Agentic Covenants

Identify (ID) · Identity

Identity at the Operator-declared layer

deterministic · Outside the model's reasoning

What agents exist, what they touch, what threats they face?

What this cell does

Operator-maintained registry; agents.yaml in GitOps; ServiceNow CMDB; internal AI inventory tool. Owner-confirmed. Updated on charter signature.

Artifacts (1)

record.yamlview on GitHub
# ABOUTME: What the operator-declared layer records for the identity concern, and which mismatch rules consume it.
# ABOUTME: Read by scripts/reconcile_inventory.py to compare the three layers against each other.

cell:
  id: identity.client-side
  concern: identity
  layer: client-side
  authority: operator-declared
  records: "The human registry of record: who owns this agent, in which domain, under which charter."

fields:
  - agent_identifier
  - charter_ref
  - ownership.owner
  - ownership.domain

feeds_rules:
  - shadow_agent
  - ghost_agent
  - charter_integrity

Cell notes

Inventory, Identity / Operator-declared

What this cell records. The operator's intent: every agent the org has approved, by name, with owner, charter reference, and creation date.

Where it lives

A GitOps registry: agents/<agent-identifier>.yaml per agent, committed to a repo under branch protection (the same protection that controls/approval-gating/server-side/ applies). PR-reviewed changes only.

Reference tooling

This cell is paperwork, not code. The structure is the inventory/templates/inventory-record.yaml format.

Cross-layer cross-references

  • - Every entry here should match a self-declared registration (../in-agent/). Operator-declared but not self-declared = ghost agent.
  • - Every entry here should match a discovered identity (../server-side/). Operator-declared but not discovered = same ghost-agent state.
  • - A self-declared agent without an operator-declared entry = unauthorized agent. Investigate.

Common failure modes

  • - Spreadsheet drift: registry hand-edited, not PR-reviewed.
  • - Stale entries: agent retired, registry not updated.
  • - Missing fields: owner-email empty or generic ("ai-team@"), backup-owner empty. Fail PR review on missing-required-field.

Citation

NIST CSF 2.0 ID.AM-01, ID.AM-02, ID.AM-08. NIST AI RMF MAP 1.1, MAP 1.5. ISO/IEC 42001 §A.5. Singapore IMDA Agentic AI Framework (Jan 22, 2026).

Primary failure modes

Documented, not hypothetical. A control whose bypass is undocumented is worse than no control, because somebody trusted it.

  • spreadsheet drift (entries stale within months)
  • registry not GitOps; changes not PR-reviewed

Crosswalk

NIST CSF 2 0ID.AM-01, ID.AM-02, ID.AM-08
NIST AI RMFMAP 1.1, MAP 1.5
CSA MAESTROLayer 7
OTHERISO/IEC 42001 §A.5, Singapore IMDA Agentic AI Framework