Agentic Covenants

Govern (GV) · Blast radius

Blast radius at the Agent charter layer

advisory · Bypassable by language alone

Who is allowed to put this agent into the world, under what authority, accountable to what policy, with what retirement criteria?

What this cell does

Specific risk tier, specific damage cap (records-per-session, USD-per-day, forbidden ops), conditions for tier downgrade or retirement.

Artifacts (1)

checks.yamlview on GitHub
# ABOUTME: Machine-checkable definition of the Charter blast-radius / agent cell.
# ABOUTME: The audit prompts in this cell's README, expressed so a validator can score them.

cell:
  id: blast-radius.in-agent
  concern: blast-radius
  layer: in-agent
  authority: agent
  document: agent-charter
  owner: "Named human owner. Counter-signed by domain authority and, at Tier 3 and above, security review."
  question: "Does the agent charter declare a specific risk tier, a quantitative damage cap, and the conditions that trigger automatic tier downgrade or retirement?"

mappings:
  csf: "GV.RM-02, ID.RA-05"
  ai_rmf: "GOVERN 1.3, MAP 5.1"
  iso42001: "A.5"
  eu_ai_act: "Art. 9"

checks:
  - id: GV-BR-A-01
    description: "A risk tier from 1 to 4 is declared."
    type: enum
    target: "risk_tier:1,2,3,4"
    document: agent-charter
    severity: blocking
    evidence: "An integer tier."
  - id: GV-BR-A-02
    description: "At least one quantitative damage cap is set."
    type: min_items
    target: "damage_cap:1"
    document: agent-charter
    severity: blocking
    evidence: "A number with a unit."
  - id: GV-BR-A-03
    description: "Forbidden operations are enumerated."
    type: min_items
    target: "damage_cap.forbidden_operations:1"
    document: agent-charter
    severity: blocking
    evidence: "Named operations."
  - id: GV-BR-A-04
    description: "Retirement criteria are concrete enough to be evaluated without judgement."
    type: min_items
    target: "retirement_criteria:2"
    document: agent-charter
    severity: blocking
    evidence: "'When no longer needed' does not count; look for a threshold or a duration."

Cell notes

Charter, Blast radius / Agent

Structural question. Does the agent charter declare a specific risk tier, a quantitative damage cap, and the conditions that trigger automatic tier downgrade or retirement?

Owner. Named human owner. Counter-signed by domain authority and (Tier 3+) security review.

Template fragment

The risk_tier:, damage_cap:, and retirement_criteria: blocks of ../../templates/agent-charter.yaml:


risk_tier: 2

damage_cap:
  max_records_per_session: 100
  max_cloud_spend_per_day_usd: 50
  forbidden_operations:
    - prod_database_writes
    - secret_modifications

retirement_criteria:
  - "Owner departs and no backup-owner accepts handoff within 30 days"
  - "Sustained false-positive rate above 30% for 14 days"
  - "Sustained Sentinels-detected scope drift for 7 days"
  - "Foundation model deprecated by vendor"

Audit prompts

  • - For [agent X], is the declared tier consistent with the actual scope it operates? An agent that touches prod databases is not Tier 2.
  • - Are damage caps enforced at runtime (ResourceQuota, IAM tag-based limits, application-level limits)?
  • - Have any retirement criteria fired? When was the agent last evaluated against them?

Operational tie-in

  • - damage_cap.max_cloud_spend_per_day_usd → AWS Cost Anomaly Detection or per-tag budget alerts.
  • - damage_cap.max_records_per_session → application-level rate limit enforced by the agent's wrapper.
  • - damage_cap.forbidden_operations → server-side denylist in ../../../controls/authorization/server-side/aws-iam-scoped-policy.json and Kyverno policies.
  • - retirement_criteria is the input to a periodic review job that flags agents for retirement.

Citation

NIST CSF 2.0 GV.RM-01, GV.RM-02. NIST AI RMF GOVERN 1.3, MAP 5.1, MAP 5.2. ISO/IEC 42001 §A.6. EU AI Act Art. 9(2)(a)–(d).

Crosswalk

NIST CSF 2 0GV.RM-01, GV.RM-02
NIST AI RMFGOVERN 1.3, MAP 5.1, MAP 5.2
ISO IEC 42001§A.6
EU AI ACTArt. 9(2)(a), Art. 9(2)(b), Art. 9(2)(c), Art. 9(2)(d)