{
  "action_maps": [
    {
      "label": "apply_remediation",
      "mappings": [
        {
          "basis": "Honoring a change freeze is configuration change control.",
          "confidence": "asserted",
          "fw": "NIST SP 800-53r5",
          "id": "CM-3",
          "name": "Configuration Change Control",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "A freeze restricts who/when changes may be applied.",
          "confidence": "asserted",
          "fw": "NIST SP 800-53r5",
          "id": "CM-5",
          "name": "Access Restrictions for Change",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "Deploying during a freeze is acting beyond authority.",
          "confidence": "asserted",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "a destructive change during a freeze maps to data destruction",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1485",
          "name": "Data Destruction",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "asserted_table",
      "subject_id": "cap_apply_the_generated_gate_to_the_target_repo_under_change_control"
    },
    {
      "label": "generate_gate",
      "mappings": [
        {
          "basis": "Requiring an approved change request is the core of change control.",
          "confidence": "asserted",
          "fw": "NIST SP 800-53r5",
          "id": "CM-3",
          "name": "Configuration Change Control",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "An unapproved production change by an agent needs human sign-off.",
          "confidence": "asserted",
          "fw": "EU AI Act",
          "id": "Art 14",
          "name": "Human oversight",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "Deploying without approval is excessive agency.",
          "confidence": "asserted",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "an unapproved production change maps to system-process modification / persistence",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1543",
          "name": "Create or Modify System Process",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "asserted_table",
      "subject_id": "cap_generate_a_policy_gate_for_an_ungoverned_action"
    },
    {
      "label": "register_receipt",
      "mappings": [
        {
          "basis": "Blocking export to an out-of-scope endpoint is information-flow enforcement.",
          "confidence": "asserted",
          "fw": "NIST SP 800-53r5",
          "id": "AC-4",
          "name": "Information Flow Enforcement",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "Preventing data leaving the controlled boundary is boundary protection.",
          "confidence": "asserted",
          "fw": "NIST SP 800-53r5",
          "id": "SC-7",
          "name": "Boundary Protection",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "Uncontrolled egress of regulated data is a data-governance failure.",
          "confidence": "asserted",
          "fw": "EU AI Act",
          "id": "Art 10",
          "name": "Data and data governance",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "Egress of regulated records is sensitive-information disclosure.",
          "confidence": "asserted",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM02",
          "name": "Sensitive Information Disclosure",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "Data leaving to an external domain maps to the Exfiltration tactic; confirm the specific technique with an analyst.",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "TA0010",
          "name": "Exfiltration",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "uncontrolled egress of regulated data maps to exfiltration",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1048",
          "name": "Exfiltration Over Alternative Protocol",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "asserted_table",
      "subject_id": "cap_publish_the_signed_receipt_to_the_trust_ledger"
    },
    {
      "label": "rollout_org_policy",
      "mappings": [
        {
          "basis": "A high blast-radius change requires an impact analysis and an accountable approver.",
          "confidence": "asserted",
          "fw": "NIST SP 800-53r5",
          "id": "CM-4",
          "name": "Impact Analyses",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "A named approver distinct from the actor is separation of duties.",
          "confidence": "asserted",
          "fw": "NIST SP 800-53r5",
          "id": "AC-5",
          "name": "Separation of Duties",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "High-impact automated changes require a named human owner.",
          "confidence": "asserted",
          "fw": "EU AI Act",
          "id": "Art 14",
          "name": "Human oversight",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "a high blast-radius destructive change maps to inhibit-system-recovery",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1490",
          "name": "Inhibit System Recovery",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "asserted_table",
