Agentic Covenants

Identify (ID) · Authorization

Authorization at the Operator-declared layer

deterministic · Outside the model's reasoning

What agents exist, what they touch, what threats they face?

What this cell does

Operator records authorized scope in registry, linked to RBAC manifest paths and IAM policy ARNs.

Artifacts (1)

record.yamlview on GitHub
# ABOUTME: What the operator-declared layer records for the authorization concern, and which mismatch rules consume it.
# ABOUTME: Read by scripts/reconcile_inventory.py to compare the three layers against each other.

cell:
  id: authorization.client-side
  concern: authorization
  layer: client-side
  authority: operator-declared
  records: "The registry records the scope the agent was authorized to hold at charter approval."

fields:
  - authorization_runtime.rbac_role_ref
  - authorization_runtime.effective_scope_last_audited

feeds_rules:
  - scope_drift

Cell notes

Inventory, Authorization / Operator-declared

What this cell records. The operator's intent for what each agent is authorized to do, linked back to source manifests.

Fields

  • - rbac_role_ref, name of the source-of-truth Role committed under manifests/rbac/.
  • - iam_policy_arns[]
  • - mcp_servers_allowlist_ref, file path to the canonical mcp-allowlist.json.
  • - last_audited_at, when the operator last verified runtime matches intent.

Cross-layer

Should equal the agent charter's authorized_scope block. Should match discovered effective permissions. Either disagreement = audit.

Citation

NIST CSF 2.0 ID.AM-02, ID.AM-08. NIST AI RMF MAP 1.5, MAP 4.1.

Crosswalk

NIST CSF 2 0ID.AM-02, ID.AM-08
NIST AI RMFMAP 1.5, MAP 4.1
CSA MAESTROLayer 7