Agentic Charter Matrix
Who is allowed to put this agent into the world, under what authority, accountable to what policy, with what retirement criteria?
Filter
Layers, by what they can actually enforce
- Agent charter — advisory
What the agent's own charter declares. Scope it claims for itself.
- Domain charter — deterministic-when-invoked
The domain or team that operates the agent, and the policy they set.
- Organizational charter — deterministic-and-external
Authority above the operator. Organizational policy the operator cannot waive.
Showing 5 of 15.
Identity at Agent charter
Named human owner accountable for the agent's actions. Backup owner identified. Identity claims tied to charter via registered agent identifier.
Authorization at Agent charter
Specific authorized scope. Named tools, MCP servers, environments, max-blast-radius. Scope expansion requires re-signature.
Blast radius at Agent charter
Specific risk tier, specific damage cap (records-per-session, USD-per-day, forbidden ops), conditions for tier downgrade or retirement.
Approval gating at Agent charter
Charter signed by owner, domain authority, and (Tier 3+) security review. Charter identifies approver of every subsequent scope change. Annual review cadence. Emergency revocation conditions specified.
Supply chain at Agent charter
Specific dependencies declared. Named foundation model and version, named MCP servers (with hashes from Covenants L2-C5), named base images, named tool versions. Dependency changes require charter amendment.