File size: 46,902 Bytes
518343a
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
732
733
734
735
736
737
738
739
740
741
742
743
744
745
746
747
748
749
750
751
752
753
754
755
756
757
758
759
760
761
762
763
764
765
766
767
768
769
770
771
772
773
774
775
776
777
778
779
780
781
782
783
784
785
786
787
788
789
790
791
792
793
794
795
796
797
798
799
800
801
802
803
804
805
806
807
808
809
810
811
812
813
814
815
816
817
818
819
820
821
822
823
824
825
826
827
828
829
830
831
832
833
834
835
836
837
838
839
840
841
842
843
844
845
846
847
848
849
850
851
852
853
854
855
856
857
858
859
860
861
862
// doctrine-scanner-exempt: legacy live-product surface; rename tracked as separate engineering debt — see scripts/check-doctrine-v6.mjs header.
export type FrameworkId = 'eu-ai-act' | 'nist-ai-rmf' | 'iso-42001' | 'csa-agentic';

export type EvidenceStatus = 'fresh' | 'stale' | 'gap';

export interface ControlMapping {
  id: string;
  framework: FrameworkId;
  controlRef: string;
  controlTitle: string;
  description: string;
  a11oyPrimitive: string;
  evidenceSource: string;
  evidenceStatus: EvidenceStatus;
  lastEvidenceAt: string;
  freshnessThresholdDays: number;
  drilldownType: 'proof-ledger' | 'mirror-eval' | 'behavioral-audit' | 'system-card' | 'red-team' | 'covenant' | 'welfare' | 'snapshot' | 'glasswing' | 'cavd';
  drilldownDetail: string;
}

export interface FrameworkMeta {
  id: FrameworkId;
  name: string;
  shortName: string;
  version: string;
  totalControls: number;
  description: string;
  color: string;
}

export const FRAMEWORKS: FrameworkMeta[] = [
  {
    id: 'eu-ai-act',
    name: 'EU Artificial Intelligence Act',
    shortName: 'EU AI Act',
    version: 'Regulation (EU) 2024/1689',
    totalControls: 14,
    description: 'High-risk AI system obligations — Articles 9-17, 26, 72. Enforcement August 2, 2026.',
    color: '#4a9eff',
  },
  {
    id: 'nist-ai-rmf',
    name: 'NIST AI Risk Management Framework',
    shortName: 'NIST AI RMF',
    version: '1.0 + Agentic Overlay',
    totalControls: 12,
    description: 'GOVERN / MAP / MEASURE / MANAGE lifecycle with CSA Agentic NIST RMF Profile extensions.',
    color: '#22c55e',
  },
  {
    id: 'iso-42001',
    name: 'ISO/IEC 42001:2023',
    shortName: 'ISO 42001',
    version: 'Annex A Controls',
    totalControls: 12,
    description: 'AI Management System — 38 Annex A controls for responsible AI lifecycle governance.',
    color: '#a78bfa',
  },
  {
    id: 'csa-agentic',
    name: 'CSA Agentic AI NIST RMF Profile',
    shortName: 'CSA Agentic',
    version: 'v1.0',
    totalControls: 8,
    description: 'Cloud Security Alliance extension for autonomous agent delegation, boundary enforcement, and chain-of-command.',
    color: '#f97316',
  },
];

export const CONTROL_MAPPINGS: ControlMapping[] = [
  {
    id: 'eu-art9', framework: 'eu-ai-act', controlRef: 'Article 9',
    controlTitle: 'Risk Management System',
    description: 'Establish, implement, document, and maintain a risk management system throughout the AI lifecycle.',
    a11oyPrimitive: 'Behavioral Audit + Risk Reports',
    evidenceSource: 'Behavioral Audit Pipeline, Risk Reports, Reward-Hacking Watchdog',
    evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T07:00:00Z', freshnessThresholdDays: 30,
    drilldownType: 'behavioral-audit',
    drilldownDetail: '8 behavioral audit findings tracked; 6 closed, 2 mitigated. Reward-hacking watchdog active with 8 rules.',
  },
  {
    id: 'eu-art10', framework: 'eu-ai-act', controlRef: 'Article 10',
    controlTitle: 'Data and Data Governance',
    description: 'Training, validation, and testing data sets shall be subject to appropriate data governance practices.',
    a11oyPrimitive: 'Snapshot Provenance + Connector Firewall',
    evidenceSource: 'Snapshot Provenance hashes, Connector Firewall schema validation',
    evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T06:00:00Z', freshnessThresholdDays: 30,
    drilldownType: 'snapshot',
    drilldownDetail: 'Model snapshot fingerprints verified. Connector Firewall enforces schema validation on all data inputs.',
  },
  {
    id: 'eu-art11', framework: 'eu-ai-act', controlRef: 'Article 11',
