Agent Dwell Time
Everybody reports that they disclosed. Nobody reports how long it ran. The industry has a scoreboard with no clock on it — and until there is one, “we detected it” and “we detected it four months later” are the same sentence.
The definition
Agent dwell time is the interval between an agent attempting an action that leaves its declared bound, and that attempt being observed by a control that is not the agent’s own environment.
The clock STARTS
At the attempt, not at the success. An attempt that fails is still the moment the agent left its declared behaviour, and a metric that only counts successes rewards being lucky.
The clock STOPS
At observation, not at remediation. A scoreboard that waits for a fix is measuring the responder’s week, not the control. How fast you cleaned up is a different metric and it belongs to a different team.
The witness must be out-of-band. If the environment reports on itself, the clock is being read by the party it is timing. That is not a measurement, it is a claim — and it is the failure this whole category was created by.
Three rules that keep it honest. One: the denominator travels with the number — dwell across how many agents, over what window. Two: an unobserved breakout is not dwell zero, it is dwell UNKNOWN, and unknown is reported as unknown. Three: the measuring control is named, so a reader can judge whether it could have seen the event at all.
Why the metric is fair, and why it is uncomfortable for everyone
It does not flatter us by construction — it flatters architecture, and it is perfectly capable of embarrassing us on a bad day.
Out-of-band
Detection happens at the moment of egress, so dwell collapses toward the decision itself.
In-band
Scores badly — not because it is weak, but because it never saw the event. It is inside the thing it is judging.
Post-hoc
Scores by whenever somebody happened to look. That is a staffing metric wearing a security badge.
Whoever defines the metric defines the ranking, and a ranking outlives every product cycle in a category. We would rather that definition be written in public, by someone willing to be measured by it, than settled quietly in a procurement document.
Our own position — scored first, and honestly
Two properties we can prove today, and one number we cannot yet publish. All three are stated, because a scoreboard that only shows its good rows is an advertisement.
PROVEN · For a kernel-bounded agent, dwell is not small — the event cannot occur. Egress does not complete. This was established differentially in production: every egress attempt denied under the bound and not under the baseline, with the control cases unaffected, so a call failing on its own arguments cannot masquerade as our control working.
PROVEN · For an observed agent, observation is synchronous with the attempt. The sensor sits IN the path of the action, not beside it: the action does not complete until the supervisor answers. There is no polling interval to hide in and no sweep to wait for.
NOT YET PUBLISHED · the empirical distribution. A property that holds by construction does not need a large sample. A DISTRIBUTION does. Our instrumented out-of-band record is currently two attestations — that is two data points, not a statistic, and we will not dress it up as one.
We will publish the distribution — median, p95 and the denominator — when the sample supports it, under this same definition, whatever it says.
This is the part most likely to be skipped by whoever publishes second. We are writing it into v1 on purpose: the credibility of a scoreboard is set entirely by what its author admits before anyone asks.
What this is not
- Not a ranking of other organisations. v1 contains no third-party figures at all. Deriving other people’s dwell from public disclosures would make us the party ranking our own prospects, and one wrong date would discredit the whole board.
- Not a published standard. This is our proposed metric, and it is marked as ours. It is not a clause from a standards body and we will never imply that it is.
- Not a breach predictor. Dwell time measures what already happened. It says nothing about what will.
Security FOR AI agents — not AI for security.
If you evaluate models, operate an agent estate, or write the standards this will be measured against — tell us where this definition is wrong. We would rather fix it now than defend it later.