Agentic Covenants

Agentic Charter Matrix

NIST CSF 2.0 · Govern (GV) · 5 concerns × 3 layers

Who is allowed to put this agent into the world, under what authority, accountable to what policy, with what retirement criteria?
ConcernAgent charteradvisoryDomain charterdeterministicOrganizational charterexternal
IdentityWho can authorize creation? Who is the named human owner accountable for this agent's actions?1 artifactNamed human owner accountable for the agent's actions. Backup owner identified. Identity claims tied to charter via registered agent identifier.1 artifactDomain leadership signs charter authorizing a class of agents. Names roles permitted to create agents and the escalation path.1 artifactAI Acceptable Use Policy names categories of agents allowed to exist. AI Governance Council holds authority to create new agent classes. Director of AI Workforce Transformation is the named …
AuthorizationWhat scope does the charter grant? Under what change-control process can scope be expanded?1 artifactSpecific authorized scope. Named tools, MCP servers, environments, max-blast-radius. Scope expansion requires re-signature.1 artifactPer-class scope, inherits org hard prohibitions, adds domain-specific restrictions.1 artifactAI Risk Appetite Statement defines hard prohibitions and change-control process for evolving scope policy.
Blast radiusWhat risk tier? What damage cap is acceptable? Under what conditions does the charter permit production access?1 artifactSpecific risk tier, specific damage cap (records-per-session, USD-per-day, forbidden ops), conditions for tier downgrade or retirement.1 artifactInherits tier taxonomy, defines which tiers the domain is authorized to operate, defines failure-mode reviews per tier.1 artifactOrg-wide risk tier taxonomy (1 read-only, 2 scoped writes, 3 destructive, 4 production-critical) with damage caps and matching control requirements.
Approval gatingWho must approve the charter itself? Who approves changes to it? Who approves retirement?1 artifactCharter signed by owner, domain authority, and (Tier 3+) security review. Charter identifies approver of every subsequent scope change. Annual review cadence. Emergency revocation conditions…1 artifactDomain authority approves charters within its domain. Multi-party signature for Tier 3+. Charter amendments require the same process as originals.1 artifactAI Governance Council approves new agent classes, ratifies risk-tier policy. Member roles named (CISO, Chief AI Officer, GC, Privacy, Domain Leads). Quorum and voting rules defined.
Supply chainWhat models, MCP servers, dependencies, base images is the charter allowed to use? Under what change-control?1 artifactSpecific dependencies declared. Named foundation model and version, named MCP servers (with hashes from Covenants L2-C5), named base images, named tool versions. Dependency changes require c…1 artifactInherits org-wide approved-model list, adds domain-specific restrictions (e.g., "no models that train on user data", "SOC 2 Type II vendors only"). Approves or denies MCP servers for the dom…1 artifactOrg-wide allowlist of approved foundation models. Org-wide policy on MCP server approval, third-party dependency approval, vendor risk assessment integrated with procurement.

Walk a row left to right and ask one question at each layer: if the agent decides to violate this concern, what stops it here? All three populated is defense in depth. Only the in-agent cell populated is an audit finding, because the model can be talked out of it.