Crosswalk

Every concern in this wiki, the dimension that owns it, the controls that answer it, the recurring process where those controls get checked, and the program-maturity level by which they should exist. This is the traceability table an examiner asks for, and it is generated from the pages rather than maintained by hand.

Regenerate with scripts/gen_crosswalk.py. The concern, dimension, control and gate columns are derived from front matter and links: a control appears against a concern if either page links to the other, so a missing row means a missing link, a defect to be fixed in the pages rather than in the table.

The level column is the exception and it is editorial. It reads the Day 1 / Day 2 / Day 3 ordering in sequencing onto the Crawl / Walk / Run scale the dimension hubs use, and it says by which level a control should exist at all, saying nothing about how good it needs to be. No framework supplies this mapping; it is an editorial judgment made here.

Two things sit outside the table. It says nothing about whether a control is working: that is what “how you’d know it’s working” on each control page is for. And a concern with few rows is not a well-covered concern; it is a concern with few linked controls, which for memory poisoning reflects a genuine shortage of controls in the field rather than an editing miss.

The table

ConcernDimensionControlGate where checkedLevel expected
Agent disclosure and AI-washingGovernanceAgent inventory and registryOffboarding agents and owners · Registry review cadenceCrawl
Agent sprawlTechnology platform · GovernanceAgent inventory and registryRegistry review cadence · Offboarding agents and ownersCrawl
Cost controlsWalk
Cross-session delayed detonationObservability · SecurityLogging and auditAgent incident response · EvalsCrawl
Kill switches and revocationRun
Runtime guardrails and policy enforcementRun
Data exfiltrationData · SecurityLogging and auditWhen to involve legal and compliance · Agent incident responseCrawl
Secrets managementCrawl
Data access governanceWalk
Egress controlWalk
Sandboxing and isolationRun
Supply-chain vettingRun
Emergent market abuseGovernance · Use casesRuntime guardrails and policy enforcementEvals · Supervisory review of agent outputRun
Memory and context poisoningData · SecurityLogging and auditAgent incident responseCrawl
Data access governanceWalk
Multi-agent cascadesObservability · SecurityLogging and auditAgent incident response · Promotion gatesCrawl
Kill switches and revocationRun
Runtime guardrails and policy enforcementRun
Oversight decayTeams & roles · GovernanceLogging and auditEvals · Registry review cadenceCrawl
Human approval gatesWalk
Runtime guardrails and policy enforcementRun
Privilege and identity abuseSecurityHuman approval gatesEvals · Offboarding agents and ownersWalk
Identity and access for agentsWalk
Kill switches and revocationRun
Runtime guardrails and policy enforcementRun
Prompt injection and goal hijackSecuritySecrets managementEvals · When to involve legal and complianceCrawl
Data access governanceWalk
Egress controlWalk
Runtime guardrails and policy enforcementRun
Sandboxing and isolationRun
Supply-chain vettingRun
Quality debt and orphaned appsTechnology platform · ProcessAgent inventory and registryOffboarding agents and owners · Promotion gatesCrawl
Secrets managementCrawl
Cost controlsWalk
Recordkeeping and compliance gapsGovernanceLogging and auditAgent incident responseCrawl
Data access governanceWalk
Regulatory exposureGovernanceAgent inventory and registryRisk-tier assignment · Exam readinessCrawl
Resource overload and runaway costTechnology platform · SecurityCost controlsEvals · Registry review cadenceWalk
Runtime guardrails and policy enforcementRun
Shadow agentsObservability · Governance · SecurityAgent inventory and registryOffboarding agents and owners · Promotion gatesCrawl
Secrets managementCrawl
Kill switches and revocationRun
Runtime guardrails and policy enforcementRun
Tool and supply-chain compromiseSecurity · VendorsAgent inventory and registryRegistry review cadence · When to involve legal and complianceCrawl
Supply-chain vettingRun
Unreliable output acting on your systemsAnalytics & evals · ProcessLogging and auditEvals · Agent incident responseCrawl
Human approval gatesWalk
Sandboxing and isolationRun