      "subject_id": "cap_roll_out_an_org_wide_governance_policy"
    },
    {
      "label": "scan_target",
      "mappings": [
        {
          "basis": "Refusing to handle data above a classification ceiling enforces the categorization of the resource.",
          "confidence": "asserted",
          "fw": "NIST SP 800-53r5",
          "id": "RA-2",
          "name": "Security Categorization",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "The ceiling governs the flow of classified information through the agent.",
          "confidence": "asserted",
          "fw": "NIST SP 800-53r5",
          "id": "AC-4",
          "name": "Information Flow Enforcement",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "Handling over-classified data is a data-governance violation.",
          "confidence": "asserted",
          "fw": "EU AI Act",
          "id": "Art 10",
          "name": "Data and data governance",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "Processing restricted data above ceiling risks sensitive-information disclosure.",
          "confidence": "asserted",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM02",
          "name": "Sensitive Information Disclosure",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "handling data above a classification ceiling maps to sensitive-data access",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1530",
          "name": "Data from Cloud Storage",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "asserted_table",
      "subject_id": "cap_scan_a_customer_agent_repository_ast_text_only_never_executed"
    },
    {
      "label": "approval_required",
      "mappings": [
        {
          "basis": "Requiring an approved change request is the core of change control.",
          "confidence": "asserted",
          "fw": "NIST SP 800-53r5",
          "id": "CM-3",
          "name": "Configuration Change Control",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "An unapproved production change by an agent needs human sign-off.",
          "confidence": "asserted",
          "fw": "EU AI Act",
          "id": "Art 14",
          "name": "Human oversight",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "Deploying without approval is excessive agency.",
          "confidence": "asserted",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "an unapproved production change maps to system-process modification / persistence",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1543",
          "name": "Create or Modify System Process",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "asserted_table",
      "subject_id": "gate_approval_required"
    },
    {
      "label": "change_freeze_active",
      "mappings": [
        {
          "basis": "Honoring a change freeze is configuration change control.",
          "confidence": "asserted",
          "fw": "NIST SP 800-53r5",
          "id": "CM-3",
          "name": "Configuration Change Control",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "A freeze restricts who/when changes may be applied.",
          "confidence": "asserted",
          "fw": "NIST SP 800-53r5",
          "id": "CM-5",
          "name": "Access Restrictions for Change",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "Deploying during a freeze is acting beyond authority.",
          "confidence": "asserted",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "a destructive change during a freeze maps to data destruction",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1485",
          "name": "Data Destruction",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "asserted_table",
      "subject_id": "gate_change_freeze_active"
    },
    {
      "label": "changes above the blast threshold escalate to a human",
      "mappings": [
        {
          "basis": "A transaction-value ceiling is an access-enforcement rule on what the agent is permitted to execute.",
          "confidence": "asserted",
          "fw": "NIST SP 800-53r5",
          "id": "AC-3",
          "name": "Access Enforcement",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "The agent is granted only the transaction authority it needs; amounts above the limit exceed that grant.",
          "confidence": "asserted",
          "fw": "NIST SP 800-53r5",
          "id": "AC-6",
          "name": "Least Privilege",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "Above-threshold value should escalate to a human rather than auto-execute.",
          "confidence": "asserted",
          "fw": "EU AI Act",
          "id": "Art 14",
          "name": "Human oversight",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "Unbounded transaction authority is excessive agency.",
          "confidence": "asserted",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "a transaction-value ceiling bounds valid-account authority",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1078",
          "name": "Valid Accounts",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "asserted_table",
      "subject_id": "gate_changes_above_the_blast_threshold_escalate_to_a_human"
