The attacks that matter now are built to stay under every individual threshold — poisoning applied one increment at a time, prompt injection that nudges rather than commands, compromise distributed across agents so no one view ever sums. Loriqa's answer is not a lower threshold. It is correlation: continuously relating every signal from every agent, so relationships invisible in isolation become undeniable in combination.
Traditional monitoring watches for things that break. Stealth attacks break nothing.
Any fixed threshold teaches a patient attacker exactly how much room they have. Activity held at 90% of every limit trips no alarm — forever.
Poisoning an agent's memory or behavior a fraction at a time means every individual increment sits within normal variance. The trend is the attack — and a per-event view has no trend.
Compromise distributed across three agents produces three individually healthy pictures. If nothing reads across agents, the coordinated pattern literally has nowhere to appear.
Correlation is only as good as what feeds it. Loriqa correlates across four continuous streams — all drawn from the same tamper-evident record.
Every action by every agent, cryptographically recorded — including intent written before execution. The complete raw material: nothing is sampled, nothing is optional.
Every agent proves health at defined intervals with cryptographic identity verification. The live pulse of the fleet — timing, cadence, and identity, continuously.
A baseline established at agent spawn, with drift scored across tool-call distribution, memory write rate, token consumption, and external endpoints — the shape of normal, per agent.
A deterministic per-run score, computed from the record, of how controllable and responsive to oversight each agent proved itself to be. Declining corrigibility is a signal by itself.
A poisoning attempt built to unfold too slowly for any threshold — as the platform sees it. Three agents. Every individual signal within normal bounds.
Each trend, alone, was a green dashboard. Related, they were an attack in progress — found not by a louder alarm, but by the discipline of relating everything to everything, all the time.
There is no LLM in the scoring path. Baseline drift and corrigibility are computed deterministically from the record — the detection layer cannot be prompt-injected, persuaded, or poisoned by the same techniques it exists to catch. The principle that governs the platform's chain of command governs its senses too.
A correlated finding is escalated with its full evidential basis to the Security Response Authority — where containment begins autonomously, in milliseconds, before damage is done. And when the adversary engages, the platform doesn't just stop them — it studies them. That is another principle: Intelligence — learning from the adversary →