Agentic Covenants

Govern (GV) · Approval gating

Approval gating at the Domain charter layer

deterministic · Outside the model's reasoning

Who is allowed to put this agent into the world, under what authority, accountable to what policy, with what retirement criteria?

What this cell does

Domain authority approves charters within its domain. Multi-party signature for Tier 3+. Charter amendments require the same process as originals.

Artifacts (1)

checks.yamlview on GitHub
# ABOUTME: Machine-checkable definition of the Charter approval-gating / domain cell.
# ABOUTME: The audit prompts in this cell's README, expressed so a validator can score them.

cell:
  id: approval-gating.client-side
  concern: approval-gating
  layer: client-side
  authority: domain
  document: domain-charter
  owner: "Domain authority."
  question: "Does the domain charter define which approvers are required for new agent charters at each tier, and the process for charter amendments?"

mappings:
  csf: "GV.PO-02, GV.RR-02"
  ai_rmf: "GOVERN 2.2"
  iso42001: "A.9"
  eu_ai_act: "Art. 14"

checks:
  - id: GV-AG-D-01
    description: "Required approvers are defined per tier."
    type: required_field
    target: "approvals_required_by_tier"
    document: domain-charter
    severity: blocking
    evidence: "A mapping from tier to approver roles."
  - id: GV-AG-D-02
    description: "An amendment process is recorded."
    type: required_field
    target: "amendment_process"
    document: domain-charter
    severity: blocking
    evidence: "How a charter changes, and who signs the change."

Cell notes

Charter, Approval gating / Domain

Structural question. Does the domain charter define which approvers are required for new agent charters at each tier, and the process for charter amendments?

Owner. Domain authority.

Template fragment

§7 (Approval gating) of ../../templates/domain-charter.md:

TierApprovers
1Domain lead alone
2Domain lead + named senior engineer
3Domain lead + security review + risk review
4Domain lead + security review + risk review + named executive

Audit prompts

  • - For each Tier 3 / Tier 4 agent in this domain, are all required approvals present in the charter?
  • - When was the last charter amendment? Did it follow the same approval process as the original?

Citation

NIST CSF 2.0 GV.RR-02; GV.OV-02 (oversight reviews). NIST AI RMF GOVERN 4.1. ISO/IEC 42001 §A.4.2. EU AI Act Art. 17(1)(c).

Crosswalk

NIST CSF 2 0GV.RR-02, GV.OV-02
NIST AI RMFGOVERN 4.1
ISO IEC 42001§A.4.2
EU AI ACTArt. 17(1)(c)