    },
    {
      "label": "classification_above_ceiling",
      "mappings": [
        {
          "basis": "Refusing to handle data above a classification ceiling enforces the categorization of the resource.",
          "confidence": "asserted",
          "fw": "NIST SP 800-53r5",
          "id": "RA-2",
          "name": "Security Categorization",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "The ceiling governs the flow of classified information through the agent.",
          "confidence": "asserted",
          "fw": "NIST SP 800-53r5",
          "id": "AC-4",
          "name": "Information Flow Enforcement",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "Handling over-classified data is a data-governance violation.",
          "confidence": "asserted",
          "fw": "EU AI Act",
          "id": "Art 10",
          "name": "Data and data governance",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "Processing restricted data above ceiling risks sensitive-information disclosure.",
          "confidence": "asserted",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM02",
          "name": "Sensitive Information Disclosure",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "handling data above a classification ceiling maps to sensitive-data access",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1530",
          "name": "Data from Cloud Storage",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "asserted_table",
      "subject_id": "gate_classification_above_ceiling"
    },
    {
      "label": "allow",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "gate_cwn_agent_fde_allow"
    },
    {
      "label": "dual_control_required",
      "mappings": [
        {
          "basis": "Dual control is the textbook separation-of-duties control: no single actor (here, one agent) completes a sensitive transaction alone.",
          "confidence": "asserted",
          "fw": "NIST SP 800-53r5",
          "id": "AC-5",
          "name": "Separation of Duties",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "A high-value financial action by an automated system requires effective human oversight before it takes effect.",
          "confidence": "asserted",
          "fw": "EU AI Act",
          "id": "Art 14",
          "name": "Human oversight",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "An agent moving money without a second authorizer is the canonical excessive-agency failure.",
          "confidence": "asserted",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "Risk treatment: enforce a control commensurate with transaction risk.",
          "confidence": "advisory",
          "fw": "NIST AI RMF",
          "id": "MANAGE",
          "name": "Manage function",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "separation of duties mitigates valid-account / privilege abuse",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1078",
          "name": "Valid Accounts",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "asserted_table",
      "subject_id": "gate_dual_control_required"
    },
    {
      "label": "high_blast_needs_named_approver",
      "mappings": [
        {
          "basis": "A high blast-radius change requires an impact analysis and an accountable approver.",
          "confidence": "asserted",
          "fw": "NIST SP 800-53r5",
          "id": "CM-4",
          "name": "Impact Analyses",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "A named approver distinct from the actor is separation of duties.",
          "confidence": "asserted",
          "fw": "NIST SP 800-53r5",
          "id": "AC-5",
          "name": "Separation of Duties",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "High-impact automated changes require a named human owner.",
          "confidence": "asserted",
          "fw": "EU AI Act",
          "id": "Art 14",
          "name": "Human oversight",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "a high blast-radius destructive change maps to inhibit-system-recovery",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1490",
          "name": "Inhibit System Recovery",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "asserted_table",
      "subject_id": "gate_high_blast_needs_named_approver"
    },
    {
      "label": "human_review_required",
      "mappings": [
        {
          "basis": "An adverse automated decision affecting a person requires human oversight before it is issued.",
          "confidence": "asserted",
          "fw": "EU AI Act",
          "id": "Art 14",
          "name": "Human oversight",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "Issuing an adverse decision with no human in the loop is excessive agency.",
          "confidence": "asserted",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "Adverse outcomes are a measured risk requiring a treatment (human review).",
          "confidence": "advisory",
          "fw": "NIST AI RMF",
          "id": "MEASURE",
          "name": "Measure function",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "autonomous execution without oversight maps to command/scripting abuse",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "asserted_table",
      "subject_id": "gate_human_review_required"
    },
    {
      "label": "no single FDE both generates and certifies a remediation",
      "mappings": [
        {
          "basis": "Dual control is the textbook separation-of-duties control: no single actor (here, one agent) completes a sensitive transaction alone.",
          "confidence": "asserted",
          "fw": "NIST SP 800-53r5",
          "id": "AC-5",
          "name": "Separation of Duties",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "A high-value financial action by an automated system requires effective human oversight before it takes effect.",
          "confidence": "asserted",
          "fw": "EU AI Act",
          "id": "Art 14",
          "name": "Human oversight",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "An agent moving money without a second authorizer is the canonical excessive-agency failure.",
          "confidence": "asserted",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "Risk treatment: enforce a control commensurate with transaction risk.",
          "confidence": "advisory",
          "fw": "NIST AI RMF",
          "id": "MANAGE",
          "name": "Manage function",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "separation of duties mitigates valid-account / privilege abuse",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1078",
          "name": "Valid Accounts",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "asserted_table",
      "subject_id": "gate_no_single_fde_both_generates_and_certifies_a_remediation"
    },
    {
      "label": "out_of_scope_domain",
      "mappings": [
        {
          "basis": "Restricting the agent to in-scope resources is least privilege.",
          "confidence": "asserted",
          "fw": "NIST SP 800-53r5",
          "id": "AC-6",
          "name": "Least Privilege",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "Scope is enforced at access time.",
          "confidence": "asserted",
          "fw": "NIST SP 800-53r5",
          "id": "AC-3",
          "name": "Access Enforcement",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "Reaching outside authorized scope is excessive agency.",
          "confidence": "asserted",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "reaching outside authorized scope maps to account/privilege manipulation",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1098",
          "name": "Account Manipulation",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "asserted_table",
      "subject_id": "gate_out_of_scope_domain"
    },
    {
      "label": "over_threshold",
      "mappings": [
        {
          "basis": "A transaction-value ceiling is an access-enforcement rule on what the agent is permitted to execute.",
          "confidence": "asserted",
          "fw": "NIST SP 800-53r5",
          "id": "AC-3",
          "name": "Access Enforcement",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "The agent is granted only the transaction authority it needs; amounts above the limit exceed that grant.",
          "confidence": "asserted",
          "fw": "NIST SP 800-53r5",
          "id": "AC-6",
          "name": "Least Privilege",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "Above-threshold value should escalate to a human rather than auto-execute.",
          "confidence": "asserted",
          "fw": "EU AI Act",
          "id": "Art 14",
          "name": "Human oversight",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "Unbounded transaction authority is excessive agency.",
          "confidence": "asserted",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "a transaction-value ceiling bounds valid-account authority",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1078",
          "name": "Valid Accounts",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "asserted_table",
      "subject_id": "gate_over_threshold"
    },
    {
      "label": "regulated_egress_blocked",
      "mappings": [
        {
          "basis": "Blocking export to an out-of-scope endpoint is information-flow enforcement.",
          "confidence": "asserted",
          "fw": "NIST SP 800-53r5",
          "id": "AC-4",
          "name": "Information Flow Enforcement",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "Preventing data leaving the controlled boundary is boundary protection.",
          "confidence": "asserted",
          "fw": "NIST SP 800-53r5",
          "id": "SC-7",
          "name": "Boundary Protection",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "Uncontrolled egress of regulated data is a data-governance failure.",
          "confidence": "asserted",
          "fw": "EU AI Act",
          "id": "Art 10",
          "name": "Data and data governance",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "Egress of regulated records is sensitive-information disclosure.",
