Identity and Passport
Agent Registry and Passport records capture owner roles, purpose, scope, lifecycle, permitted data classes, reviewed tools, prohibited actions, expiration, renewal, suspension, and revocation posture.
Agent Audit & Assurance Framework
Scaled Agents helps organize audit-supporting records for governed AI workers across identity, Passport governance, runtime permits, human review, security testing, drift signals, incidents, framework mappings, and export packages.
Evidence-generating platform
The goal is practical traceability: who owns the AI worker, what it is allowed to do, which controls apply, what evidence exists, what remains unresolved, and where accountable human review is required.
Agent Registry and Passport records capture owner roles, purpose, scope, lifecycle, permitted data classes, reviewed tools, prohibited actions, expiration, renewal, suspension, and revocation posture.
Toll Gate, Runtime Permit, Human Review, and Action Broker records help separate AI recommendations from scoped authority records and review-bounded action paths.
Audit Export Packages organize record IDs, timeline, mapped controls, missing evidence, open risks, reviewer notes, and reconstruction status for customer review preparation.
Security and drift
Security Harness records can document attempts to override source hierarchy, Passport scope, prohibited actions, tool boundaries, or human review requirements.
Harness records can capture unapproved actions, restricted destinations, data-exposure attempts, privilege expansion attempts, and agent-to-agent delegation abuse.
Governance Drift Signals can route suspected drift to evidence requests, human review, remediation, pause, suspension, revocation, or customer clarification.
Public descriptions are high-level readiness context. Security testing, monitoring, red-team activity, framework applicability, and production controls require qualified customer review and implementation evidence.
Framework readiness
Scaled Agents can help map records to common governance, security, privacy, operational-risk, and AI-risk frameworks. Mapping a record does not mean the customer is compliant, certified, legally covered, security approved, audit approved, or production authorized.
ISO/IEC 42001, NIST AI RMF, GDPR, EU AI Act, OWASP, MITRE ATLAS, SOC 2, and related sources may inform readiness mapping where applicable.
Each mapped control should identify an owner role, required evidence, review status, limitations, and next action.
Open findings should remain visible until owner review, evidence, exception handling, or closure review is complete.
Publication record