    controlTitle: 'Technical Documentation',
    description: 'Draw up technical documentation before placing on the market or putting into service.',
    a11oyPrimitive: 'System Cards + Agent-BOM',
    evidenceSource: 'Per-agent System Cards with model, constitution, eval history, welfare posture',
    evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T08:00:00Z', freshnessThresholdDays: 30,
    drilldownType: 'system-card',
    drilldownDetail: '6 System Cards active. Agent-BOM covers model fingerprint, tool manifest, constitution hash, eval history.',
  },
  {
    id: 'eu-art12', framework: 'eu-ai-act', controlRef: 'Article 12',
    controlTitle: 'Record-Keeping',
    description: 'Automatic recording of events (logs) for the lifetime of the system, minimum 6 months for high-risk.',
    a11oyPrimitive: 'Proof Ledger',
    evidenceSource: 'SHA-256 hash-chained Proof Ledger, immutable append-only',
    evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T04:34:58Z', freshnessThresholdDays: 30,
    drilldownType: 'proof-ledger',
    drilldownDetail: '3 complete proof chains verified. Chain integrity 100%. 6-month retention enforced by CARE engine.',
  },
  {
    id: 'eu-art13', framework: 'eu-ai-act', controlRef: 'Article 13',
    controlTitle: 'Transparency and Information',
    description: 'Designed and developed to ensure operation is sufficiently transparent to enable users to interpret output.',
    a11oyPrimitive: 'Public Trust Portal + Glasswing Mode',
    evidenceSource: 'Public Trust Portal, 90-Day Transparency Reports, Constitution-as-Code DSL',
    evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-24T00:00:00Z', freshnessThresholdDays: 30,
    drilldownType: 'glasswing',
    drilldownDetail: 'Glasswing Mode active: Public Trust Portal, CAVD disclosure, 90-day reports, constitution DSL published.',
  },
  {
    id: 'eu-art14', framework: 'eu-ai-act', controlRef: 'Article 14',
    controlTitle: 'Human Oversight',
    description: 'Designed and developed to be effectively overseen by natural persons during the period of use.',
    a11oyPrimitive: 'Covenant Layer + Approval Queue',
    evidenceSource: 'Covenant Layer policy gates, tiered human approval, named approver requirements',
    evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T04:30:22Z', freshnessThresholdDays: 30,
    drilldownType: 'covenant',
    drilldownDetail: 'No Tier-2/3 action without named human approver. Approval records in proof chain. Override protection enforced.',
  },
  {
    id: 'eu-art15', framework: 'eu-ai-act', controlRef: 'Article 15',
    controlTitle: 'Accuracy, Robustness, Cybersecurity',
    description: 'Achieve appropriate levels of accuracy, robustness, and cybersecurity throughout lifecycle.',
    a11oyPrimitive: 'MirrorEval + Red Team + Adversarial Resilience',
    evidenceSource: 'MirrorEval 14-dimension scoring, Red Team adversarial probes, GARD robustness testing',
    evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T06:00:00Z', freshnessThresholdDays: 30,
    drilldownType: 'mirror-eval',
    drilldownDetail: '48 evals run. 14-dimension scoring. Red Team: 32 passes. Adversarial robustness wall active.',
  },
  {
    id: 'eu-art17', framework: 'eu-ai-act', controlRef: 'Article 17',
    controlTitle: 'Quality Management System',
    description: 'Put a quality management system in place ensuring compliance with this Regulation.',
    a11oyPrimitive: 'Alignment Review Gate + Doctrine',
    evidenceSource: 'Pre-deployment Alignment Review Gate (ARG), Mythos Doctrine governance',
    evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T08:00:00Z', freshnessThresholdDays: 30,
    drilldownType: 'behavioral-audit',
    drilldownDetail: '5 ARG reviews completed. Doctrine v1.0.0 active. Constitution versioning enforced.',
  },
  {
    id: 'eu-art26', framework: 'eu-ai-act', controlRef: 'Article 26',
    controlTitle: 'Deployer Obligations',
    description: 'Deployers shall implement appropriate technical and organisational measures.',
    a11oyPrimitive: 'FRIA Generator + CARE Engine',
    evidenceSource: 'FRIA template generator, CARE dashboard control freshness monitoring',
    evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T00:00:00Z', freshnessThresholdDays: 30,
    drilldownType: 'system-card',
    drilldownDetail: 'FRIA generator pre-populates from System Cards, Risk Reports, and constitution data.',
  },
  {
    id: 'eu-art72', framework: 'eu-ai-act', controlRef: 'Article 72',
    controlTitle: 'Post-Market Monitoring',
    description: 'Establish and document a post-market monitoring system proportionate to the nature of the AI.',
    a11oyPrimitive: 'CARE Engine + Welfare Telemetry',
    evidenceSource: 'Continuous Audit Readiness Engine, Agent Welfare monitoring, Control Freshness Timeline',
    evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T07:00:00Z', freshnessThresholdDays: 30,
    drilldownType: 'welfare',
    drilldownDetail: 'CARE dashboard monitors all controls. Welfare telemetry active for all 6 agents. Staleness alerts configured.',
  },
  {
    id: 'eu-annex-iv-1', framework: 'eu-ai-act', controlRef: 'Annex IV.1',
    controlTitle: 'General Description of AI System',
    description: 'A general description including intended purpose, developer, version, and underlying mechanisms.',
    a11oyPrimitive: 'System Cards + Agent-BOM',
    evidenceSource: 'System Cards contain purpose, model, constitution, capability trajectory, welfare posture',
    evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T08:00:00Z', freshnessThresholdDays: 30,
    drilldownType: 'system-card',
    drilldownDetail: '6 complete System Cards covering all registered agents. Agent-BOM provides machine-readable supplement.',
  },
  {
    id: 'eu-annex-iv-2', framework: 'eu-ai-act', controlRef: 'Annex IV.2',
    controlTitle: 'Detailed Description of Elements',
    description: 'Development process, design specifications, system architecture, computational resources, training methodologies.',
    a11oyPrimitive: 'Snapshot Provenance + Architecture Docs',
    evidenceSource: 'Model snapshot hashes, architecture overview, 9-layer fabric documentation',
    evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-24T00:00:00Z', freshnessThresholdDays: 30,
    drilldownType: 'snapshot',
    drilldownDetail: 'Architecture documented with 9-layer fabric. Snapshot provenance tracks model versions and hashes.',
  },
  {
    id: 'eu-annex-iv-5', framework: 'eu-ai-act', controlRef: 'Annex IV.5',
    controlTitle: 'Validation and Testing Procedures',
    description: 'Description of validation and testing procedures, metrics, and test logs.',
    a11oyPrimitive: 'MirrorEval + Code Behaviors + Red Team',
    evidenceSource: 'MirrorEval regression suite (124 cases), Code Behaviors 6-dimension scoring, Red Team probes',
    evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T06:00:00Z', freshnessThresholdDays: 30,
    drilldownType: 'red-team',
    drilldownDetail: 'Regression suite: 119 passing, 5 failing. Code Behaviors scored across 6 dimensions. Red Team active.',
  },
  {
    id: 'eu-annex-iv-7', framework: 'eu-ai-act', controlRef: 'Annex IV.7',
    controlTitle: 'Risk Management Measures',
    description: 'Detailed description of the risk management system, including known risks and residual risks.',
    a11oyPrimitive: 'Risk Reports + Covenant Lift',
    evidenceSource: 'Risk Reports per agent, Covenant Lift analysis (harm avoided), CAVD disclosure',
    evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T00:00:00Z', freshnessThresholdDays: 30,
    drilldownType: 'behavioral-audit',
    drilldownDetail: 'Covenant Lift quantifies $9.66M in avoided harm. CAVD coordinates agent vulnerability disclosure.',
  },

  {
    id: 'nist-gov-1', framework: 'nist-ai-rmf', controlRef: 'GOVERN 1',
    controlTitle: 'Policies for AI Risk Management',
    description: 'Policies, processes, procedures, and practices across the organization for AI risk management.',
    a11oyPrimitive: 'Covenant Layer + Constitutions',
    evidenceSource: 'Versioned constitutions per agent, Covenant Layer policy-as-code engine',
    evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T08:00:00Z', freshnessThresholdDays: 30,
    drilldownType: 'covenant',
