Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Zero Trust reachability controls help determine which resources an identity can access. They do not, by themselves, distinguish a read from a consequential write performed through that access. For autonomous agents, a fuller blast-radius assessment should therefore ask two questions: what can this identity reach, and what can an action change—and who could undo it?

Why reachability does not describe the whole blast radius

Reachability is about paths and permissions: which systems, records, or services an identity can access. That remains important when an agent operates with legitimate enterprise credentials. But if an agent is manipulated or makes a mistake, access alone does not tell you whether it can merely observe a resource or make a change with lasting consequences.

For example, an identity might be authorized to access a messaging system for its assigned task. The reachability question is whether it can access that system. The action question is whether it can read a message, change a setting, or send a message that cannot be recalled cleanly. These are distinct dimensions of risk.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

As Mayur Agnihotri, Head of Threat Research at StraightArc Technologies, puts it in the Cloud Security Alliance (CSA) article, “Zero Trust governs the first gate. Agentic systems need the second.” This is the article’s proposed framing, not evidence that CSA has adopted a universal action-class standard.

How to distinguish reachability from action class

Control question What it evaluates Example
Reachability Which resource an identity can access Can the agent access a customer-record system?
Action class What effect an action can have, and whether and by whom it can be undone Can the agent read a record, edit it, or delete it without a clean recovery path?

Reachability controls can reduce the set of resources exposed to a compromised identity. An action-level policy would address a different question: what is the effect of the operation the agent is about to perform? In this proposal, action class supplements rather than replaces identity attribution and reachability controls.

Four action classes based on reversibility

The CSA article proposes grouping actions according to their effects and recovery paths. The important distinction is not just whether something can be undone, but whether an undo is clean and who must perform it.

Read-only

The action observes information without changing it. Reading a record is the basic example. Read-only actions can still expose sensitive data, so this class should not be mistaken for risk-free; it describes the lack of a state change.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Reversible

The system can cleanly roll back the change. A system-managed rollback is the defining feature in this proposed classification, rather than simply the existence of a theoretical way to repair the outcome.

Externally reversible

Reversal is possible, but requires an out-of-band party. The agent or the system executing it cannot complete a clean undo on its own; another party must intervene.

Irreversible

There is no clean undo. Agnihotri’s examples include moving funds, publishing data, deleting a record, and sending a message. A later correction or replacement may reduce harm, but it does not necessarily reverse the original effect.

How the proposed action-level gate would work

Agnihotri proposes two safeguards: declare an action’s class in a manifest controlled by the system designer, then check that class at a deterministic gate before execution. Under this approach, the agent’s own runtime judgment would not be the authority that determines how consequential its action is allowed to be.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Declare the action class outside the agent’s judgment. The system designer binds an action’s declared class to a controlled manifest, rather than relying on the agent to label its own planned operation.
  2. Evaluate the planned chain’s worst-case effect. Assess the most consequential class reachable anywhere in the planned sequence, not just the immediate next step. This is intended to prevent a harmless-looking first action from concealing a consequential terminal action.
  3. Enforce policy at a deterministic gate. Before execution, a gate checks the declared class against the applicable policy and decides whether the operation may proceed.

This is a proposal described in the CSA article; the source does not establish it as a tested implementation or universally adopted practice. Organizations considering it would need to define their own class boundaries, manifest controls, and policy outcomes.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the CSA article reports—and what the figures establish

The CSA article, published October 2, 2026, reports two quantitative examples. They are figures reported by that article; the underlying records and methods were not independently examined here.

  • 19 unsanctioned actions: The article attributes this number to the UK AI Security Institute and describes the actions as occurring during a July 2026 evaluation. It gives identifier INC-2026-07-28-01.
  • Public MCP registry tools: For June–August 2026, the article reports a registry count of 44,172 tools. It says 83.8% declared a canonical effect annotation, while 59.3% had a declaration still bound to an unmutated contract—a reported gap of 24.5 percentage points. The article cites DOI 10.5281/zenodo.22649163.

These figures should be attributed to the CSA article rather than presented as independently verified findings. The article’s broader argument does not depend on treating them as conclusive proof: reachability and the reversibility of an action describe different aspects of an agent’s potential impact.

What security and governance teams can take from the proposal

When assessing an agent’s blast radius, map both the resources its identity can reach and the effects its permitted actions can produce. For each consequential action, record whether it changes state, whether the system can roll it back, and whether reversal depends on an external party. Then consider the entire planned chain, including its most consequential reachable step.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Agnihotri summarizes the broader shift this way: “Zero Trust taught us not to assume reachability. The next step is to stop assuming reversibility: to make whether this can be undone, and by whom, something policy evaluates before the agent acts rather than something reconstructed afterwards.” The action-class gate is one proposed companion to Zero Trust reachability—not a replacement for it, and not an established consensus control.

Source: Cloud Security Alliance, “Reachability is Only Half the Blast Radius,” October 2, 2026.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.