A maturity scale for agentic runtime enforcement that measures how deeply a control can intervene before an action completes. Lower levels rely on observation or remediation, while higher levels support inline prevention, step-up checks, and autonomous governance around sensitive actions, credentials, and workflows.
What ARISE Control Depth Measures
ARISE Control Depth measures how far an agentic runtime control can intervene before an action finishes. At the low end, controls observe and report; at the high end, they can block, step up, or govern sensitive actions in flight.
Why Control Depth Matters
Control depth is the difference between seeing a bad action happen and stopping it before it completes. In agentic systems, that distinction matters because a single runtime decision can trigger tool calls, data movement, or credential use faster than a post hoc review can contain.
Deeper controls are more valuable when the action itself is high impact, such as a privileged workflow, a sensitive approval, or a credential-bearing operation. Shallow controls still have value for visibility and investigation, but they do not reduce the immediate blast radius in the same way.
How the Maturity Scale Works
ARISE is best read as a progression of enforcement strength. Lower maturity usually means detection, logging, or after-the-fact remediation. Mid-range depth adds human or policy intervention before completion, while higher depth moves into inline prevention and autonomous governance for actions that should not proceed without extra assurance.
The practical question is not whether a control exists, but where it sits in the action path. A control that evaluates after the fact may improve accountability, but a control that can pause, challenge, or deny the action changes the runtime security posture much more materially.
Where ARISE Fits in Agentic Governance
ARISE is useful for comparing controls that operate inside an agentic workflow, especially where the system can request approvals, enforce policy, or restrict execution based on context. It helps distinguish simple monitoring from controls that actively shape what the agent is allowed to do.
That makes it a governance concept as much as a technical one: the deeper the intervention, the more the organisation is asserting control over autonomy, privilege, and workflow execution. It is therefore a useful way to discuss whether a control is merely informative or genuinely preventive.
Risk and Threat Considerations
Shallow control depth creates exposure when a risky action can complete before anyone notices. In agentic systems, that can mean unauthorized tool use, premature credential use, or irreversible changes to data or workflows.
Failure mechanism: The control only detects or remediates after the action has already executed, so the attacker, misconfigured workflow, or over-permissioned agent gets a completion window with no inline barrier.
Impact: Sensitive actions can succeed even when they should have been blocked, which increases the chance of privilege abuse, accidental harm, and delayed containment.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | ASI03 — Identity & Privilege Abuse | ARISE depth governs how agent actions are constrained before privileged execution completes. |
| ASI02 — Tool Misuse | ARISE depth matters when a control must stop unsafe tool invocation, not just observe it. | |
| Recommendation — Apply ASI03 to block privileged agent actions until policy checks and step-up approval complete. Constrain tool calls with policy checks that intervene before unsafe execution. | ||
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | Deeper runtime controls reinforce least-privilege enforcement for sensitive actions. |
| AU-6 — Audit Record Review, Analysis, and Reporting | Lower-depth controls rely on observation and reporting, which maps to audit visibility. | |
| Recommendation — Apply AC-6 to limit agent actions to the minimum privileges required. Use AU-6 to detect and review agent actions that were not prevented inline. | ||
| NIST Zero Trust (SP 800-207) | N/A — Zero Trust Architecture | ARISE aligns with continuous verification before sensitive actions are allowed to complete. |
| Recommendation — Apply Zero Trust principles to verify context before each sensitive action is executed. | ||
Practitioner Guidance
What to watch for: Treat control depth as a design choice, not a reporting metric. If a workflow can trigger high-impact actions, a control that only logs events is usually not enough to meaningfully constrain risk.
Governance implication: Use the term to decide where inline prevention, step-up checks, or autonomous policy enforcement are warranted, especially for actions that involve privilege, sensitive data, or externally visible side effects.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 30, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org