Executive summary
The Agentic System Evidence Workbook is a public set of human-readable guides and machine-readable templates. It covers the machine-intelligence reference architecture, agent control plane, tool contract, trace schema, topology decision matrix, incident-response runbook, change register, failure taxonomy, and release gate. The workbook is intentionally modular: a deterministic or fixed-RAG workflow may need only a subset, while a consequential multi-agent or swarm system needs stronger coordination, containment, and recovery evidence.
Decision relevance: Assemble the minimum architecture and evidence package needed to decide whether one agentic workflow is ready for deeper evaluation or release review.
Workbook components
Workbook component
Reference architecture
Define the operating planes, authority boundary, and evidence path.
Workbook component
Agent control loop
Map propose, authorize, execute, verify, update, and stop.
Workbook component
Tool contract JSON
Constrain identity, authorization, effects, budgets, errors, and change.
Workbook component
Trace schema JSON
Correlate task, policy, tool, effect, state, human decision, and recovery.
Workbook component
Topology matrix
Select a coordination topology only when it beats a simpler baseline.
Workbook component
Swarm pattern catalog
Use local feedback inside externally enforced invariants.
Workbook component
Incident-response checklist
Contain authority, preserve evidence, reconcile effects, and validate recovery.
Workbook component
Change-control register
Reopen the release decision when a material boundary changes.
Workbook component
Release gate
Record release, conditional release, hold, or stop.
How to use the workbook
Begin with one named workflow, consequence, owner, and prohibited-use boundary. Select the least complex architecture that can meet the need. Fill only the templates that correspond to real system capabilities. Attach current evidence rather than aspirational policy text.
- Define the decision, affected people, use boundary, and completion condition.
- Map models, context, state, tools, identities, authority, human review, and operations.
- Write a contract for every consequential tool or remote agent capability.
- Define trace evidence before testing so that failures can be reconstructed.
- Run representative, edge, adverse, recovery, and change cases.
- Record release, conditional release, hold, or stop with owners and evidence-to-close.
What the workbook does not do
It does not generate a maturity score, certify security, make a legal determination, estimate return on investment, or authorize autonomous action. It is a starting structure for accountable human review.
Sources
Sources support the linked statements and terminology. They do not certify a system, establish buyer intent, or convert this research into a formal assurance.
- Artificial Intelligence Risk Management FrameworkNIST · Accessed 2026-08-01
Government framework
- AI Agent Standards InitiativeNIST · Accessed 2026-08-01
Government initiative
- Accelerating the Adoption of Software and Artificial Intelligence Agent Identity and AuthorizationNIST NCCoE · Accessed 2026-08-01
Government concept paper
- Summary Analysis of Responses to the Request for Information Regarding Security Considerations for AI AgentsNIST · Accessed 2026-08-01
Government technical report
- Model Context Protocol specification, 2026-07-28Model Context Protocol · Accessed 2026-08-01
Technical specification
- Agent2Agent Protocol Specification 1.0A2A Protocol · Accessed 2026-08-01
Open technical specification
- OpenTelemetry Semantic ConventionsOpenTelemetry · Accessed 2026-08-01
Open telemetry specification
- Securing Agentic Applications Guide 1.0OWASP GenAI Security Project · Accessed 2026-08-01
Open security guidance