Engagement Setup
Every downstream finding specializes off the frame set here. Regulatory context drives the threat lens; the methodology pin guarantees the audit is reproducible and reconstructible under examination.
methodology pinned
signatory countersigned
A federal assistance agent and a logistics routing agent receive substantively different threat lenses, scoring weights, and evidence requirements from the same tool, because of the context selected here. The pinned methodology is recorded on every artifact, so an examiner asking "what was applied" gets a machine-readable answer.
Agent Graph Builder
The deployed architecture rendered as a typed node-and-edge graph, often the first time the client sees their own system as a structured map. It is the evidentiary foundation every later finding cites back to.
intermediate actions modeled
edges annotated
STRIDE Threat Analysis
Six threat dimensions applied per node and edge of the graph, including intermediate actions, not just endpoints. Every threat carries a consultant disposition and an evidence citation back to the M2 graph.
consultant-dispositioned
evidence-linked
| Dimension | Threat hypothesis (illustrative) | Disposition |
|---|---|---|
| Repudiation | The decision context (which rules and inputs produced a determination) is not captured in a non-repudiable log. | Confirmed |
| Elevation | A reasoning subagent holds direct write capability into the payment-authorization path without a capability boundary. | Confirmed |
| Tampering | The determination payload is mutable between reasoner output and the authorization step. | Confirmed |
| Spoofing | Identity asserted by the upstream provider is trusted at determination time without independent attestation. | Mitigate |
| Info Disclosure | Sensitive applicant data traverses an internal edge without documented encryption-in-transit attestation. | Mitigate |
| Denial of Service | No load bounding on the determination path; degraded behavior under volume is uncharacterized. | Accept |
Repudiation is the highest-leverage category for government deployments: non-repudiable decision-context logs are the single most common gap and the first thing an OIG examiner asks for.
FMEA Risk Prioritization
Each threat scored on Severity, Occurrence, and Detectability, with detectability assessed at the intermediate action level, which is exactly what monitoring dashboards miss. The resulting priority band drives remediation sequencing end to end.
five-band prioritization
drives M6 sequence
| Threat | Severity | Occurrence | Detectability | Priority band | Rank |
|---|---|---|---|---|---|
| Decision-context not logged (Repudiation) | High | High | High | Critical | 1 |
| Unbounded payment write (Elevation) | High | Med | High | Critical | 2 |
| Mutable determination payload (Tampering) | High | Med | Med | Major | 3 |
| Unattested upstream identity (Spoofing) | Med | Med | Med | Major | 4 |
| Unattested data-in-transit (Info Disclosure) | Med | Low | Med | Tolerable | 5 |
| Uncharacterized load behavior (DoS) | Low | Low | Low | Acceptable | 6 |
Bands shown qualitatively. The same risk signal that ranks threats here becomes the requirement priority in remediation and, in pipeline engagements, the sprint sequencing in the build phase. One audit signal, traceable from finding to shipped fix.
NIST AI RMF Maturity
Findings map to the four NIST AI RMF functions, with maturity scored at four evidence levels: nothing, asserted, documented, implemented, tested. The output is a scorecard procurement, legal, and IG audiences recognize without translation.
maturity 0–4
gap inventory
Measure is the weakest function, directly downstream of the unlogged decision context surfaced in STRIDE. Without a non-repudiable record of what produced each determination, the agent cannot demonstrate it measures its own behavior, and three other functions inherit that gap.
Govern lags because accountability for the autonomous payment-write path is not documented. These two functions are where the roadmap concentrates first.
Remediation Roadmap
A sequenced plan ordered by risk priority, not by ease. Each step names what it fixes and links back to the findings that justify it. Top-band remediations require senior counter-signature before the artifact can close.
finding-linked
counter-signed at gates
Audit Artifact
The deliverable. A trust-readiness verdict, a machine-readable record for downstream remediation tooling, and a signed artifact whose every layer can be reconstructed under examination.
custody-hashed
re-audit on change
The Individual Assistance Determination Agent is auditable and remediable, but not yet trust-ready for autonomous determination. Two Critical-band findings, unlogged decision context and an unbounded payment-write path, must close before any determination is authorized without a human checkpoint. The remediation roadmap, executed in order, is projected to lift the system from early to defensible maturity within one cycle.
88ae14d70b93ff215e6ac9d03a17e4b2
Deterministic over the canonical artifact contents. Two runs with identical inputs produce an identical hash, tamper-evident by construction.
{
"engagement": { "id": "[redacted]", "methodology_pin": "[redacted]" },
"verdict": "auditable; not yet trust-ready",
"graph": { /* typed nodes + edges */ },
"findings": [ /* dimension, disposition, priority band, evidence ref */ ],
"maturity": { /* govern, map, measure, manage */ },
"remediation": [ /* sequenced, finding-linked */ ],
"custody_hash": "a7f3c1d9…e4b2"
}
The PDF brief goes to the client. This record is the cross-pillar handoff. For Pipeline engagements it flows straight into SprintiQ Turbo so the build is sequenced by the same risk signal (next slide).
The before/after maturity delta is the proof point: the audit does not just rank risk, it produces a measurable lift once the roadmap is executed.
Closed Loop: Audit to Build to Re-Audit
For Pipeline engagements the M7 record is not just handed over. It feeds SprintiQ Turbo, the Build pillar, so the same risk signal that ranked the threats now sequences the remediation build. One continuous chain from finding to shipped fix, then a re-audit that proves the fix landed.
RPN-sequenced build
re-audit closes loop
Every audit delivers the M7 record. Pipeline clients have Turbo execute the remediation build and the re-audit confirms the lift. Audit-only clients take the same record to their own engineering team.