Govern (GV) · Supply chain
Supply chain at the Domain charter layer
deterministic · Outside the model's reasoning
Who is allowed to put this agent into the world, under what authority, accountable to what policy, with what retirement criteria?
What this cell does
Inherits org-wide approved-model list, adds domain-specific restrictions (e.g., "no models that train on user data", "SOC 2 Type II vendors only"). Approves or denies MCP servers for the domain.
Artifacts (1)
checks.yamlview on GitHub# ABOUTME: Machine-checkable definition of the Charter supply-chain / domain cell.
# ABOUTME: The audit prompts in this cell's README, expressed so a validator can score them.
cell:
id: supply-chain.client-side
concern: supply-chain
layer: client-side
authority: domain
document: domain-charter
owner: "Domain authority."
question: "Does the domain charter inherit the org's approved-models list, add domain-specific restrictions, and maintain its own MCP server approval list?"
mappings:
csf: "GV.SC-04, GV.SC-07"
ai_rmf: "GOVERN 6.1"
iso42001: "A.10"
eu_ai_act: "Art. 25"
checks:
- id: GV-SC-D-01
description: "The domain references the organisational approved-models list."
type: required_field
target: "supply_chain.inherits_models_from"
document: domain-charter
severity: blocking
evidence: "A reference, so drift is visible."
- id: GV-SC-D-02
description: "The domain maintains its own MCP server approval list."
type: field_present
target: "supply_chain.approved_mcp_servers"
document: domain-charter
severity: blocking
evidence: "An explicit list, empty by decision if that is the decision."
Cell notes
Charter, Supply chain / Domain
Structural question. Does the domain charter inherit the org's approved-models list, add domain-specific restrictions, and maintain its own MCP server approval list?
Owner. Domain authority.
Template fragment
§8 (Supply chain) of ../../templates/domain-charter.md.
Audit prompts
- - What domain-specific restrictions exist on top of the org allowlist?
- - Are MCP servers approved per-domain, with version + hash + date?
- - When did the domain last review its MCP allowlist?
Citation
NIST CSF 2.0 GV.SC-04, GV.SC-07. NIST AI RMF GOVERN 6.1, MAP 4.1. ISO/IEC 42001 §A.10. EU AI Act Art. 25.
Crosswalk
| NIST CSF 2 0 | GV.SC-04, GV.SC-07 |
|---|---|
| NIST AI RMF | GOVERN 6.1, MAP 4.1 |
| ISO IEC 42001 | §A.10 |
| EU AI ACT | Art. 25 |
Cite this cell:
https://agenticcovenants.com/govern/supply-chain/client-side/