CABIER Global Assurance · Reference architecture
Agent Assurance Control Plane
The agent surfaces already exist: identity, permissions, workforce, transaction assurance and runtime. What was missing was the connection between them, because an agent is not governed by any one of those things alone. It is governed by its identity, its objective, its authority, its reach and its delegation, read together.
Agent, objective, authority, environment and action together produce governable agency. An action outside the envelope generates an evidence record and a recommended disposition. It does not trigger autonomous consequential execution.
Reference architecture connecting existing surfaces. No duplicate agent registry, and no autonomous consequential execution is implied.
The surfaces this connects
Connected, not replaced. Each remains the system of record for its own part of the position.
Agent Identity Registry
Identity, ownership, purpose, jurisdiction and authority envelope.
Agent Permission Fabric
Permissions, credentials, tools and data reach.
Agent Workforce
The operating population of agents and what each is for.
Agent Transaction Assurance
Consequential financial and transactional action.
AI Runtime Assurance
Observation, evaluation, control and intervention at runtime.
AI Control Plane
Model and version governance, routing and enterprise tool governance.
Every agent as an institutional object
Agent identity
An agent without a resolvable identity cannot hold authority or be held to an envelope.
Model and version
Behaviour belongs to a version. Change the version and prior evidence is no longer current.
Owner
A named human owner, because accountability does not survive being assigned to a team.
Purpose and objective
What it exists to do, and what it is actually optimising for, which are not always the same.
Parent and child agents
Delegation is where authority quietly expands. The lineage has to be explicit.
Tools and tool servers
Every attached tool is an extension of reach, granted at a point in time.
Credentials
What it can authenticate as, and when that ability expires.
Data and resources
Classification and residency of everything inside its reach.
Permissions
The authority envelope, stated positively rather than inferred from absence of failure.
Jurisdictions
Where it operates, whose data it touches and which regimes therefore apply.
Actions
What it did, under which authority, with what effect.
Changes
Version, prompt, policy, tool, permission and data changes, each dated and attributable.
Evidence
The dated record that makes the position re-examinable.
Assurance state
The derived position, with its expiry and invalidating conditions.
Termination status
Whether it is live, suspended, contained or retired, and who decided.
The agent lineage graph
Expressed in the existing relationship graph, so delegation is traversable rather than documented.
The agent control chain
Eleven steps, each of which can be evidenced or found missing.
Identity
Established, current and resolvable to a named owner.
Objective
Recorded, because an unstated objective cannot be governed.
Authority
Granted by someone entitled to grant it, with a stated boundary.
Capability
What the model and its tools can actually do, not what the design intended.
Access
The data, systems and credentials inside reach at this moment.
Delegation
What it may pass to a child agent, and what it may never pass on.
Action
The consequential step, classified before it is taken.
Observation
What was seen, at what fidelity, and what the observation could not cover.
Evidence
A dated record sufficient for someone absent to re-examine the decision.
Intervention
The requirement placed on a person or system when the envelope is exceeded.
Assurance
The derived state, with the condition that would invalidate it.
Agentic exposure in the resilience position
This is an extension feeding the existing institutional resilience position. It is not a second score, and it does not replace the resilience foundation already in use.
Model concentration
How much institutional capability rests on a single model or family.
Agent concentration
How much consequential activity rests on a small number of agents.
Cloud concentration
Dependency on one hosting environment for continuity of assurance itself.
Tool concentration
A single tool or tool server on which many agents depend.
Credential concentration
One credential whose compromise or expiry stops a great deal.
Agent dependency
Agents that cannot function without another agent remaining correct.
Sub-agent propagation
How far an error or authority travels down a delegation chain.
Recovery independence
Whether recovery depends on the same provider that failed.
Human override
Whether a person can actually stop the activity, tested rather than asserted.
Evidence freshness
How much of the current position rests on evidence that has aged out.
Scenario performance
Behaviour under the severe but plausible conditions already modelled.
Containment effectiveness
Whether isolation holds when it is used in anger.
Change velocity
How quickly models, prompts, tools and permissions change relative to review capacity.
Autonomy level
How much consequence can occur before a person is involved.
A delegation chain exceeding its envelope
Deterministic and synthetic. Every entity is illustrative.
Synthetic demonstrator · illustrative
Agent lineage and control chain
A reconciliation agent that delegates to a retrieval child agent
- 1. Identity and objective
- 2. Access and delegation
- 3. Action
- 4. Observation and evidence
- Assurance state
Individually acceptable agents can produce an unacceptable joint outcome, which is a question about the environment rather than the model.
Then ask the harder question