Agentic Covenants

Govern (GV) · Supply chain

Supply chain at the Domain charter layer

deterministic · Outside the model's reasoning

Who is allowed to put this agent into the world, under what authority, accountable to what policy, with what retirement criteria?

What this cell does

Inherits org-wide approved-model list, adds domain-specific restrictions (e.g., "no models that train on user data", "SOC 2 Type II vendors only"). Approves or denies MCP servers for the domain.

Cell notes

Charter, Supply chain / Domain

Structural question. Does the domain charter inherit the org's approved-models list, add domain-specific restrictions, and maintain its own MCP server approval list?

Owner. Domain authority.

Template fragment

§8 (Supply chain) of ../../templates/domain-charter.md.

Audit prompts

  • - What domain-specific restrictions exist on top of the org allowlist?
  • - Are MCP servers approved per-domain, with version + hash + date?
  • - When did the domain last review its MCP allowlist?

Citation

NIST CSF 2.0 GV.SC-04, GV.SC-07. NIST AI RMF GOVERN 6.1, MAP 4.1. ISO/IEC 42001 §A.10. EU AI Act Art. 25.

Crosswalk

NIST CSF 2 0GV.SC-04, GV.SC-07
NIST AI RMFGOVERN 6.1, MAP 4.1
ISO IEC 42001§A.10
EU AI ACTArt. 25