Published July 10, 2026 | Version 1.0

The Evidence Closure Loop: Engineering a Bounded-Autonomous, Multi-Agent Security Staff for Evidence-Grounded Assessments and Bug Bounty

Authors/Creators

Description

Security teams are increasingly experimenting with large-language-model agents, yet most implementations optimize for generation speed rather than decision integrity. A system that can produce a polished report faster can also produce a polished mistake faster. This practitioner whitepaper presents an architecture for a scalable security staff built around role separation, explicit evidence models, mandatory adversarial quality assurance, and bounded autonomy. The implementation uses a central chief-of-staff, specialized security SMEs, a shared evidence workspace, and an independent Security QA gate. It applies Knowledge Augmented Generation (KAG) in two distinct planes: a retrieval plane that produces provenance-preserving evidence packs, and a decision plane that links scope, vulnerability semantics, evidence strength, trust boundaries, and qualification criteria. The paper contributes a transferable operating model, a dual-plane KAG pattern, an evidence-closure discipline, a triage-first bug bounty gate, and an evaluation framework that measures decision quality in addition to cost. The MiniCISO implementation is used as a reproducible case study, not as a product pitch.

Notes

Repository details in this paper were checked against the public icidade/miniCISO repository and the supplied Service Catalog v5. Operational telemetry and historical incidents are author-provided observations and are labeled as such.

Files

evidence-closure-loop-whitepaper.pdf

Files (1.1 MB)

Name Size Download all
md5:12a404d6847ae722ce6f0f231946042d
1.1 MB Preview Download

Additional details

Related works

Documents
Software: https://github.com/icidade/miniCISO (URL)

References