CABIER Global Assurance · Reference architecture

    Agent Assurance Control Plane

    The agent surfaces already exist: identity, permissions, workforce, transaction assurance and runtime. What was missing was the connection between them, because an agent is not governed by any one of those things alone. It is governed by its identity, its objective, its authority, its reach and its delegation, read together.

    Agent, objective, authority, environment and action together produce governable agency. An action outside the envelope generates an evidence record and a recommended disposition. It does not trigger autonomous consequential execution.

    Reference architecture connecting existing surfaces. No duplicate agent registry, and no autonomous consequential execution is implied.

    Every agent as an institutional object

    Agent identity

    An agent without a resolvable identity cannot hold authority or be held to an envelope.

    Model and version

    Behaviour belongs to a version. Change the version and prior evidence is no longer current.

    Owner

    A named human owner, because accountability does not survive being assigned to a team.

    Purpose and objective

    What it exists to do, and what it is actually optimising for, which are not always the same.

    Parent and child agents

    Delegation is where authority quietly expands. The lineage has to be explicit.

    Tools and tool servers

    Every attached tool is an extension of reach, granted at a point in time.

    Credentials

    What it can authenticate as, and when that ability expires.

    Data and resources

    Classification and residency of everything inside its reach.

    Permissions

    The authority envelope, stated positively rather than inferred from absence of failure.

    Jurisdictions

    Where it operates, whose data it touches and which regimes therefore apply.

    Actions

    What it did, under which authority, with what effect.

    Changes

    Version, prompt, policy, tool, permission and data changes, each dated and attributable.

    Evidence

    The dated record that makes the position re-examinable.

    Assurance state

    The derived position, with its expiry and invalidating conditions.

    Termination status

    Whether it is live, suspended, contained or retired, and who decided.

    The agent lineage graph

    Expressed in the existing relationship graph, so delegation is traversable rather than documented.

    AgentModelVersionOwnerObjectiveAuthorityToolsCredentialsDataActionsChild agentsEvidenceAssurance state

    The agent control chain

    Eleven steps, each of which can be evidenced or found missing.

    Identity

    Established, current and resolvable to a named owner.

    Objective

    Recorded, because an unstated objective cannot be governed.

    Authority

    Granted by someone entitled to grant it, with a stated boundary.

    Capability

    What the model and its tools can actually do, not what the design intended.

    Access

    The data, systems and credentials inside reach at this moment.

    Delegation

    What it may pass to a child agent, and what it may never pass on.

    Action

    The consequential step, classified before it is taken.

    Observation

    What was seen, at what fidelity, and what the observation could not cover.

    Evidence

    A dated record sufficient for someone absent to re-examine the decision.

    Intervention

    The requirement placed on a person or system when the envelope is exceeded.

    Assurance

    The derived state, with the condition that would invalidate it.

    Agentic exposure in the resilience position

    This is an extension feeding the existing institutional resilience position. It is not a second score, and it does not replace the resilience foundation already in use.

    Model concentration

    How much institutional capability rests on a single model or family.

    Agent concentration

    How much consequential activity rests on a small number of agents.

    Cloud concentration

    Dependency on one hosting environment for continuity of assurance itself.

    Tool concentration

    A single tool or tool server on which many agents depend.

    Credential concentration

    One credential whose compromise or expiry stops a great deal.

    Agent dependency

    Agents that cannot function without another agent remaining correct.

    Sub-agent propagation

    How far an error or authority travels down a delegation chain.

    Recovery independence

    Whether recovery depends on the same provider that failed.

    Human override

    Whether a person can actually stop the activity, tested rather than asserted.

    Evidence freshness

    How much of the current position rests on evidence that has aged out.

    Scenario performance

    Behaviour under the severe but plausible conditions already modelled.

    Containment effectiveness

    Whether isolation holds when it is used in anger.

    Change velocity

    How quickly models, prompts, tools and permissions change relative to review capacity.

    Autonomy level

    How much consequence can occur before a person is involved.

    A delegation chain exceeding its envelope

    Deterministic and synthetic. Every entity is illustrative.

    Synthetic demonstrator · illustrative

    Agent lineage and control chain

    A reconciliation agent that delegates to a retrieval child agent

    Consequence class: Regulated
    1. 1. Identity and objective
    2. 2. Access and delegation
    3. 3. Action
    4. 4. Observation and evidence
    5. Assurance state

    Individually acceptable agents can produce an unacceptable joint outcome, which is a question about the environment rather than the model.

    Then ask the harder question