          "confidence": "asserted",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM02",
          "name": "Sensitive Information Disclosure",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "Data leaving to an external domain maps to the Exfiltration tactic; confirm the specific technique with an analyst.",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "TA0010",
          "name": "Exfiltration",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "uncontrolled egress of regulated data maps to exfiltration",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1048",
          "name": "Exfiltration Over Alternative Protocol",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "asserted_table",
      "subject_id": "gate_regulated_egress_blocked"
    },
    {
      "label": "the FDE stays within the signed engagement scope",
      "mappings": [
        {
          "basis": "Restricting the agent to in-scope resources is least privilege.",
          "confidence": "asserted",
          "fw": "NIST SP 800-53r5",
          "id": "AC-6",
          "name": "Least Privilege",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "Scope is enforced at access time.",
          "confidence": "asserted",
          "fw": "NIST SP 800-53r5",
          "id": "AC-3",
          "name": "Access Enforcement",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "Reaching outside authorized scope is excessive agency.",
          "confidence": "asserted",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "reaching outside authorized scope maps to account/privilege manipulation",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1098",
          "name": "Account Manipulation",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "asserted_table",
      "subject_id": "gate_the_fde_stays_within_the_signed_engagement_scope"
    }
  ],
  "edges": [
    {
      "dst": "gate_approval_required",
      "provenance": "EXTRACTED",
      "rel": "GATED_BY",
      "src": "agent_agent_fde"
    },
    {
      "dst": "gate_change_freeze_active",
      "provenance": "EXTRACTED",
      "rel": "GATED_BY",
      "src": "agent_agent_fde"
    },
    {
      "dst": "gate_changes_above_the_blast_threshold_escalate_to_a_human",
      "provenance": "EXTRACTED",
      "rel": "GATED_BY",
      "src": "agent_agent_fde"
    },
    {
      "dst": "gate_classification_above_ceiling",
      "provenance": "EXTRACTED",
      "rel": "GATED_BY",
      "src": "agent_agent_fde"
    },
    {
      "dst": "gate_cwn_agent_fde_allow",
      "provenance": "EXTRACTED",
      "rel": "GATED_BY",
      "src": "agent_agent_fde"
    },
    {
      "dst": "gate_dual_control_required",
      "provenance": "EXTRACTED",
      "rel": "GATED_BY",
      "src": "agent_agent_fde"
    },
    {
      "dst": "gate_high_blast_needs_named_approver",
      "provenance": "EXTRACTED",
      "rel": "GATED_BY",
      "src": "agent_agent_fde"
    },
    {
      "dst": "gate_human_review_required",
      "provenance": "EXTRACTED",
      "rel": "GATED_BY",
      "src": "agent_agent_fde"
    },
    {
      "dst": "gate_no_single_fde_both_generates_and_certifies_a_remediation",
      "provenance": "EXTRACTED",
      "rel": "GATED_BY",
      "src": "agent_agent_fde"
    },
    {
      "dst": "gate_out_of_scope_domain",
      "provenance": "EXTRACTED",
      "rel": "GATED_BY",
      "src": "agent_agent_fde"
    },
    {
      "dst": "gate_over_threshold",
      "provenance": "EXTRACTED",
      "rel": "GATED_BY",
      "src": "agent_agent_fde"
    },
    {
      "dst": "gate_regulated_egress_blocked",
      "provenance": "EXTRACTED",
      "rel": "GATED_BY",
      "src": "agent_agent_fde"
    },
    {
      "dst": "gate_the_fde_stays_within_the_signed_engagement_scope",
      "provenance": "EXTRACTED",
      "rel": "GATED_BY",
      "src": "agent_agent_fde"
    },
    {
      "dst": "cap_apply_the_generated_gate_to_the_target_repo_under_change_control",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_agent_fde"
    },
    {
      "dst": "cap_generate_a_policy_gate_for_an_ungoverned_action",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_agent_fde"
    },
    {
      "dst": "cap_publish_the_signed_receipt_to_the_trust_ledger",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_agent_fde"
    },
    {
      "dst": "cap_roll_out_an_org_wide_governance_policy",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_agent_fde"
    },
    {
      "dst": "cap_scan_a_customer_agent_repository_ast_text_only_never_executed",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_agent_fde"
    }
  ],
  "frameworks": [
    "EU AI Act",
    "NIST SP 800-53r5",
    "OWASP LLM Top 10 (2025)"
  ],
  "nodes": [
    {
      "id": "agent_agent_fde",
      "name": "agent_fde",
      "props": {
        "source_kind": "directory"
      },
      "provenance": "EXTRACTED",
      "type": "Agent"
    },
    {
      "id": "cap_apply_the_generated_gate_to_the_target_repo_under_change_control",
      "name": "apply the generated gate to the target repo under change control",
      "props": {
