{
  "action_maps": [
    {
      "label": "delete_dataset",
      "mappings": [
        {
          "basis": "inferred from action verb 'delete'; confirm against published text (asserted basis: Honoring a change freeze is configuration change control.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "CM-3",
          "name": "Configuration Change Control",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'delete'; confirm against published text (asserted basis: A freeze restricts who/when changes may be applied.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "CM-5",
          "name": "Access Restrictions for Change",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'delete'; confirm against published text (asserted basis: Deploying during a freeze is acting beyond authority.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "INFERRED"
        },
        {
          "basis": "a destructive change during a freeze maps to data destruction",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1485",
          "name": "Data Destruction",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "cap_delete_dataset"
    },
    {
      "label": "deploy a billing-service config change",
      "mappings": [
        {
          "basis": "inferred from action verb 'deploy'; confirm against published text (asserted basis: Requiring an approved change request is the core of change control.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "CM-3",
          "name": "Configuration Change Control",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'deploy'; confirm against published text (asserted basis: An unapproved production change by an agent needs human sign-off.)",
          "confidence": "inferred",
          "fw": "EU AI Act",
          "id": "Art 14",
          "name": "Human oversight",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'deploy'; confirm against published text (asserted basis: Deploying without approval is excessive agency.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "INFERRED"
        },
        {
          "basis": "an unapproved production change maps to system-process modification / persistence",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1543",
          "name": "Create or Modify System Process",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "cap_deploy_a_billing_service_config_change"
    },
    {
      "label": "Deploy API",
      "mappings": [
        {
          "basis": "inferred from action verb 'deploy'; confirm against published text (asserted basis: Requiring an approved change request is the core of change control.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "CM-3",
          "name": "Configuration Change Control",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'deploy'; confirm against published text (asserted basis: An unapproved production change by an agent needs human sign-off.)",
          "confidence": "inferred",
          "fw": "EU AI Act",
          "id": "Art 14",
          "name": "Human oversight",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'deploy'; confirm against published text (asserted basis: Deploying without approval is excessive agency.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "INFERRED"
        },
        {
          "basis": "an unapproved production change maps to system-process modification / persistence",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1543",
          "name": "Create or Modify System Process",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "cap_deploy_api"
    },
    {
      "label": "deploy_service",
      "mappings": [
        {
          "basis": "inferred from action verb 'deploy'; confirm against published text (asserted basis: Requiring an approved change request is the core of change control.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "CM-3",
          "name": "Configuration Change Control",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'deploy'; confirm against published text (asserted basis: An unapproved production change by an agent needs human sign-off.)",
          "confidence": "inferred",
          "fw": "EU AI Act",
          "id": "Art 14",
          "name": "Human oversight",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'deploy'; confirm against published text (asserted basis: Deploying without approval is excessive agency.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "INFERRED"
        },
        {
          "basis": "an unapproved production change maps to system-process modification / persistence",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1543",
          "name": "Create or Modify System Process",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "cap_deploy_service"
    },
    {
      "label": "export the reconciliation extract",
      "mappings": [
        {
          "basis": "inferred from action verb 'export'; confirm against published text (asserted basis: Blocking export to an out-of-scope endpoint is information-flow enforcement.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "AC-4",
          "name": "Information Flow Enforcement",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'export'; confirm against published text (asserted basis: Preventing data leaving the controlled boundary is boundary protection.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "SC-7",
          "name": "Boundary Protection",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'export'; confirm against published text (asserted basis: Uncontrolled egress of regulated data is a data-governance failure.)",
          "confidence": "inferred",
          "fw": "EU AI Act",
          "id": "Art 10",
          "name": "Data and data governance",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'export'; confirm against published text (asserted basis: Egress of regulated records is sensitive-information disclosure.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM02",
          "name": "Sensitive Information Disclosure",
          "provenance": "INFERRED"
        },
        {
          "basis": "Data leaving to an external domain maps to the Exfiltration tactic; confirm the specific technique with an analyst.",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "TA0010",
