Agentic Covenants

Govern (GV) · Supply chain

Supply chain at the Domain charter layer

deterministic · Outside the model's reasoning

Who is allowed to put this agent into the world, under what authority, accountable to what policy, with what retirement criteria?

What this cell does

Inherits org-wide approved-model list, adds domain-specific restrictions (e.g., "no models that train on user data", "SOC 2 Type II vendors only"). Approves or denies MCP servers for the domain.

Artifacts (1)

checks.yamlview on GitHub
# ABOUTME: Machine-checkable definition of the Charter supply-chain / domain cell.
# ABOUTME: The audit prompts in this cell's README, expressed so a validator can score them.

cell:
  id: supply-chain.client-side
  concern: supply-chain
  layer: client-side
  authority: domain
  document: domain-charter
  owner: "Domain authority."
  question: "Does the domain charter inherit the org's approved-models list, add domain-specific restrictions, and maintain its own MCP server approval list?"

mappings:
  csf: "GV.SC-04, GV.SC-07"
  ai_rmf: "GOVERN 6.1"
  iso42001: "A.10"
  eu_ai_act: "Art. 25"

checks:
  - id: GV-SC-D-01
    description: "The domain references the organisational approved-models list."
    type: required_field
    target: "supply_chain.inherits_models_from"
    document: domain-charter
    severity: blocking
    evidence: "A reference, so drift is visible."
  - id: GV-SC-D-02
    description: "The domain maintains its own MCP server approval list."
    type: field_present
    target: "supply_chain.approved_mcp_servers"
    document: domain-charter
    severity: blocking
    evidence: "An explicit list, empty by decision if that is the decision."

Cell notes

Charter, Supply chain / Domain

Structural question. Does the domain charter inherit the org's approved-models list, add domain-specific restrictions, and maintain its own MCP server approval list?

Owner. Domain authority.

Template fragment

§8 (Supply chain) of ../../templates/domain-charter.md.

Audit prompts

  • - What domain-specific restrictions exist on top of the org allowlist?
  • - Are MCP servers approved per-domain, with version + hash + date?
  • - When did the domain last review its MCP allowlist?

Citation

NIST CSF 2.0 GV.SC-04, GV.SC-07. NIST AI RMF GOVERN 6.1, MAP 4.1. ISO/IEC 42001 §A.10. EU AI Act Art. 25.

Crosswalk

NIST CSF 2 0GV.SC-04, GV.SC-07
NIST AI RMFGOVERN 6.1, MAP 4.1
ISO IEC 42001§A.10
EU AI ACTArt. 25