Govern (GV) · Approval gating
Approval gating at the Agent charter layer
advisory · Bypassable by language alone
Who is allowed to put this agent into the world, under what authority, accountable to what policy, with what retirement criteria?
What this cell does
Charter signed by owner, domain authority, and (Tier 3+) security review. Charter identifies approver of every subsequent scope change. Annual review cadence. Emergency revocation conditions specified.
Artifacts (1)
checks.yamlview on GitHub# ABOUTME: Machine-checkable definition of the Charter approval-gating / agent cell.
# ABOUTME: The audit prompts in this cell's README, expressed so a validator can score them.
cell:
id: approval-gating.in-agent
concern: approval-gating
layer: in-agent
authority: agent
document: agent-charter
owner: "Named human owner. Counter-signed by domain authority and, at Tier 3 and above, security review."
question: "Does the agent charter carry the required approval signatures, an annual review cadence, conditions for emergency revocation, and a clear identifier of the approver of every subsequent change?"
mappings:
csf: "GV.PO-02, GV.OV-01"
ai_rmf: "GOVERN 2.2, MANAGE 2.3"
iso42001: "A.9"
eu_ai_act: "Art. 14, Art. 26"
checks:
- id: GV-AG-A-01
description: "At least two approval signatures are recorded."
type: min_items
target: "approvals:2"
document: agent-charter
severity: blocking
evidence: "Separation of duties at the governance layer."
- id: GV-AG-A-02
description: "Every approval carries a signature reference, not just a name."
type: every_has_key
target: "approvals|approval_signature"
document: agent-charter
severity: blocking
evidence: "A commit SHA or a detached signature."
- id: GV-AG-A-03
description: "The next review date is in the future."
type: date_future
target: "next_review_due"
document: agent-charter
severity: blocking
evidence: "An overdue charter is an expired one."
- id: GV-AG-A-04
description: "Emergency revocation names an authority and a procedure."
type: required_field
target: "incident_revocation.procedure"
document: agent-charter
severity: blocking
evidence: "A runnable procedure, referenced by path."
Cell notes
Charter, Approval gating / Agent
Structural question. Does the agent charter carry the required approval signatures, an annual review cadence, conditions for emergency revocation, and a clear identifier of the approver of every subsequent change?
Owner. Named human owner. Counter-signed by domain authority and (Tier 3+) security review.
Template fragment
The approvals:, review_cadence:, next_review_due:, and incident_revocation: blocks of ../../templates/agent-charter.yaml:
approvals:
- approver_name: Steven Heckler
approver_role: Managing Director
approval_date: 2026-04-15
approval_signature: <PGP signature or commit SHA of approval PR>
- approver_name: Tapas Banerjee
approver_role: Security Review
approval_date: 2026-04-15
approval_signature: <PGP signature or commit SHA of approval PR>
review_cadence: quarterly
next_review_due: 2026-07-15
incident_revocation:
conditions:
- "Detected lethal-trifecta pattern in agent context"
- "Two or more Sentinels alerts at severity ERROR within 24h"
- "Owner judgment"
authority: owner_or_domain_lead
Audit prompts
- - For [agent X], are all required approvers signed? Are signatures verifiable (PGP, signed-commit SHA)?
- - When is the next review due? Has it been scheduled?
- - What conditions trigger emergency revocation? Has the runbook for emergency revocation been drilled?
Operational tie-in
- - The charter file lives under branch protection from
../../../controls/approval-gating/server-side/. Tampering with the charter is detected by../../../sentinels/approval-gating/server-side/audit-branch-protection.yml. - -
incident_revocationconditions feed the on-call's authority to invoke../../../interventions/identity/server-side/agent-revoke-serverwithout a second approval.
Common failure mode
Approval signatures become reflexive, alert fatigue at the governance layer. Tiered approval (more rigorous review for Tier 3+) is the same cure used in Covenants L2-C4.
Citation
NIST CSF 2.0 GV.RR-02; GV.OV-02, GV.OV-03 (oversight reviews; organization adjusts). NIST AI RMF GOVERN 4.1, MANAGE 4.1. ISO/IEC 42001 §A.4.2, §A.9 (performance evaluation). EU AI Act Art. 14, Art. 26.
Crosswalk
| NIST CSF 2 0 | GV.RR-02, GV.OV-02, GV.OV-03 |
|---|---|
| NIST AI RMF | GOVERN 4.1, MANAGE 4.1 |
| ISO IEC 42001 | §A.4.2, §A.9 |
| EU AI ACT | Art. 14, Art. 26 |
Cite this cell:
https://agenticcovenants.com/govern/approval-gating/in-agent/