          "name": "Exfiltration",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "uncontrolled egress of regulated data maps to exfiltration",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1048",
          "name": "Exfiltration Over Alternative Protocol",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "cap_export_the_reconciliation_extract"
    },
    {
      "label": "Payments API",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_payments_api"
    },
    {
      "label": "deploy",
      "mappings": [
        {
          "basis": "inferred from action verb 'deploy'; confirm against published text (asserted basis: Requiring an approved change request is the core of change control.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "CM-3",
          "name": "Configuration Change Control",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'deploy'; confirm against published text (asserted basis: An unapproved production change by an agent needs human sign-off.)",
          "confidence": "inferred",
          "fw": "EU AI Act",
          "id": "Art 14",
          "name": "Human oversight",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'deploy'; confirm against published text (asserted basis: Deploying without approval is excessive agency.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "INFERRED"
        },
        {
          "basis": "an unapproved production change maps to system-process modification / persistence",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1543",
          "name": "Create or Modify System Process",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "cap_post_deploy_config"
    },
    {
      "label": "wire_transfer",
      "mappings": [
        {
          "basis": "inferred from action verb 'wire'; confirm against published text (asserted basis: Dual control is the textbook separation-of-duties control: no single actor (here, one agent) completes a sensitive transaction alone.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "AC-5",
          "name": "Separation of Duties",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'wire'; confirm against published text (asserted basis: A high-value financial action by an automated system requires effective human oversight before it takes effect.)",
          "confidence": "inferred",
          "fw": "EU AI Act",
          "id": "Art 14",
          "name": "Human oversight",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'wire'; confirm against published text (asserted basis: An agent moving money without a second authorizer is the canonical excessive-agency failure.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "INFERRED"
        },
        {
          "basis": "Risk treatment: enforce a control commensurate with transaction risk.",
          "confidence": "advisory",
          "fw": "NIST AI RMF",
          "id": "MANAGE",
          "name": "Manage function",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "separation of duties mitigates valid-account / privilege abuse",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1078",
          "name": "Valid Accounts",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "cap_post_payments_wire_transfer"
    },
    {
      "label": "export_records",
      "mappings": [
        {
          "basis": "inferred from action verb 'export'; confirm against published text (asserted basis: Blocking export to an out-of-scope endpoint is information-flow enforcement.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "AC-4",
          "name": "Information Flow Enforcement",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'export'; confirm against published text (asserted basis: Preventing data leaving the controlled boundary is boundary protection.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "SC-7",
          "name": "Boundary Protection",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'export'; confirm against published text (asserted basis: Uncontrolled egress of regulated data is a data-governance failure.)",
          "confidence": "inferred",
          "fw": "EU AI Act",
          "id": "Art 10",
          "name": "Data and data governance",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'export'; confirm against published text (asserted basis: Egress of regulated records is sensitive-information disclosure.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM02",
          "name": "Sensitive Information Disclosure",
          "provenance": "INFERRED"
        },
        {
          "basis": "Data leaving to an external domain maps to the Exfiltration tactic; confirm the specific technique with an analyst.",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "TA0010",
          "name": "Exfiltration",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "uncontrolled egress of regulated data maps to exfiltration",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1048",
          "name": "Exfiltration Over Alternative Protocol",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "cap_post_warehouse_export_records"
    },
    {
      "label": "read_status",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_read_status"
    },
    {
      "label": "Warehouse Export API",
      "mappings": [
        {
          "basis": "inferred from action verb 'export'; confirm against published text (asserted basis: Blocking export to an out-of-scope endpoint is information-flow enforcement.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "AC-4",
          "name": "Information Flow Enforcement",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'export'; confirm against published text (asserted basis: Preventing data leaving the controlled boundary is boundary protection.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "SC-7",
          "name": "Boundary Protection",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'export'; confirm against published text (asserted basis: Uncontrolled egress of regulated data is a data-governance failure.)",
          "confidence": "inferred",
          "fw": "EU AI Act",
          "id": "Art 10",
          "name": "Data and data governance",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'export'; confirm against published text (asserted basis: Egress of regulated records is sensitive-information disclosure.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM02",
          "name": "Sensitive Information Disclosure",
