Skip to content

Agentic Covenants

Agentic Charter Matrix

Who is allowed to put this agent into the world, under what authority, accountable to what policy, with what retirement criteria?

Filter

Layers, by what they can actually enforce

  • Agent charteradvisory

    What the agent's own charter declares. Scope it claims for itself.

  • Domain charterdeterministic-when-invoked

    The domain or team that operates the agent, and the policy they set.

  • Organizational charterdeterministic-and-external

    Authority above the operator. Organizational policy the operator cannot waive.

Showing 5 of 15.

  • Identity at Agent charter

    Named human owner accountable for the agent's actions. Backup owner identified. Identity claims tied to charter via registered agent identifier.

  • Authorization at Agent charter

    Specific authorized scope. Named tools, MCP servers, environments, max-blast-radius. Scope expansion requires re-signature.

  • Blast radius at Agent charter

    Specific risk tier, specific damage cap (records-per-session, USD-per-day, forbidden ops), conditions for tier downgrade or retirement.

  • Approval gating at Agent charter

    Charter signed by owner, domain authority, and (Tier 3+) security review. Charter identifies approver of every subsequent scope change. Annual review cadence. Emergency revocation conditions specified.

  • Supply chain at Agent charter

    Specific dependencies declared. Named foundation model and version, named MCP servers (with hashes from Covenants L2-C5), named base images, named tool versions. Dependency changes require charter amendment.