • Feed the normative context the physics cannot read: regulatory calendar, disclosure windows, organizational state.
  • Stand up the should-gate evaluators: de-automation triggers for fraught moments, propriety vetoes for the settled red lines.
  • Route the fast, signatureless cases to a human co-sign instead of letting them run on autopilot.
outcome
Actions pass both gates: safe to do, and right to do now.
phase 4 hardening

Appropriateness governance starts only after capacity enforcement is real. You cannot gate on whether an action is right for the moment until you can already gate on whether it is safe. This is the layer co-developed with Tamed Autonomy, and the maturity beyond control.

§02before / after

before / no ktp
after / ktp enforced
Agents act freely.
Actions are evaluated inline.
Controls are after-the-fact.
Risky behavior is blocked or constrained.
Detection is delayed.
Escalation happens automatically.
Blast radius is large.
Blast radius is bounded.

§03the tool gateway is the headline

if you do nothing else

The most important control is the Tool Gateway. If you do nothing else: centralize tool access, enforce policy there, log everything. That alone covers a large share of the top risks.

Every agent action goes through a single, policy-enforced choke point: databases, APIs, shells, browsers, file systems, ticketing, payments, cloud consoles, MCP servers. One layer to instrument, one layer to govern, one layer to audit.

next doors

Architecture

The PDP/PEP reference. Seven enforcement surfaces. Ten control sets. The verb library and the action tuple.

CISO

Eleven reasons in CISO terms. Budget justification frame. The board-ready narrative.

Methods

Failure modes named explicitly. The bounded public claim. The governability ladder.

the brutal summary
You don't need to solve all 1,612 risks. You need to control the ~337 risks where AI systems can actually act.
How to cite
APA 7th ed.

Perkins, C. (2026, May 6). From visibility to enforcement to governance, in five phases. Kinetic Trust Protocol. https://kinetic-trust-protocol.net/enterprise/roadmap
Plain text

Chris Perkins, "From visibility to enforcement to governance, in five phases," Kinetic Trust Protocol, https://kinetic-trust-protocol.net/enterprise/roadmap (accessed May 6, 2026).