Agentic Charter Matrix
Who is allowed to put this agent into the world, under what authority, accountable to what policy, with what retirement criteria?
Filter
Layers, by what they can actually enforce
- Agent charter — advisory
What the agent's own charter declares. Scope it claims for itself.
- Domain charter — deterministic-when-invoked
The domain or team that operates the agent, and the policy they set.
- Organizational charter — deterministic-and-external
Authority above the operator. Organizational policy the operator cannot waive.
Showing 15 of 15.
Identity at Organizational charter
AI Acceptable Use Policy names categories of agents allowed to exist. AI Governance Council holds authority to create new agent classes. Director of AI Workforce Transformation is the named org-wide owner.
Identity at Domain charter
Domain leadership signs charter authorizing a class of agents. Names roles permitted to create agents and the escalation path.
Identity at Agent charter
Named human owner accountable for the agent's actions. Backup owner identified. Identity claims tied to charter via registered agent identifier.
Authorization at Organizational charter
AI Risk Appetite Statement defines hard prohibitions and change-control process for evolving scope policy.
Authorization at Domain charter
Per-class scope, inherits org hard prohibitions, adds domain-specific restrictions.
Authorization at Agent charter
Specific authorized scope. Named tools, MCP servers, environments, max-blast-radius. Scope expansion requires re-signature.
Blast radius at Organizational charter
Org-wide risk tier taxonomy (1 read-only, 2 scoped writes, 3 destructive, 4 production-critical) with damage caps and matching control requirements.
Blast radius at Domain charter
Inherits tier taxonomy, defines which tiers the domain is authorized to operate, defines failure-mode reviews per tier.
Blast radius at Agent charter
Specific risk tier, specific damage cap (records-per-session, USD-per-day, forbidden ops), conditions for tier downgrade or retirement.
Approval gating at Organizational charter
AI Governance Council approves new agent classes, ratifies risk-tier policy. Member roles named (CISO, Chief AI Officer, GC, Privacy, Domain Leads). Quorum and voting rules defined.
Approval gating at Domain charter
Domain authority approves charters within its domain. Multi-party signature for Tier 3+. Charter amendments require the same process as originals.
Approval gating at Agent charter
Charter signed by owner, domain authority, and (Tier 3+) security review. Charter identifies approver of every subsequent scope change. Annual review cadence. Emergency revocation conditions specified.
Supply chain at Organizational charter
Org-wide allowlist of approved foundation models. Org-wide policy on MCP server approval, third-party dependency approval, vendor risk assessment integrated with procurement.
Supply chain at Domain charter
Inherits org-wide approved-model list, adds domain-specific restrictions (e.g., "no models that train on user data", "SOC 2 Type II vendors only"). Approves or denies MCP servers for the domain.
Supply chain at Agent charter
Specific dependencies declared. Named foundation model and version, named MCP servers (with hashes from Covenants L2-C5), named base images, named tool versions. Dependency changes require charter amendment.