OWASP GenAI / Agent Control Standard

Agent Control Standard, mapped to BitEvo authority and evidence gates

The OWASP GenAI Security Project added the Agent Control Standard on 1 September 2026. ACS v0.1.0 defines a Guardian-mediated control channel and conformance profiles. This page maps those control surfaces to evidence questions BitEvo can scope. It is not an ACS implementation, conformance test or certification claim.

v0.1.0 · seven declared profile IDs

ACS profile → BitEvo gates → evidence → boundary

acs-core

ACS-Core

BitEvo gates: Authority Budget · Object binding · Authority owner

Evidence we would scope

For a consequential step: the agent and Guardian identities, the requested action and object, and the Guardian decision that is bound before the action proceeds.

Boundary

ACS-Core is the mandatory v0.1.0 baseline. This mapping does not claim that Core alone makes a deployment secure or its policy strict.

acs-trace

Trace

BitEvo gates: Evidence Before Effect · Freshness

Evidence we would scope

A trace or event record that links the Guardian decision to the governed step with enough identity and time context to reconstruct what happened.

Boundary

Trace is observability evidence. A trace event is not, by itself, proof that the external system reached the intended state.

acs-inspect

Inspect

BitEvo gates: Authority Budget · Freshness

Evidence we would scope

The Agent Bill of Materials visible for the session: models, MCP servers, A2A peers, tools, knowledge sources and memory stores relevant to the scoped action.

Boundary

We use the component inventory as evidence for the scoped workflow; this is not a software-composition certification.

acs-inspect-dynamic

Inspect Dynamic

BitEvo gates: Freshness · Recovery

Evidence we would scope

The component mutation reported during the session and the control response when the component set changes after the original decision context.

Boundary

We test the agreed change path and constrained response, not every possible runtime mutation.

acs-provenance

Provenance

BitEvo gates: Evidence Before Effect · Freshness

Evidence we would scope

Origin, source identifier and lineage available for decision-bearing fields at the control boundary.

Boundary

We test whether the decision can bind to provenance evidence. We do not assign a universal trust score to the source.

acs-crypto

Crypto

BitEvo gates: Evidence Before Effect · Authority owner

Evidence we would scope

Where the profile is in scope, the signed audit material, verification result and identity or key relationship used to attribute the record.

Boundary

Cryptographic evidence does not turn an unsafe policy into a safe one, and this mapping is not a key-management or non-repudiation certification.

acs-audit

Audit

BitEvo gates: Recovery · Evidence Before Effect

Evidence we would scope

A reconstructable audit chain for the governed action and the defined response when required audit evidence is missing, broken or cannot be verified.

Boundary

We test evidence continuity and constrained behavior for the agreed action. This is not an ACS conformance audit.

Control boundary

ACS and BitEvo answer different questions.

ACS defines a control and observability protocol surface. BitEvo's seven gates ask whether authority for a specific external effect is bounded and evidenced. This page is a scoping crosswalk, not an ACS conformance statement or OWASP endorsement.