Manifest-based trusted agent management in a trusted operating system
environment includes receiving a request to execute a process is received
and setting up a virtual memory space for the process. Additionally, a
manifest corresponding to the process is accessed, and which of a
plurality of binaries can be executed in the virtual memory space is
limited based on indicators, of the binaries, that are included in the
manifest.