International Journal For Multidisciplinary Research

E-ISSN: 2582-2160     Impact Factor: 9.24

A Widely Indexed Open Access Peer Reviewed Multidisciplinary Bi-monthly Scholarly International Journal

Call for Paper Volume 8, Issue 4 (July-August 2026) Submit your research before last 3 days of August to publish your research paper in the issue of July-August.

When the Observer Acts: Threat Modeling Agentic AI in Observability Pipelines

Author(s) Shiva Raju
Country India
Abstract Observability platforms have historically been read-only consumers of telemetry: they collected, correlated, and displayed. Recent reference architectures for generative and agentic root cause analysis (RCA) break that assumption. When an initial diagnosis falls below a confidence threshold, the system invokes an agent that autonomously queries monitoring tools, reads source repositories, and executes policy-driven actions until sufficient evidence is assembled. The observer has become an actor. This paper argues that the security consequences of that shift have not been systematically analyzed, and supplies the missing analysis. Taking the four-layer GenAI-driven observability architecture of [1] as a representative system under analysis, we construct an explicit threat model: three trust zones, three trust boundaries, four adversary classes, and nineteen threats enumerated with STRIDE across seven architectural elements. We then trace three end-to-end attack chains that each cross all three boundaries, the most consequential being telemetry-borne instruction injection, in which an adversary who can influence a single application log line reaches the production control plane without ever authenticating to the observability platform. Two structural properties make agentic observability distinctively exposed: telemetry is attacker-influenced input that has never been treated as such, and the diagnostic agent necessarily holds broad standing read privilege across the estate. We propose twelve design-level controls organized into four families — provenance, corpus integrity, least authority, and accountability — and identify the residual risks that no current control fully addresses. This work is analytical in scope. It contributes no implementation and reports no experiments; its purpose is to establish the threat vocabulary and design constraints that empirical work in this area will need.
Keywords agentic AI, observability, AIOps, root cause analysis, threat modeling, prompt injection, LLM security, retrieval-augmented generation, least privilege, autonomous remediation.
Field Engineering
Published In Volume 8, Issue 4, July-August 2026
Published On 2026-08-17
DOI https://doi.org/10.36948/ijfmr.2026.v08i04.85812

Share this