Agentic Covenants

Identify (ID) · Supply chain

Supply chain at the Operator-declared layer

deterministic · Outside the model's reasoning

What agents exist, what they touch, what threats they face?

What this cell does

Operator records authorized-dependency manifest from agent charter. Linked to Covenants L2-C5 and L3-C5 allowlists. Version-controlled audit trail.

Artifacts (1)

record.yamlview on GitHub
# ABOUTME: What the operator-declared layer records for the supply-chain concern, and which mismatch rules consume it.
# ABOUTME: Read by scripts/reconcile_inventory.py to compare the three layers against each other.

cell:
  id: supply-chain.client-side
  concern: supply-chain
  layer: client-side
  authority: operator-declared
  records: "The registry holds the dependency set the charter approved, pinned by hash and digest."

fields:
  - dependencies_runtime.foundation_model
  - dependencies_runtime.mcp_servers
  - dependencies_runtime.pinned_at

feeds_rules:
  - dependency_drift

Cell notes

Inventory, Supply chain / Operator-declared

What this cell records. The authorized dependency manifest from the agent charter, version-controlled with audit trail.

Fields

Mirrors the dependencies: block of charter/templates/agent-charter.yaml. Linked to:

Common failure mode

Manifest is updated in Charter but allowlist hashes in Covenants L2-C5 are not regenerated. Charter and runtime drift. Fix: automation that derives the runtime allowlist from the charter file at deploy time.

Citation

NIST CSF 2.0 ID.AM-04, ID.RA-09. NIST AI RMF MAP 4.1. CSA MAESTRO Layer 1, Layer 7. NIST SP 800-218A.

Crosswalk

NIST CSF 2 0ID.AM-04, ID.RA-09
NIST AI RMFMAP 4.1
CSA MAESTROLayer 1, Layer 7
OTHERNIST SP 800-218A