Published July 10, 2026
| Version 1.0
Report
Open
The Evidence Closure Loop: Engineering a Bounded-Autonomous, Multi-Agent Security Staff for Evidence-Grounded Assessments and Bug Bounty
Authors/Creators
Description
Security teams are increasingly experimenting with large-language-model agents, yet most implementations optimize for generation speed rather than decision integrity. A system that can produce a polished report faster can also produce a polished mistake faster. This practitioner whitepaper presents an architecture for a scalable security staff built around role separation, explicit evidence models, mandatory adversarial quality assurance, and bounded autonomy. The implementation uses a central chief-of-staff, specialized security SMEs, a shared evidence workspace, and an independent Security QA gate. It applies Knowledge Augmented Generation (KAG) in two distinct planes: a retrieval plane that produces provenance-preserving evidence packs, and a decision plane that links scope, vulnerability semantics, evidence strength, trust boundaries, and qualification criteria. The paper contributes a transferable operating model, a dual-plane KAG pattern, an evidence-closure discipline, a triage-first bug bounty gate, and an evaluation framework that measures decision quality in addition to cost. The MiniCISO implementation is used as a reproducible case study, not as a product pitch.
Notes
Files
evidence-closure-loop-whitepaper.pdf
Files
(1.1 MB)
| Name | Size | Download all |
|---|---|---|
|
md5:12a404d6847ae722ce6f0f231946042d
|
1.1 MB | Preview Download |
Additional details
Related works
- Documents
- Software: https://github.com/icidade/miniCISO (URL)
References
- I. A. Cidade, "miniCISO: agentic security staff," public GitHub repository, 2026. https://github.com/icidade/miniCISO
- I. A. Cidade, "MiniCISO Staff Service Catalog v5," July 10, 2026. https://github.com/icidade/miniCISO/blob/main/miniciso-staff-service-catalog-v5.md
- P. Lewis et al., "Retrieval-Augmented Generation for Knowledge-Intensive NLP Tasks," NeurIPS, 2020. https://arxiv.org/abs/2005.11401
- L. Liang et al., "KAG: Boosting LLMs in Professional Domains via Knowledge Augmented Generation," 2024. https://arxiv.org/abs/2409.13731
- D. Edge et al., "From Local to Global: A Graph RAG Approach to Query-Focused Summarization," 2024. https://arxiv.org/abs/2404.16130
- Q. Wu et al., "AutoGen: Enabling Next-Gen LLM Applications via Multi-Agent Conversation," 2023. https://arxiv.org/abs/2308.08155
- National Institute of Standards and Technology, "Artificial Intelligence Risk Management Framework (AI RMF 1.0)," NIST AI 100-1, 2023. https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf
- National Institute of Standards and Technology, "Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile," NIST AI 600-1, 2024. https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf