Agentic Charter Matrix
Who is allowed to put this agent into the world, under what authority, accountable to what policy, with what retirement criteria?
Filter
Layers, by what they can actually enforce
- Agent charter — advisory
What the agent's own charter declares. Scope it claims for itself.
- Domain charter — deterministic-when-invoked
The domain or team that operates the agent, and the policy they set.
- Organizational charter — deterministic-and-external
Authority above the operator. Organizational policy the operator cannot waive.
Showing 5 of 15.
Identity at Organizational charter
AI Acceptable Use Policy names categories of agents allowed to exist. AI Governance Council holds authority to create new agent classes. Director of AI Workforce Transformation is the named org-wide owner.
Authorization at Organizational charter
AI Risk Appetite Statement defines hard prohibitions and change-control process for evolving scope policy.
Blast radius at Organizational charter
Org-wide risk tier taxonomy (1 read-only, 2 scoped writes, 3 destructive, 4 production-critical) with damage caps and matching control requirements.
Approval gating at Organizational charter
AI Governance Council approves new agent classes, ratifies risk-tier policy. Member roles named (CISO, Chief AI Officer, GC, Privacy, Domain Leads). Quorum and voting rules defined.
Supply chain at Organizational charter
Org-wide allowlist of approved foundation models. Org-wide policy on MCP server approval, third-party dependency approval, vendor risk assessment integrated with procurement.