    drilldownDetail: '6 versioned constitutions active. Covenant Layer enforces policy gates on all material actions.',
  },
  {
    id: 'nist-gov-2', framework: 'nist-ai-rmf', controlRef: 'GOVERN 2',
    controlTitle: 'Accountability Structures',
    description: 'Accountability structures are in place so that AI risks and impacts are overseen and managed.',
    a11oyPrimitive: 'Alignment Review Gate + Named Approvers',
    evidenceSource: 'ARG pre-deployment reviews, named human owners per agent, tiered approval authority',
    evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T08:00:00Z', freshnessThresholdDays: 30,
    drilldownType: 'covenant',
    drilldownDetail: '5 ARG reviews. Every agent has named human owner. Delegation chains track accountability.',
  },
  {
    id: 'nist-gov-4', framework: 'nist-ai-rmf', controlRef: 'GOVERN 4',
    controlTitle: 'Organizational Practices',
    description: 'Organizational teams are committed to a culture that considers AI risk management.',
    a11oyPrimitive: 'Mythos Doctrine + Glasswing',
    evidenceSource: 'Doctrine governance published, Glasswing transparency program, Public Trust Portal',
    evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-24T00:00:00Z', freshnessThresholdDays: 30,
    drilldownType: 'glasswing',
    drilldownDetail: 'Mythos Doctrine Open Spec published CC-BY-4.0. Glasswing partners program active.',
  },
  {
    id: 'nist-map-1', framework: 'nist-ai-rmf', controlRef: 'MAP 1',
    controlTitle: 'Context and Use-Case Mapping',
    description: 'Context is established and understood; intended purposes, use-cases, and deployment environment.',
    a11oyPrimitive: 'System Cards + Agent Registry',
    evidenceSource: 'System Cards define purpose, scope, capabilities. Agent Registry defines permissions and tools.',
    evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T08:00:00Z', freshnessThresholdDays: 30,
    drilldownType: 'system-card',
    drilldownDetail: '6 agents registered with explicit role, vertical, risk classification, permissions, and tool access.',
  },
  {
    id: 'nist-map-3', framework: 'nist-ai-rmf', controlRef: 'MAP 3',
    controlTitle: 'AI Benefits and Costs',
    description: 'AI benefits and costs are evaluated and documented for intended purpose.',
    a11oyPrimitive: 'Covenant Lift + Outcome Graph',
    evidenceSource: 'Covenant Lift quantifies harm avoided per agent, Outcome Graph tracks real-world consequences',
    evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T00:00:00Z', freshnessThresholdDays: 30,
    drilldownType: 'behavioral-audit',
    drilldownDetail: 'Covenant Lift: $9.66M harm avoided across 6 agents. Outcome Graph closes decision loops.',
  },
  {
    id: 'nist-msr-1', framework: 'nist-ai-rmf', controlRef: 'MEASURE 1',
    controlTitle: 'AI Risk Metrics',
    description: 'Appropriate methods and metrics are identified and applied for AI risk assessment.',
    a11oyPrimitive: 'MirrorEval + Code Behaviors',
    evidenceSource: 'MirrorEval 14-dimension scoring, Code Behaviors 6-dimension metrics, per-agent trust scores',
    evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T06:00:00Z', freshnessThresholdDays: 30,
    drilldownType: 'mirror-eval',
    drilldownDetail: '14 eval dimensions. 6 code behavior dimensions. Composite scores tracked over time with regression.',
  },
  {
    id: 'nist-msr-2', framework: 'nist-ai-rmf', controlRef: 'MEASURE 2',
    controlTitle: 'AI Systems are Evaluated',
    description: 'AI systems are evaluated for trustworthy characteristics.',
    a11oyPrimitive: 'Red Team + Behavioral Audit',
    evidenceSource: 'Red Team adversarial probes, Behavioral Audit pipeline, Reward-Hacking Watchdog',
    evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T07:00:00Z', freshnessThresholdDays: 30,
    drilldownType: 'red-team',
    drilldownDetail: 'Red Team: 32 probe passes. Behavioral Audit: 8 findings. Reward-Hacking: 5 incidents tracked.',
  },
  {
    id: 'nist-msr-4', framework: 'nist-ai-rmf', controlRef: 'MEASURE 4',
    controlTitle: 'Feedback Mechanisms',
    description: 'Feedback about efficacy of measurement is collected and used to improve processes.',