        "action": "apply_remediation",
        "reason": "change_freeze_active"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_generate_a_policy_gate_for_an_ungoverned_action",
      "name": "generate a policy gate for an ungoverned action",
      "props": {
        "action": "generate_gate",
        "reason": "approval_required"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_publish_the_signed_receipt_to_the_trust_ledger",
      "name": "publish the signed receipt to the trust ledger",
      "props": {
        "action": "register_receipt",
        "reason": "regulated_egress_blocked"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_roll_out_an_org_wide_governance_policy",
      "name": "roll out an org-wide governance policy",
      "props": {
        "action": "rollout_org_policy",
        "reason": "high_blast_needs_named_approver"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_scan_a_customer_agent_repository_ast_text_only_never_executed",
      "name": "scan a customer agent repository (AST/text only, never executed)",
      "props": {
        "action": "scan_target",
        "reason": "classification_above_ceiling"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "gate_approval_required",
      "name": "approval_required",
      "props": {
        "action": "approval_required",
        "reason": "approval_required"
      },
      "provenance": "EXTRACTED",
      "type": "Gate"
    },
    {
      "id": "gate_change_freeze_active",
      "name": "change_freeze_active",
      "props": {
        "action": "change_freeze_active",
        "reason": "change_freeze_active"
      },
      "provenance": "EXTRACTED",
      "type": "Gate"
    },
    {
      "id": "gate_changes_above_the_blast_threshold_escalate_to_a_human",
      "name": "changes above the blast threshold escalate to a human",
      "props": {
        "action": "changes above the blast threshold escalate to a human",
        "reason": "over_threshold"
      },
      "provenance": "EXTRACTED",
      "type": "Gate"
    },
    {
      "id": "gate_classification_above_ceiling",
      "name": "classification_above_ceiling",
      "props": {
        "action": "classification_above_ceiling",
        "reason": "classification_above_ceiling"
      },
      "provenance": "EXTRACTED",
      "type": "Gate"
    },
    {
      "id": "gate_cwn_agent_fde_allow",
      "name": "cwn.agent_fde.allow",
      "props": {
        "action": "allow"
      },
      "provenance": "EXTRACTED",
      "type": "Gate"
    },
    {
      "id": "gate_dual_control_required",
      "name": "dual_control_required",
      "props": {
        "action": "dual_control_required",
        "reason": "dual_control_required"
      },
      "provenance": "EXTRACTED",
      "type": "Gate"
    },
    {
      "id": "gate_high_blast_needs_named_approver",
      "name": "high_blast_needs_named_approver",
      "props": {
        "action": "high_blast_needs_named_approver",
        "reason": "high_blast_needs_named_approver"
      },
      "provenance": "EXTRACTED",
      "type": "Gate"
    },
    {
      "id": "gate_human_review_required",
      "name": "human_review_required",
      "props": {
        "action": "human_review_required",
        "reason": "human_review_required"
      },
      "provenance": "EXTRACTED",
      "type": "Gate"
    },
    {
      "id": "gate_no_single_fde_both_generates_and_certifies_a_remediation",
      "name": "no single FDE both generates and certifies a remediation",
      "props": {
        "action": "no single FDE both generates and certifies a remediation",
        "reason": "dual_control_required"
      },
      "provenance": "EXTRACTED",
      "type": "Gate"
    },
    {
      "id": "gate_out_of_scope_domain",
      "name": "out_of_scope_domain",
      "props": {
        "action": "out_of_scope_domain",
        "reason": "out_of_scope_domain"
      },
      "provenance": "EXTRACTED",
      "type": "Gate"
    },
    {
      "id": "gate_over_threshold",
      "name": "over_threshold",
      "props": {
        "action": "over_threshold",
        "reason": "over_threshold"
      },
      "provenance": "EXTRACTED",
      "type": "Gate"
    },
    {
      "id": "gate_regulated_egress_blocked",
      "name": "regulated_egress_blocked",
      "props": {
        "action": "regulated_egress_blocked",
        "reason": "regulated_egress_blocked"
      },
      "provenance": "EXTRACTED",
      "type": "Gate"
    },
    {
      "id": "gate_the_fde_stays_within_the_signed_engagement_scope",
      "name": "the FDE stays within the signed engagement scope",
      "props": {
        "action": "the FDE stays within the signed engagement scope",
        "reason": "out_of_scope_domain"
      },
      "provenance": "EXTRACTED",
      "type": "Gate"
    }
  ],
  "note": "Proposed CWN mappings, confidence-tagged. Confirm against the current published control text before relying on them for audit. Enterprise control ids are mapped at onboarding by your GRC team, never auto-asserted.",
  "source": "examples\\agent_fde",
  "source_kind": "directory"
}
