Agentic Covenants

Govern (GV) · Approval gating

Approval gating at the server side layer

external · Outside the agent entirely

Who is allowed to put this agent into the world, under what authority, accountable to what policy, with what retirement criteria?

What this cell does

AI Governance Council approves new agent classes, ratifies risk-tier policy. Member roles named (CISO, Chief AI Officer, GC, Privacy, Domain Leads). Quorum and voting rules defined.

Cell notes

Charter, Approval gating / Organizational

Structural question. Does the org have a named AI Governance Council with member roles, quorum, voting rules, and recorded minutes?

Owner. AI Governance Council itself; minutes ratified by the chair.

Template fragment

§4.1 (AI Governance Council) of ../../templates/organizational-policy.md.

Audit prompts

  • - Who are the Council members by role? Are the named individuals current?
  • - When did the Council last meet? Were minutes recorded? Where are they stored?
  • - What decisions has the Council made in the last 12 months? Voting record?

Common failure mode

Council named but never meets. Minutes never recorded. ISO/IEC 42001 conformity assessment fails on §A.4.

Citation

NIST CSF 2.0 GV.RR-01, GV.RR-02, GV.RR-03 (organizational leadership, roles, adequate resources). NIST AI RMF GOVERN 2.1, GOVERN 2.2 (accountability). ISO/IEC 42001 §A.4 (leadership), §A.5 (planning). EU AI Act Art. 17(1)(b), Art. 26.

Crosswalk

NIST CSF 2 0GV.RR-01, GV.RR-02, GV.RR-03
NIST AI RMFGOVERN 2.1, GOVERN 2.2
ISO IEC 42001§A.4, §A.5
EU AI ACTArt. 17(1)(b), Art. 26