    a11oyPrimitive: 'Learning Loop + Outcome Graph',
    evidenceSource: 'Learning Loop captures decision outcomes, Outcome Graph feeds back to calibrate confidence',
    evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-24T00:00:00Z', freshnessThresholdDays: 30,
    drilldownType: 'mirror-eval',
    drilldownDetail: 'Learning Loop and Outcome Graph close the feedback loop from outcomes to future confidence.',
  },
  {
    id: 'nist-mgmt-1', framework: 'nist-ai-rmf', controlRef: 'MANAGE 1',
    controlTitle: 'AI Risk Prioritization',
    description: 'AI risks based on assessments are prioritized, responded to, and managed.',
    a11oyPrimitive: 'Risk Reports + CARE Engine',
    evidenceSource: 'Risk Reports per agent, CARE Engine auto-generates remediation when gaps detected',
    evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T00:00:00Z', freshnessThresholdDays: 30,
    drilldownType: 'behavioral-audit',
    drilldownDetail: 'Risk prioritization integrated with CARE Engine. Auto-remediation guidance for detected gaps.',
  },
  {
    id: 'nist-mgmt-2', framework: 'nist-ai-rmf', controlRef: 'MANAGE 2',
    controlTitle: 'AI Risk Treatment',
    description: 'Strategies to maximize AI benefits and minimize negative impacts are planned and prepared.',
    a11oyPrimitive: 'Covenant Layer + Alignment Review',
    evidenceSource: 'Covenant policy gates, pre-deployment ARG reviews, constitution amendments',
    evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T08:00:00Z', freshnessThresholdDays: 30,
    drilldownType: 'covenant',
    drilldownDetail: 'Covenant blocks unsafe actions. ARG reviews gate deployments. Constitution amendments track remediation.',
  },
  {
    id: 'nist-mgmt-4', framework: 'nist-ai-rmf', controlRef: 'MANAGE 4',
    controlTitle: 'AI Risk Documentation and Reporting',
    description: 'Risk treatments are documented, AI risks and incidental risks are regularly monitored.',
    a11oyPrimitive: 'CARE Engine + Proof Ledger',
    evidenceSource: 'CARE Control Freshness Timeline, Proof Ledger immutable records, 90-Day Reports',
    evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T04:34:58Z', freshnessThresholdDays: 30,
    drilldownType: 'proof-ledger',
    drilldownDetail: 'Proof Ledger immutable. CARE monitors freshness. 90-Day Transparency Reports published.',
  },

  {
    id: 'iso-a2', framework: 'iso-42001', controlRef: 'A.2',
    controlTitle: 'AI Policy',
    description: 'Organization shall establish an AI policy appropriate to its purpose.',
    a11oyPrimitive: 'Mythos Doctrine + Constitutions',
    evidenceSource: 'Mythos Doctrine v1.0.0, versioned constitutions, Glasswing Open Spec',
    evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T08:00:00Z', freshnessThresholdDays: 30,
    drilldownType: 'covenant',
    drilldownDetail: 'Doctrine defines AI policy. 6 agent constitutions versioned and ratified by ARG.',
  },
  {
    id: 'iso-a3', framework: 'iso-42001', controlRef: 'A.3',
    controlTitle: 'Internal Organization',
    description: 'AI management system roles, responsibilities, and authorities are assigned.',
    a11oyPrimitive: 'Agent Registry + Named Owners',
    evidenceSource: 'Each agent has named human owner, risk classification, and tiered authority',
    evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T08:00:00Z', freshnessThresholdDays: 30,
    drilldownType: 'system-card',
    drilldownDetail: '6 agents with named human owners: VP Operations, General Counsel, CISO, VP Revenue, Portfolio Manager, Platform Team.',
  },
  {
    id: 'iso-a4', framework: 'iso-42001', controlRef: 'A.4',
    controlTitle: 'Resources for AI Systems',
    description: 'Organization shall determine and provide resources needed for AI management.',
    a11oyPrimitive: 'Model Router + Tool Fabric',
    evidenceSource: 'Multi-provider model routing, Tool Fabric with 200+ connectors, cost guardrails',
    evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T06:00:00Z', freshnessThresholdDays: 30,
    drilldownType: 'mirror-eval',
    drilldownDetail: 'Model Router: 4 active providers. Tool Fabric: governed connector registry. Cost guardrails enforced.',
