SprintiQ Agent Trust Audit · Built for the audit, not the demo
methodology pinned engagement DEMO-0001 M1 · Setup
M1

Engagement Setup

Every downstream finding specializes off the frame set here. Regulatory context drives the threat lens; the methodology pin guarantees the audit is reproducible and reconstructible under examination.

◆ SOW parsed by proprietary extraction engine
scope confirmed
methodology pinned
signatory countersigned
Subject System
SystemIndividual Assistance Determination Agent
PurposeIntake → determination → payment routing
DeploymentFedRAMP Moderate (GovCloud)
Criticality tierFinancial / Regulatory
Population affectedDisaster-assistance applicants
Audit Frame
Regulatory contextFederal · Civilian
Engagement typeFull audit
MethodologyPinned (immutable)
Conflict-of-interest screenCleared
SOW parsed & confirmedYes
Why this matters

A federal assistance agent and a logistics routing agent receive substantively different threat lenses, scoring weights, and evidence requirements from the same tool, because of the context selected here. The pinned methodology is recorded on every artifact, so an examiner asking "what was applied" gets a machine-readable answer.

M2

Agent Graph Builder

The deployed architecture rendered as a typed node-and-edge graph, often the first time the client sees their own system as a structured map. It is the evidentiary foundation every later finding cites back to.

◆ Node-type proposals from proprietary discovery engine
6 node types
intermediate actions modeled
edges annotated
Identity ProviderEXTERNAL SYSTEM Determination OrchestratorORCHESTRATOR Document Intake ClassifierSUBAGENT Determination ReasonerSUBAGENT Fraud ScreenerSUBAGENT Assistance Rules CorpusDATA SOURCE Payment AuthorizationTOOL Caseworker ReviewHUMAN CHECKPOINT
Orchestrator Subagent Tool Data Source External System Human Checkpoint Dashed = human-in-the-loop confirmation
M3

STRIDE Threat Analysis

Six threat dimensions applied per node and edge of the graph, including intermediate actions, not just endpoints. Every threat carries a consultant disposition and an evidence citation back to the M2 graph.

◆ Hypotheses from proprietary reasoning engine ◆ Retrieval over proprietary threat library (RAG)
applied per node & edge
consultant-dispositioned
evidence-linked
DimensionThreat hypothesis (illustrative)Disposition
RepudiationThe decision context (which rules and inputs produced a determination) is not captured in a non-repudiable log.Confirmed
ElevationA reasoning subagent holds direct write capability into the payment-authorization path without a capability boundary.Confirmed
TamperingThe determination payload is mutable between reasoner output and the authorization step.Confirmed
SpoofingIdentity asserted by the upstream provider is trusted at determination time without independent attestation.Mitigate
Info DisclosureSensitive applicant data traverses an internal edge without documented encryption-in-transit attestation.Mitigate
Denial of ServiceNo load bounding on the determination path; degraded behavior under volume is uncharacterized.Accept

Repudiation is the highest-leverage category for government deployments: non-repudiable decision-context logs are the single most common gap and the first thing an OIG examiner asks for.

M4

FMEA Risk Prioritization

Each threat scored on Severity, Occurrence, and Detectability, with detectability assessed at the intermediate action level, which is exactly what monitoring dashboards miss. The resulting priority band drives remediation sequencing end to end.

Severity × Occurrence × Detectability
five-band prioritization
drives M6 sequence
ThreatSeverityOccurrenceDetectabilityPriority bandRank
Decision-context not logged (Repudiation)HighHighHighCritical1
Unbounded payment write (Elevation)HighMedHighCritical2
Mutable determination payload (Tampering)HighMedMedMajor3
Unattested upstream identity (Spoofing)MedMedMedMajor4
Unattested data-in-transit (Info Disclosure)MedLowMedTolerable5
Uncharacterized load behavior (DoS)LowLowLowAcceptable6

Bands shown qualitatively. The same risk signal that ranks threats here becomes the requirement priority in remediation and, in pipeline engagements, the sprint sequencing in the build phase. One audit signal, traceable from finding to shipped fix.

M5

NIST AI RMF Maturity

Findings map to the four NIST AI RMF functions, with maturity scored at four evidence levels: nothing, asserted, documented, implemented, tested. The output is a scorecard procurement, legal, and IG audiences recognize without translation.

◆ Mapping from proprietary reasoning engine ◆ Retrieval over proprietary regulatory corpus (RAG)
Govern · Map · Measure · Manage
maturity 0–4
gap inventory
Maturity Scorecard
GovernAsserted4 gaps
MapDocumented2 gaps
MeasureAsserted5 gaps
ManageDocumented3 gaps
Read of the scorecard

Measure is the weakest function, directly downstream of the unlogged decision context surfaced in STRIDE. Without a non-repudiable record of what produced each determination, the agent cannot demonstrate it measures its own behavior, and three other functions inherit that gap.

Govern lags because accountability for the autonomous payment-write path is not documented. These two functions are where the roadmap concentrates first.

