Identify (ID) · Approval gating
Approval gating at the Discovered layer
external · Outside the agent entirely
What agents exist, what they touch, what threats they face?
What this cell does
Registry of charter files in source control. Last-modified, last-PR-merged. Cross-reference with self-declared and operator-declared.
Artifacts (1)
record.yamlview on GitHub# ABOUTME: What the discovered layer records for the approval-gating concern, and which mismatch rules consume it.
# ABOUTME: Read by scripts/reconcile_inventory.py to compare the three layers against each other.
cell:
id: approval-gating.server-side
concern: approval-gating
layer: server-side
authority: discovered
records: "Observed evidence that gates exist: branch protection state on the charter file, approval events."
fields:
- charter_ref
- last_charter_review
feeds_rules:
- charter_integrity
Cell notes
Inventory, Approval gating / Discovered
What this cell records. Independent verification that charter files actually exist and have been touched on cadence.
Sources
- -
git log charters/, last-modified dates per charter file. - - GitHub Pull Request API, last-PR-merged per charter file.
- - Cross-reference against operator-declared
next_review_dueand self-declaredlast_charter_review_date.
Cross-layer
- - charter file last modified before the operator-declared
last_owner_attestation= stale, attestation may have been ceremonial. - - self-declared
last_charter_review_dateafter the file was last modified = self-declared is reporting a review that didn't happen.
Citation
NIST CSF 2.0 ID.IM-01, ID.IM-03. NIST AI RMF GOVERN 1.5, MANAGE 4.1.
Crosswalk
| NIST CSF 2 0 | ID.IM-01, ID.IM-03 |
|---|---|
| NIST AI RMF | GOVERN 1.5, MANAGE 4.1 |
Cite this cell:
https://agenticcovenants.com/identify/approval-gating/server-side/