Identify (ID) · Supply chain
Supply chain at the operator declared layer
·
What agents exist, what they touch, what threats they face?
What this cell does
Operator records authorized-dependency manifest from agent charter. Linked to Covenants L2-C5 and L3-C5 allowlists. Version-controlled audit trail.
Cell notes
Inventory, Supply chain / Operator-declared
What this cell records. The authorized dependency manifest from the agent charter, version-controlled with audit trail.
Fields
Mirrors the dependencies: block of charter/templates/agent-charter.yaml. Linked to:
- -
controls/supply-chain/client-side/mcp-allowlist.jsonfor runtime enforcement. - -
controls/supply-chain/server-side/kyverno-verify-image-signatures.yamlfor admission-time verification.
Common failure mode
Manifest is updated in Charter but allowlist hashes in Covenants L2-C5 are not regenerated. Charter and runtime drift. Fix: automation that derives the runtime allowlist from the charter file at deploy time.
Citation
NIST CSF 2.0 ID.AM-04, ID.RA-09. NIST AI RMF MAP 4.1. CSA MAESTRO Layer 1, Layer 7. NIST SP 800-218A.
Crosswalk
| NIST CSF 2 0 | ID.AM-04, ID.RA-09 |
|---|---|
| NIST AI RMF | MAP 4.1 |
| CSA MAESTRO | Layer 1, Layer 7 |
| OTHER | NIST SP 800-218A |
Cite this cell:
https://agenticcovenants.com/identify/supply-chain/operator-declared/