Evaluating Folder-Oriented Governance for Agentic AI with Automated SIEM-Driven Alerts

Authors

DOI:

https://doi.org/10.70715/jitcai.2026.v3.i5.095

Keywords:

Agentic AI governance, Policy-as-code, SOC automation, SIEM integration, Runtime guardrails, Auditability

Abstract

Agentic AI can support security operations center (SOC) workflows, but ungoverned autonomy creates risks of unsafe action, weak traceability, and limited runtime control. This paper extends a prior folder-oriented governance prototype by replacing manual alerts with automated Wazuh SIEM ingestion while preserving folder-scoped policy-as-code, runtime guardrails, escalation, and structured audit logging. A controlled comparison with an unconstrained baseline evaluates policy effectiveness, escalation, auditability, and latency. The governed pipeline blocked 90 disallowed actions, produced complete audit traces, and consistently routed 75% of evaluated alerts to draft-only review states, with moderate latency overhead. These results indicate that folder-oriented governance can preserve bounded autonomy and accountability under automated alert ingestion.

Downloads

Download data is not yet available.

References

[1] G. Elongha, “Folder-oriented governance for agentic AI: A policy-as-code pattern for secure enterprise agents,” Issues in Information Systems, Vol. 27, no. 1, 2026. Available: doi:10.48009/1_iis_2026_01-14.

[2] E. Tabassi, “Artificial Intelligence Risk Management Framework (AI RMF 1.0)”, NIST AI 100-1. Gaithersburg, MD, USA: National Institute of Standards and Technology, Jan. 2023. Available: https://doi.org/10.6028/NIST.AI.100-1 DOI: https://doi.org/10.6028/NIST.AI.100-1

[3] Y. Shavit, S. Agarwal, M. Brundage, S. Adler, C. O'Keefe, R. Campbell, T. Lee, P. Mishkin, T. Eloundou, A. Hickey, K. Slama, L. Ahmad, P. McMillan, A. Beutel, A. Passos, and D. G. Robinson, Practices for Governing Agentic AI Systems. OpenAI, Dec. 2023. Available: https://openai.com/index/practices-for-governing-agentic-ai-systems/

[4] C. L. Wang, T. Singhal, A. Kelkar, and J. Tuo, "MI9: An Integrated Runtime Governance Framework for Agentic AI," arXiv preprint arXiv:2508.03858, Aug. 2025. Available: https://arxiv.org/abs/2508.03858

[5] A. G. Patil, “Governing Agentic AI: A Strategic Framework for Autonomous Systems,” Sep. 2025. Available: https://doi.org/10.13140/RG.2.2.16705.21608

[6] M. Abou Ali, F. Dornaika, and J. Charafeddine, "Agentic AI: A comprehensive survey of architectures, applications, and future directions," Artificial Intelligence Review, vol. 59, art. no. 11, 2026, Available: https://doi.org/10.1007/s10462-025-11422-4 DOI: https://doi.org/10.1007/s10462-025-11422-4

Downloads

Published

09/30/2026

Data Availability Statement

No datasets were generated in this study. The described methodology, system architecture, and Wazuh-SIEM integration provide enough information for independent reproduction of the approach.

How to Cite

[1]
D. G. Elongha, “Evaluating Folder-Oriented Governance for Agentic AI with Automated SIEM-Driven Alerts”, Journal of Information Technology, Cybersecurity, and Artificial Intelligence, vol. 3, no. 5, pp. 17–24, Sep. 2026, doi: 10.70715/jitcai.2026.v3.i5.095.

Share