Agentic Covenants

Govern (GV) · Supply chain

Supply chain at the domain layer

·

Who is allowed to put this agent into the world, under what authority, accountable to what policy, with what retirement criteria?

What this cell does

Inherits org-wide approved-model list, adds domain-specific restrictions (e.g., "no models that train on user data", "SOC 2 Type II vendors only"). Approves or denies MCP servers for the domain.

Cell notes

Charter, Supply chain / Domain

Structural question. Does the domain charter inherit the org's approved-models list, add domain-specific restrictions, and maintain its own MCP server approval list?

Owner. Domain authority.

Template fragment

§8 (Supply chain) of ../../templates/domain-charter.md.

Audit prompts

  • - What domain-specific restrictions exist on top of the org allowlist?
  • - Are MCP servers approved per-domain, with version + hash + date?
  • - When did the domain last review its MCP allowlist?

Citation

NIST CSF 2.0 GV.SC-04, GV.SC-07. NIST AI RMF GOVERN 6.1, MAP 4.1. ISO/IEC 42001 §A.10. EU AI Act Art. 25.

Crosswalk

NIST CSF 2 0GV.SC-04, GV.SC-07
NIST AI RMFGOVERN 6.1, MAP 4.1
ISO IEC 42001§A.10
EU AI ACTArt. 25