Govern (GV) · Supply chain
Supply chain at the Domain charter layer
deterministic · Outside the model's reasoning
Who is allowed to put this agent into the world, under what authority, accountable to what policy, with what retirement criteria?
What this cell does
Inherits org-wide approved-model list, adds domain-specific restrictions (e.g., "no models that train on user data", "SOC 2 Type II vendors only"). Approves or denies MCP servers for the domain.
Cell notes
Charter, Supply chain / Domain
Structural question. Does the domain charter inherit the org's approved-models list, add domain-specific restrictions, and maintain its own MCP server approval list?
Owner. Domain authority.
Template fragment
§8 (Supply chain) of ../../templates/domain-charter.md.
Audit prompts
- - What domain-specific restrictions exist on top of the org allowlist?
- - Are MCP servers approved per-domain, with version + hash + date?
- - When did the domain last review its MCP allowlist?
Citation
NIST CSF 2.0 GV.SC-04, GV.SC-07. NIST AI RMF GOVERN 6.1, MAP 4.1. ISO/IEC 42001 §A.10. EU AI Act Art. 25.
Crosswalk
| NIST CSF 2 0 | GV.SC-04, GV.SC-07 |
|---|---|
| NIST AI RMF | GOVERN 6.1, MAP 4.1 |
| ISO IEC 42001 | §A.10 |
| EU AI ACT | Art. 25 |
Cite this cell:
https://agenticcovenants.com/govern/supply-chain/client-side/