Agentic Covenants

Identify (ID) · Blast radius

Blast radius at the Self-declared layer

advisory · Bypassable by language alone

What agents exist, what they touch, what threats they face?

What this cell does

Agent reports declared risk tier, damage cap, forbidden operations from its charter. Reports current environment and data class access.

Artifacts (1)

record.yamlview on GitHub
# ABOUTME: What the self-declared layer records for the blast-radius concern, and which mismatch rules consume it.
# ABOUTME: Read by scripts/reconcile_inventory.py to compare the three layers against each other.

cell:
  id: blast-radius.in-agent
  concern: blast-radius
  layer: in-agent
  authority: self-declared
  records: "The agent reports the tier and environments it believes it operates under."

fields:
  - risk_tier
  - blast_radius_profile.environments

feeds_rules:
  - tier_drift

Cell notes

Inventory, Blast radius / Self-declared

What this cell records. What the agent says about its own scope of damage potential.

Fields

  • - risk_tier (1–4 from charter)
  • - damage_cap (records-per-session, USD-per-day, forbidden ops)
  • - current_environment (dev / staging / prod)
  • - current_data_class (public / internal / confidential / regulated)

Cross-layer

Should equal operator-declared. If self-declared current_environment > operator-declared environments = escalation event.

Citation

NIST CSF 2.0 ID.RA-01. NIST AI RMF MAP 5.1, MAP 5.2.

Crosswalk

NIST CSF 2 0ID.RA-01
NIST AI RMFMAP 5.1, MAP 5.2