Agentic Covenants

Identify (ID) · Blast radius

Blast radius at the Operator-declared layer

deterministic · Outside the model's reasoning

What agents exist, what they touch, what threats they face?

What this cell does

Operator records blast-radius profile per agent. Worst-case impact statement (revenue, customer, compliance).

Artifacts (1)

record.yamlview on GitHub
# ABOUTME: What the operator-declared layer records for the blast-radius concern, and which mismatch rules consume it.
# ABOUTME: Read by scripts/reconcile_inventory.py to compare the three layers against each other.

cell:
  id: blast-radius.client-side
  concern: blast-radius
  layer: client-side
  authority: operator-declared
  records: "The registry records the tier assigned at charter approval and the worst-case impact accepted."

fields:
  - risk_tier
  - blast_radius_profile.worst_case_impact
  - blast_radius_profile.data_classes

feeds_rules:
  - tier_drift

Cell notes

Inventory, Blast radius / Operator-declared

What this cell records. The operator's worst-case impact statement and theoretical blast envelope.

Fields

  • - environments[]
  • - data_classes[]
  • - worst_case_impact, quantitative or scoped statement (e.g., "Q4 revenue forecasting outage up to 4 hours" or "limited to internal CI/CD tooling").
  • - recovery_time_objective_hours
  • - recovery_point_objective_hours

Cross-layer

Drives Charter risk tier choice. Drives which Covenants cells are mandatory for this agent.

Common failure mode

Worst-case impact written as boilerplate ("low impact"). Vague impact statements cannot drive tiering. Force quantitative entries.

Citation

NIST CSF 2.0 ID.RA-01, ID.RA-04. NIST AI RMF MAP 5.1, MAP 5.2. CSA MAESTRO Layer 4, Layer 6. NIST AI 600-1 (GAI risks taxonomy). EU AI Act Art. 9(2).

Crosswalk

NIST CSF 2 0ID.RA-01, ID.RA-04
NIST AI RMFMAP 5.1, MAP 5.2
CSA MAESTROLayer 4, Layer 6
OTHERNIST AI 600-1 (GAI risks taxonomy), EU AI Act Art. 9(2)