          "provenance": "INFERRED"
        },
        {
          "basis": "Data leaving to an external domain maps to the Exfiltration tactic; confirm the specific technique with an analyst.",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "TA0010",
          "name": "Exfiltration",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "uncontrolled egress of regulated data maps to exfiltration",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1048",
          "name": "Exfiltration Over Alternative Protocol",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "cap_warehouse_export_api"
    },
    {
      "label": "wire transfer to a beneficiary",
      "mappings": [
        {
          "basis": "inferred from action verb 'wire'; confirm against published text (asserted basis: Dual control is the textbook separation-of-duties control: no single actor (here, one agent) completes a sensitive transaction alone.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "AC-5",
          "name": "Separation of Duties",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'wire'; confirm against published text (asserted basis: A high-value financial action by an automated system requires effective human oversight before it takes effect.)",
          "confidence": "inferred",
          "fw": "EU AI Act",
          "id": "Art 14",
          "name": "Human oversight",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'wire'; confirm against published text (asserted basis: An agent moving money without a second authorizer is the canonical excessive-agency failure.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "INFERRED"
        },
        {
          "basis": "Risk treatment: enforce a control commensurate with transaction risk.",
          "confidence": "advisory",
          "fw": "NIST AI RMF",
          "id": "MANAGE",
          "name": "Manage function",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "separation of duties mitigates valid-account / privilege abuse",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1078",
          "name": "Valid Accounts",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "cap_wire_transfer_to_a_beneficiary"
    },
    {
      "label": "beneficiary_unverified",
      "mappings": [
        {
          "basis": "Paying only verified beneficiaries enforces who the agent may transact with.",
          "confidence": "asserted",
          "fw": "NIST SP 800-53r5",
          "id": "AC-3",
          "name": "Access Enforcement",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "Acting on unverified counterparty data is a data-governance failure.",
          "confidence": "asserted",
          "fw": "EU AI Act",
          "id": "Art 10",
          "name": "Data and data governance",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "Sending funds to an unverified party is acting beyond safe authority.",
          "confidence": "asserted",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "acting on behalf of an unverified party is valid-account abuse",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1078",
          "name": "Valid Accounts",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "asserted_table",
      "subject_id": "gate_beneficiary_unverified"
    },
    {
      "label": "dual_control_required",
      "mappings": [
        {
          "basis": "Dual control is the textbook separation-of-duties control: no single actor (here, one agent) completes a sensitive transaction alone.",
          "confidence": "asserted",
          "fw": "NIST SP 800-53r5",
          "id": "AC-5",
          "name": "Separation of Duties",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "A high-value financial action by an automated system requires effective human oversight before it takes effect.",
          "confidence": "asserted",
          "fw": "EU AI Act",
          "id": "Art 14",
          "name": "Human oversight",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "An agent moving money without a second authorizer is the canonical excessive-agency failure.",
          "confidence": "asserted",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "Risk treatment: enforce a control commensurate with transaction risk.",
          "confidence": "advisory",
          "fw": "NIST AI RMF",
          "id": "MANAGE",
          "name": "Manage function",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "separation of duties mitigates valid-account / privilege abuse",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1078",
          "name": "Valid Accounts",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "asserted_table",
      "subject_id": "gate_dual_control_required"
    },
    {
      "label": "over_threshold",
      "mappings": [
        {
          "basis": "A transaction-value ceiling is an access-enforcement rule on what the agent is permitted to execute.",
          "confidence": "asserted",
          "fw": "NIST SP 800-53r5",
          "id": "AC-3",
          "name": "Access Enforcement",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "The agent is granted only the transaction authority it needs; amounts above the limit exceed that grant.",
          "confidence": "asserted",
          "fw": "NIST SP 800-53r5",
          "id": "AC-6",
          "name": "Least Privilege",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "Above-threshold value should escalate to a human rather than auto-execute.",
          "confidence": "asserted",
          "fw": "EU AI Act",
          "id": "Art 14",
          "name": "Human oversight",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "Unbounded transaction authority is excessive agency.",
          "confidence": "asserted",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "a transaction-value ceiling bounds valid-account authority",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1078",
          "name": "Valid Accounts",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "asserted_table",
      "subject_id": "gate_over_threshold"
    },
    {
      "label": "allow",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "gate_sample_agent_firewall_payments_allow"
    }
  ],
  "edges": [
    {
      "dst": "op_post_deploy_config",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_sample_agent"
    },
    {
      "dst": "op_post_payments_wire_transfer",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_sample_agent"
