What was read, and against which version
Written against what is tagged, and the version is printed on every row that needs one.
Every guarantee cited below is in the catalogue
ctrlrun verify runs today, G1 through
G32, and every one of them is in the 0.12.2 wheel. There are no design rows. A Since
column names the milestone that added the row rather than a separate download: 0.3.0 was
published to TestPyPI alone, and what it added reached PyPI inside 0.4.0. This page was first written against an unreleased 1.0 and marked the rows that waited
on it; none of them waits any longer, and the hedge came out rather than being left to read
as a disclaimer on rows that ship. Nothing here is ticked on the strength of something
unreleased, and a row whose guarantee loses its test goes back to No in the same commit.
The form’s entry codes are ASI01:26 through ASI10:26, the same 2026 edition the
OWASP Agentic Top 10 reading was written against; that page
records how the ten titles were derived and asks anyone holding the published PDF to check
them.
Three words. Yes means a guarantee or a shipped command does what the checkbox says, and
the row names it. Partly means ctrlrun does a stated part of it, and the row says which part
it does not. No means nothing in ctrlrun addresses the box, and the reason is one sentence.
Lifecycle stages
The form asks which stages of the agent lifecycle a solution covers. ctrlrun is a library that sits at one point, between the decision to act and the call that acts, so it reaches most stages from that one point rather than covering each in its own right.Capabilities, checkbox by checkbox
The wording in the first column is the form’s, quoted so a reviewer can match rows without translation. Where the form names a technology as an example (e.g., Sigstore, Immudb), the example is theirs and is not a claim that ctrlrun uses it.Scope & Plan
Develop & Experiment
Augment & Fine Tune Data
Test & Evaluate
Release
Deploy
Monitor
Operate
Govern
Agentic Top 10 coverage
The form asks forASI01:26 through ASI10:26 as ten checkboxes. The
Agentic Top 10 reading carries the row-by-row mapping and the
sentence for each entry saying what is not covered; this table is the summary at 0.12.2,
with the version that moved each entry. Each row’s guarantees are exactly what that reading
maps to the entry, which is a test and not an intention.
What this page is for
A submission to the landscape is filled in from this page and from nothing else, so that every ticked box has a row here and every row points at something that runs. If a box is ticked on the form and its row here says No, the form is wrong. If a guarantee behind a Yes loses its test, the row becomes Partly or No in the same commit, on the rule the Agentic Top 10 reading already follows. This page is regenerated when the guarantee catalogue changes, when a version named in a Since column is tagged, and when OWASP revises the form. The first two both happened without it, so the rule is now a test rather than a sentence:tests/test_owasp_landscape.py checks
that every guarantee cited here exists in the registry, that the catalogue named is the one
ctrlrun verify reports, that no Since column names a version the changelog has not
released, and that each ASI row’s guarantees are exactly what the
Agentic Top 10 reading maps to that entry. It was written against
ctrlrun.guarantees/v7, the catalogue 0.12.2 ships, and the form as read on 2026-09-10.
Next
- OWASP Agentic Top 10: the row-by-row mapping this summary is drawn from.
- Verify: how each guarantee is checked against your configuration, and why not applicable is not a pass.
- Why ctrlrun and Get started.