Plain-language translation

For agent workflows, trust should not be granted because a model or vendor is approved. It should be granted per identity, environment, task, tool and action.

That is the operational meaning of zero trust in this context.

Control categories

The practical categories are identity, least privilege, tool governance, data protection, runtime monitoring, incident response and evidence. Each category should map to a policy decision that can be tested.

A framework becomes useful when teams can ask: what would block this action?

Implementation path

Start with one high-risk workflow, define approved actions, enforce locally and collect evidence. Then expand to more environments once the control loop is understandable.

Policy before action. Evidence after execution.