Arcezia / AI agent security / Where Arcezia fits
AI agent security stack: where execution integrity fits
AI agent security splits into five layers. Model security stops prompt injection and jailbreaks from changing what a model says. Agent governance finds and inventories the agents an organisation runs. Identity and authorization decides who an agent is and what it may hold. Execution integrity decides whether this exact tool call should run now, with these arguments, on the evidence available. The execution environment limits what a call can reach once it runs. Arcezia works at the fourth layer, execution integrity, alongside the other four. It does not replace them.
The five layers, and what each cannot answer
Each layer answers one question well and leaves another open. The gaps are why a stack needs more than one of them.
Model and AI security
Answers: Stops prompt injection and jailbreaks from changing what a model says, and filters what goes in and comes out.
Cannot answer: Whether a well-formed, polite tool call should run. A call can pass every content check and still delete the wrong thing.
Agent governance
Answers: Finds the agents an organisation runs, keeps an inventory, and reports their configuration and posture.
Cannot answer: What a given agent is about to do in the next second. An inventory describes agents; it does not stand between an agent and a call.
Identity and authorization
Answers: Gives an agent an identity, keeps its secrets, and grants it privileges: who is calling, and what it may hold.
Cannot answer: Whether this one call, with these arguments, should run now. A valid credential with broad rights answers yes to every call it covers.
Execution integrity
Answers: Whether this exact tool call should run now, on the evidence available: the arguments, the records it touches, the session’s signed limits, and what your own systems confirm. Arcezia works here.
Cannot answer: What a call can reach once it runs, and who the agent is. Those are the layers on either side.
Execution environment
Answers: Limits what running code can reach: sandboxes, containers, network rules, endpoint and workload security.
Cannot answer: Whether an action that is allowed by the sandbox should happen. A delete inside the sandbox’s reach is still a delete.
Execution integrity vs guardrails, identity and sandboxes
Guardrails mostly look at text. Identity looks at who is calling. A sandbox looks at what code can reach. None of these, on its own, asks whether this call should happen now. In the Replit incident, the agent acknowledged a code freeze in its text and then ran destructive commands. In the PocketOS incident, a valid token deleted a production volume. More cases, each from primary sources: AI agent incidents.
What Arcezia covers
| Covers | How |
|---|---|
| A decision before the call runs | ALLOW, REVIEW or BLOCK on the exact call: tool, arguments, records, session. Only ALLOW should reach the tool. |
| Evidence from your own systems | Facts that only your systems can confirm, such as an approval or a recent backup, come from your systems. What the agent claims never clears a call; it can only be caught out. |
| Multi-step checks | A plan of several calls checked as a whole before any step runs. |
| Approvals bound to one call | A person’s approval is a token your backend signs, released once for one call. An approval the agent merely claims is refused. |
| Signed records | Every answer is kept as a signed record that an auditor can check offline. |
| A check after the action | What a cleared action actually did can be compared with what was intended. |
What Arcezia does not cover
| Layer | Covered? |
|---|---|
| Sandboxing | No. Run agents in a sandbox or container as well. |
| Endpoint and workload security | No. |
| Secrets management | No. Keep keys and credentials in a secrets manager. |
| Agent identity | Partly. The session’s limits and each approval are signed with keys you hold, and a pass can bind one call to one service. Arcezia does not issue or manage agent identities. |
| Prompt-injection filtering | Only indirectly. It does not read or filter prompts. An injected instruction still has to become a tool call, and the call is what gets checked. |
| Software supply chain | No. |
Use Arcezia with those layers, not instead of them.
Check the layer yourself
One SQL call, checked three times on the live service, with the code to replay it on your own free key: allowed, held and refused. The signed records of that run, with the offline checker: audit evidence.