    },
    {
      "dst": "op_post_warehouse_export_records",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_sample_agent"
    },
    {
      "dst": "gate_beneficiary_unverified",
      "provenance": "EXTRACTED",
      "rel": "GATED_BY",
      "src": "agent_sample_agent"
    },
    {
      "dst": "gate_dual_control_required",
      "provenance": "EXTRACTED",
      "rel": "GATED_BY",
      "src": "agent_sample_agent"
    },
    {
      "dst": "gate_over_threshold",
      "provenance": "EXTRACTED",
      "rel": "GATED_BY",
      "src": "agent_sample_agent"
    },
    {
      "dst": "gate_sample_agent_firewall_payments_allow",
      "provenance": "EXTRACTED",
      "rel": "GATED_BY",
      "src": "agent_sample_agent"
    },
    {
      "dst": "cap_delete_dataset",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_sample_agent"
    },
    {
      "dst": "cap_deploy_a_billing_service_config_change",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_sample_agent"
    },
    {
      "dst": "cap_deploy_api",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_sample_agent"
    },
    {
      "dst": "cap_deploy_service",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_sample_agent"
    },
    {
      "dst": "cap_export_the_reconciliation_extract",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_sample_agent"
    },
    {
      "dst": "cap_payments_api",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_sample_agent"
    },
    {
      "dst": "cap_post_deploy_config",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_sample_agent"
    },
    {
      "dst": "cap_post_payments_wire_transfer",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_sample_agent"
    },
    {
      "dst": "cap_post_warehouse_export_records",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_sample_agent"
    },
    {
      "dst": "cap_read_status",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_sample_agent"
    },
    {
      "dst": "cap_warehouse_export_api",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_sample_agent"
    },
    {
      "dst": "cap_wire_transfer_to_a_beneficiary",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_sample_agent"
    }
  ],
  "frameworks": [
    "EU AI Act",
    "NIST SP 800-53r5",
    "OWASP LLM Top 10 (2025)"
  ],
  "nodes": [
    {
      "id": "agent_sample_agent",
      "name": "sample_agent",
      "props": {
        "source_kind": "directory"
      },
      "provenance": "EXTRACTED",
      "type": "Agent"
    },
    {
      "id": "cap_delete_dataset",
      "name": "delete_dataset",
      "props": {
        "action": "delete_dataset"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_deploy_a_billing_service_config_change",
      "name": "deploy a billing-service config change",
      "props": {
        "action": "deploy a billing-service config change"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_deploy_api",
      "name": "Deploy API",
      "props": {
        "action": "Deploy API"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_deploy_service",
      "name": "deploy_service",
      "props": {
        "action": "deploy_service"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_export_the_reconciliation_extract",
      "name": "export the reconciliation extract",
      "props": {
        "action": "export the reconciliation extract"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_payments_api",
      "name": "Payments API",
      "props": {
        "action": "Payments API"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_post_deploy_config",
      "name": "deploy",
      "props": {
        "action": "deploy"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_post_payments_wire_transfer",
      "name": "wire_transfer",
      "props": {
        "action": "wire_transfer"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_post_warehouse_export_records",
      "name": "export_records",
      "props": {
        "action": "export_records"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_read_status",
      "name": "read_status",
      "props": {
        "action": "read_status"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_warehouse_export_api",
      "name": "Warehouse Export API",
      "props": {
        "action": "Warehouse Export API"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_wire_transfer_to_a_beneficiary",
      "name": "wire transfer to a beneficiary",
      "props": {
        "action": "wire transfer to a beneficiary"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "gate_beneficiary_unverified",
      "name": "beneficiary_unverified",
      "props": {
        "action": "beneficiary_unverified",
        "reason": "beneficiary_unverified"
      },
      "provenance": "EXTRACTED",
      "type": "Gate"
    },
    {
      "id": "gate_dual_control_required",
      "name": "dual_control_required",
      "props": {
        "action": "dual_control_required",
        "reason": "dual_control_required"
      },
      "provenance": "EXTRACTED",
      "type": "Gate"
    },
    {
      "id": "gate_over_threshold",
      "name": "over_threshold",
      "props": {
        "action": "over_threshold",
        "reason": "over_threshold"
      },
      "provenance": "EXTRACTED",
      "type": "Gate"
    },
    {
      "id": "gate_sample_agent_firewall_payments_allow",
      "name": "sample.agent_firewall.payments.allow",
      "props": {
        "action": "allow"
      },
      "provenance": "EXTRACTED",
      "type": "Gate"
    },
    {
      "id": "op_post_deploy_config",
      "name": "deploy",
      "props": {
        "action": "deploy"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "op_post_payments_wire_transfer",
      "name": "wire_transfer",
      "props": {
        "action": "wire_transfer"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "op_post_warehouse_export_records",
      "name": "export_records",
      "props": {
        "action": "export_records"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    }
  ],
  "note": "Proposed CWN mappings, confidence-tagged. Confirm against the current published control text before relying on them for audit. Enterprise control ids are mapped at onboarding by your GRC team, never auto-asserted.",
  "source": "examples\\sample_agent",
  "source_kind": "directory"
}
