The frame

Security has three A's. The agent era needs a fourth.

Authentication, authorization, and accounting were built for actors that stayed inside one system and could be trusted to keep their own books. Autonomous agents are neither. Attestation is the fourth A, and Behavry is it.

/001 · THE MANIFESTOBEHAVRY · RECORD

An actor cannot attest to itself.

Security has always rested on three A's. Authentication: who are you? Authorization: what may you do? Accounting: what did you do?

They were built for a world where the actor was a human or a static service. It lived inside one environment, and the account it kept of itself could be trusted.

Autonomous agents break both assumptions. They act across environments no single vendor owns. And their self-report cannot be trusted, because the actor is the party under examination.

So the agent era needs a fourth A. Attestation: an independent, provable record of what an agent actually did, across every environment it touched.

Behavry is that fourth A. And the only way to deliver it is to not stop at the boundaries between AI environments, which is exactly where every other tool stops.

Guardian agents enforce. Behavry is the one that also proves it

/002 · THE FOUR A'SON ONE SLIDE

Authentication. Authorization. Accounting. Attestation.

Three of these have an owner. The fourth has a gap where the owner should be, and the gap is exactly where autonomous agents do their damage.

The AThe questionWho answers it todayIn the guardian-agent anatomyWhy it is not enough for agents
Authentication Who is the agent? IAM. Okta, Entra Agent identity. The layer beneath the new-to-AI layers Proves the agent got in the door. Says nothing about what it does next.
Authorization What may it do? IAM, RBAC, policy The Operative. Runtime inspection and enforcement Governs access, not execution. Every step is permitted. The composition is the breach.
Accounting What did it do? SIEM and vendor logs. Splunk, Datadog, CrowdStrike Tamper-evident audit trails, self-produced by each vendor Self-reported by the actor, siloed per vendor. A curated log is exactly what an incident cannot rely on.
Attestation What did it actually do, and can you prove it? Nobody. This is Behavry. The unnamed intersection of independence and tamper-evidence The record has to be independent of the actor and span every environment it crossed.

THE ONE-LINERS/The first three A's stop at a boundary. We don't/The other A's answer who and whether. We answer what actually happened, provably

/003 · THE PROBLEMRISK IS COMPOSITION

Three green checkmarks. One breach.

A Copilot reads an earnings draft. A Salesforce agent updates the deal. An internal agent emails it out. Each step passes authentication and authorization. Each system's accounting says it did its job. And the workflow is still a breach.

IAM · Okta, Entra

Authenticates at the door: who got in. Blind to what the agent did next, and to delegation that crosses into another vendor. Not a missing field. The wrong evaluation model.

SIEM · Splunk, Datadog, CrowdStrike

Aggregates what got logged. Blind to why it happened, or how events across systems connect into one intent. You cannot observe your way to chain of custody.

Vendor-native · Microsoft, Salesforce

Guards its own product and is self-attested, which is the one thing an incident cannot rely on. Microsoft sees Microsoft. Salesforce sees Salesforce.

Observe everything. Control nothing. Not anymore.

Risk is not a bad action. Risk is composition. Each hop is green. The chain is red.

/004 · WHY ONLY BEHAVRYINDEPENDENT · CROSS-PERIMETER · DETERMINISTIC

Three structural properties. None is a feature.

The fourth A can only be delivered by a guardian agent with all three. All three are architecture, which is why they hold, and why this is the guardian agent no incumbent can become.

PROPERTY 01 Independent

An actor cannot attest to its own behavior. Behavry signs the Decision Trace from a control plane the agent, its vendor, and your SIEM cannot reach. That is not a claim about our integrity. It is a property of where the signature happens. It is also why we survive consolidation: the moment an acquirer absorbs an independent attester, it stops being independent, so this is the one function a platform cannot roll up.

PROPERTY 02 Cross-perimeter

Every competitor sees one surface. Harm from autonomous agents lives in the chain across surfaces, where every step is authorized and the composition is the breach. We are in-path at the tool boundary across vendors and reconstruct the whole causal sequence. You have to be in-path across vendors to enforce on the chain, and being in-path across vendors is exactly what lets you prove it.

PROPERTY 03 Deterministic

We decide with an OPA policy engine, fail-closed. We do not adjudicate a consequential action with a probabilistic model. Most guardian agents put an AI in the enforcement path and log their own verdicts. That is one party grading its own work with a probabilistic pen. To a security architect, that is the difference between a control and a guess.

12 inventions filed March 2026

The portfolio covers the Decision Trace (causal chain-of-custody across agents, tools, and delegations), delegation-graph enforcement (authorization over the delegation chain, not just the credential), cross-session reconstruction (fragment reassembly for compositional harm), and versioned behavioral contracts.

/005 · THE CATEGORYINDEPENDENT GUARDIAN AGENT

The fourth A is not a rival category. It is the insight inside one.

Gartner's Market Guide for Guardian Agents requires independence from the AI platforms, and separately requires tamper-evident audit trails. It never fuses them. The word attestation appears zero times in its 33 pages. That intersection is the fourth A, and it is the whitespace the guide circles without naming.

To an analyst

Behavry is a guardian-agent Operative that also produces the evidence. Your Market Guide mandates independence and mandates tamper-evident audit trails, but never names their intersection. We do. It is independent attestation.

To a CISO

You already run three A's. Agents broke them, because the actor now crosses systems and keeps its own books. Behavry is the fourth A.

WHY NOW/A Fortune 500 will run 150,000+ agents by 2028, up from fewer than 15 in 2025/Source: Gartner

/006 · PROOFNO ACCOUNT · NO LOGIN · NO TRUST REQUIRED

Don't trust our log. Check it.

The strongest thing Behavry says is not a claim. It is an invitation. Verify a real evidence package yourself, in your browser, no account. The record is signed by a control plane the agent could not touch, and anyone you hand it to can confirm it independently.

GET /api/v1/public/verify?hash=<event-hash>

200 OK
{ "verified": true }

Say yes to autonomous agents. With proof.

BOOK A BRIEFING →