What was read, and against which version
Written against v1.0, and the version is printed on every row that needs one. The
guarantee catalogue this page reads is the one v1.0 freezes:
G1–G11 ship today, and
G12–G24 arrive with v0.7 through v0.9 on the chain the roadmap sets out.
A row whose Since column names a version that is not yet tagged is a (design) row until
it is, and a reader on an earlier release should discount it. Nothing here is ticked on the
strength of a version that the roadmap does not already commit to before 1.0.
The form’s entry codes are ASI01:26 through ASI10:26, the same 2026 edition the
OWASP Agentic Top 10 reading was written against; that page
records how the ten titles were derived and asks anyone holding the published PDF to check
them.
Three words. Yes means a guarantee or a shipped command does what the checkbox says, and
the row names it. Partly means CTRLRun does a stated part of it, and the row says which part
it does not. No means nothing in CTRLRun addresses the box, and the reason is one sentence.
Lifecycle stages
The form asks which stages of the agent lifecycle a solution covers. CTRLRun is a library that sits at one point, between the decision to act and the call that acts, so it reaches most stages from that one point rather than covering each in its own right.Capabilities, checkbox by checkbox
The wording in the first column is the form’s, quoted so a reviewer can match rows without translation. Where the form names a technology as an example (e.g., Sigstore, Immudb), the example is theirs and is not a claim that CTRLRun uses it.Scope & Plan
Develop & Experiment
Augment & Fine Tune Data
Test & Evaluate
Release
Deploy
Monitor
Operate
Govern
Agentic Top 10 coverage
The form asks forASI01:26 through ASI10:26 as ten checkboxes. The
Agentic Top 10 reading carries the row-by-row mapping and the
sentence for each entry saying what is not covered; this table is the summary at v1.0, with
the version that moved each entry.
What this page is for
A submission to the landscape is filled in from this page and from nothing else, so that every ticked box has a row here and every row points at something that runs. If a box is ticked on the form and its row here says No, the form is wrong. If a guarantee behind a Yes loses its test, the row becomes Partly or No in the same commit, on the rule the Agentic Top 10 reading already follows. This page is regenerated when the guarantee catalogue changes, when a version named in a Since column is tagged, and when OWASP revises the form. It was written againstctrlrun.guarantees/v5 as the roadmap defines it for v0.9 and the form as
read on 2026-09-10.
Next
- OWASP Agentic Top 10: the row-by-row mapping this summary is drawn from.
- Verify: how each guarantee is checked against your configuration, and why not applicable is not a pass.
- Why CTRLRun and Get started.