Cross-framework reuseISO 42001 · 800-53 · EU AI Act
Federal evidence shapeOSCAL-ready
M6

Remediation Roadmap

A sequenced plan ordered by risk priority, not by ease. Each step names what it fixes and links back to the findings that justify it. Top-band remediations require senior counter-signature before the artifact can close.

risk-priority ordered
finding-linked
counter-signed at gates
1
Establish non-repudiable decision logging
Capture decision context (inputs, rules applied, and outcome) in an immutable, hash-anchored record for every determination.
addresses Repudiation (Critical) · lifts Measure
2
Bound confidence; require human checkpoint
Route low-confidence and high-value determinations through the caseworker checkpoint rather than auto-authorizing.
addresses autonomous-determination risk · lifts Manage
3
Bound subagent capability
Remove direct payment-authorization write from the reasoner; route through an explicit authorization gate with its own controls.
addresses Elevation (Critical) · lifts Govern
4
Attest data provenance on internal edges
Document classification and encryption-in-transit on edges carrying sensitive applicant data; lock the determination payload after reasoner output.
addresses Info Disclosure · Tampering
M7

Audit Artifact

The deliverable. A trust-readiness verdict, a machine-readable record for downstream remediation tooling, and a signed artifact whose every layer can be reconstructed under examination.

◆ Verdict synthesized by proprietary reasoning engine
verdict → export → sign
custody-hashed
re-audit on change
Trust-readiness verdict

The Individual Assistance Determination Agent is auditable and remediable, but not yet trust-ready for autonomous determination. Two Critical-band findings, unlogged decision context and an unbounded payment-write path, must close before any determination is authorized without a human checkpoint. The remediation roadmap, executed in order, is projected to lift the system from early to defensible maturity within one cycle.

Why this artifact holds up
Methodology version pinned on the artifact
Hash-chained immutable audit log
Every finding cited to graph evidence
Senior counter-signature at each gate
Reproducible: same inputs, same output
Re-audit branches; nothing is overwritten
Custody hash (SHA-256)
a7f3​c1d9​e2b4​6f08​9c5a​d31e​7b40​2f6c
88ae​14d7​0b93​ff21​5e6a​c9d0​3a17​e4b2

Deterministic over the canonical artifact contents. Two runs with identical inputs produce an identical hash, tamper-evident by construction.

Machine-readable record (structure only)
{
  "engagement": { "id": "[redacted]", "methodology_pin": "[redacted]" },
  "verdict": "auditable; not yet trust-ready",
  "graph": { /* typed nodes + edges */ },
  "findings": [ /* dimension, disposition, priority band, evidence ref */ ],
  "maturity": { /* govern, map, measure, manage */ },
  "remediation": [ /* sequenced, finding-linked */ ],
  "custody_hash": "a7f3c1d9…e4b2"
}

The PDF brief goes to the client. This record is the cross-pillar handoff. For Pipeline engagements it flows straight into SprintiQ Turbo so the build is sequenced by the same risk signal (next slide).

✓ Signed · Senior Auditor · · custody hash anchored
Projected re-audit: before / after one remediation cycle
Measure · Asserted (1)→Implemented (3)
Govern · Asserted (1)→Documented (2)
2 Critical findings open→0 Critical findings open

The before/after maturity delta is the proof point: the audit does not just rank risk, it produces a measurable lift once the roadmap is executed.

PIPELINE

Closed Loop: Audit to Build to Re-Audit

For Pipeline engagements the M7 record is not just handed over. It feeds SprintiQ Turbo, the Build pillar, so the same risk signal that ranked the threats now sequences the remediation build. One continuous chain from finding to shipped fix, then a re-audit that proves the fix landed.

◆ Sprint planning by proprietary engine ◆ Optional · Pipeline (Audit + Build) only
M7 JSON → Turbo
RPN-sequenced build
re-audit closes loop
◆ FMEA risk-priority signal propagates end to end closed loop AUDITAudit ArtifactM7 JSON · custody hash PRESTRUCT BRIDGEMaster SpecificationRPN-sequenced requirements BUILDSprintiQ Turborisk-priority sprint plan BUILDShipped RemediationClaude Code delivery log AUDITRe-Auditmaturity lift, verified
What the M7 record carries into Turbo
Requirements sequenced highest-risk-first by the same FMEA signal
Acceptance criteria constrained by the NIST gaps from M5
Capacity-aware sprint plan generated in risk-priority order
User stories with compliance embedded in acceptance criteria
Immutable delivery audit trail via Claude Code sync
The loop closes
Measure · Asserted (1)→Implemented (3)
2 Critical findings open→0 Critical findings open
Audit evidence trail→continuous build delivery trail

Every audit delivers the M7 record. Pipeline clients have Turbo execute the remediation build and the re-audit confirms the lift. Audit-only clients take the same record to their own engineering team.

01 / 08
Illustrative demonstration. The subject system, graph, findings, scores, and verdict shown are synthetic. The proprietary reasoning, discovery, and retrieval (RAG) engines are referenced but not exposed; this walkthrough deliberately omits SprintiQ's threat library, scoring rubric thresholds, framework crosswalks, remediation playbooks, and model prompts.