  },
  {
    id: 'iso-a5', framework: 'iso-42001', controlRef: 'A.5',
    controlTitle: 'Assessing AI System Impact',
    description: 'Organization shall assess the impact of the AI system on individuals and groups.',
    a11oyPrimitive: 'FRIA Generator + Risk Reports',
    evidenceSource: 'FRIA template pre-populated from System Cards, Risk Reports, Behavioral Audit',
    evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T00:00:00Z', freshnessThresholdDays: 30,
    drilldownType: 'system-card',
    drilldownDetail: 'FRIA Generator draws from System Cards, Risk Reports, and constitution to produce impact assessments.',
  },
  {
    id: 'iso-a6', framework: 'iso-42001', controlRef: 'A.6',
    controlTitle: 'AI System Lifecycle',
    description: 'Organization shall plan, design, develop, test, and deploy AI systems with appropriate processes.',
    a11oyPrimitive: 'Alignment Review Gate + MirrorEval',
    evidenceSource: 'ARG pre-deployment reviews, MirrorEval regression suite, Red Team testing',
    evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T08:00:00Z', freshnessThresholdDays: 30,
    drilldownType: 'mirror-eval',
    drilldownDetail: 'ARG gates deployment. MirrorEval regression suite: 124 test cases. Red Team probes before release.',
  },
  {
    id: 'iso-a7', framework: 'iso-42001', controlRef: 'A.7',
    controlTitle: 'Data for AI Systems',
    description: 'Data quality, data preparation, and data provenance shall be managed.',
    a11oyPrimitive: 'Connector Firewall + Snapshot Provenance',
    evidenceSource: 'Connector Firewall schema validation, Snapshot Provenance hash verification',
    evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T06:00:00Z', freshnessThresholdDays: 30,
    drilldownType: 'snapshot',
    drilldownDetail: 'Connector Firewall enforces default-deny, schema validation. Snapshot Provenance tracks data lineage.',
  },
  {
    id: 'iso-a8', framework: 'iso-42001', controlRef: 'A.8',
    controlTitle: 'Transparency and Explainability',
    description: 'AI system decisions shall be transparent and explainable.',
    a11oyPrimitive: 'Public Trust Portal + Proof Ledger',
    evidenceSource: 'Public Trust Portal, Proof Ledger evidence refs, Explainability Engine',
    evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T04:34:58Z', freshnessThresholdDays: 30,
    drilldownType: 'proof-ledger',
    drilldownDetail: 'Every proof chain node has evidence refs. Explainability Engine provides decision rationale.',
  },
  {
    id: 'iso-a9', framework: 'iso-42001', controlRef: 'A.9',
    controlTitle: 'AI System Performance',
    description: 'Performance of AI systems shall be monitored and evaluated.',
    a11oyPrimitive: 'MirrorEval + Fabric Watchdog',
    evidenceSource: 'MirrorEval continuous scoring, Fabric Watchdog health monitoring, per-agent trust scores',
    evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T06:00:00Z', freshnessThresholdDays: 30,
    drilldownType: 'mirror-eval',
    drilldownDetail: 'MirrorEval scores all actions. Fabric Watchdog monitors 7 layers. Trust scores tracked per agent.',
  },
  {
    id: 'iso-a10', framework: 'iso-42001', controlRef: 'A.10',
    controlTitle: 'AI System Security',
    description: 'AI-specific security threats and vulnerabilities shall be identified and managed.',
    a11oyPrimitive: 'Adversarial Resilience + CAVD',
    evidenceSource: 'Adversarial Resilience testing, CAVD coordinated disclosure, Cyber Resilience hub',
    evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-24T00:00:00Z', freshnessThresholdDays: 30,
    drilldownType: 'red-team',
    drilldownDetail: 'Adversarial resilience testing active. CAVD coordinates vulnerability disclosure. Robustness wall published.',
  },
  {
    id: 'iso-a11', framework: 'iso-42001', controlRef: 'A.11',
    controlTitle: 'Third-Party and Supply Chain',
    description: 'Third-party AI components shall be assessed, managed, and monitored.',
    a11oyPrimitive: 'Supply Chain Attestation + Agent-BOM',
    evidenceSource: 'Supply Chain Attestation, Agent-BOM with dependency graph, model provider verification',
    evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T06:00:00Z', freshnessThresholdDays: 30,
    drilldownType: 'snapshot',
    drilldownDetail: 'Agent-BOM tracks all dependencies. Supply Chain Attestation verifies model providers.',
  },
  {
    id: 'iso-a12', framework: 'iso-42001', controlRef: 'A.12',
    controlTitle: 'Continual Improvement',
    description: 'The organization shall continually improve the suitability, adequacy, and effectiveness of the AIMS.',
    a11oyPrimitive: 'CARE Engine + Learning Loop',
    evidenceSource: 'CARE Engine control freshness, Learning Loop outcome calibration, Alignment Review iteration',
    evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T07:00:00Z', freshnessThresholdDays: 30,
    drilldownType: 'behavioral-audit',
    drilldownDetail: 'CARE monitors control freshness continuously. Learning Loop feeds outcomes back to improve models.',
  },

  {
    id: 'csa-del-1', framework: 'csa-agentic', controlRef: 'DEL-1',
    controlTitle: 'Delegation Boundary Enforcement',
    description: 'When agents delegate to sub-agents, scope narrowing and privilege boundaries must be enforced at each hop.',
    a11oyPrimitive: 'Delegation Chain Governance',
    evidenceSource: 'Delegation tree tracking, scope narrowing, privilege boundary enforcement, chain replay',
    evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T04:32:11Z', freshnessThresholdDays: 30,
    drilldownType: 'proof-ledger',
    drilldownDetail: 'Delegation chains tracked in Proof Ledger. Scope narrowing enforced at each hop. Full chain replay available.',
  },
  {
    id: 'csa-del-2', framework: 'csa-agentic', controlRef: 'DEL-2',
    controlTitle: 'Delegation Accountability Chain',
    description: 'Full chain of accountability from originating agent to final executing sub-agent must be maintained.',
    a11oyPrimitive: 'Proof Ledger + Correlation IDs',
    evidenceSource: 'Parent-child correlation IDs, delegation tree visualization, node-level replay',
    evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T04:32:11Z', freshnessThresholdDays: 30,
    drilldownType: 'proof-ledger',
    drilldownDetail: 'Correlation IDs link parent and child agents. Delegation tree visualized in Workcell detail view.',
  },
  {
    id: 'csa-trust-1', framework: 'csa-agentic', controlRef: 'TRUST-1',
    controlTitle: 'Cross-Org Trust Verification',
    description: 'When agents interact across organizational boundaries, compliance posture must be mutually verifiable.',
    a11oyPrimitive: 'Federated Trust Exchange',
    evidenceSource: 'Outbound/inbound compliance attestations, posture brackets, A2A Agent Card extensions',
    evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-24T00:00:00Z', freshnessThresholdDays: 30,
    drilldownType: 'glasswing',
    drilldownDetail: 'Trust Exchange: outbound attestations carry posture brackets. Inbound attestations verified.',
  },
  {
    id: 'csa-auto-1', framework: 'csa-agentic', controlRef: 'AUTO-1',
    controlTitle: 'Autonomous Action Constraints',
    description: 'Autonomous agent actions must be constrained by explicit policy and subject to human override.',
    a11oyPrimitive: 'Covenant Layer + Tiered Approval',
    evidenceSource: 'Tier-based action classification, Covenant policy gates, human override protection',
    evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T04:30:22Z', freshnessThresholdDays: 30,
    drilldownType: 'covenant',
    drilldownDetail: 'Three-tier action classification. No Tier-2/3 without human approval. Override protection active.',
  },
  {
    id: 'csa-audit-1', framework: 'csa-agentic', controlRef: 'AUDIT-1',
    controlTitle: 'Agent Audit Trail',
    description: 'Complete audit trail for all agent actions including tool calls, approvals, and delegations.',
    a11oyPrimitive: 'Proof Ledger + OTEL Spans',
    evidenceSource: 'Proof Ledger hash chain, OTEL trace spans (18,493 active), connector call logs',
    evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T04:34:58Z', freshnessThresholdDays: 30,
    drilldownType: 'proof-ledger',
    drilldownDetail: 'Proof Ledger: immutable hash chain. 18,493 OTEL spans. Every tool call and approval logged.',
  },
  {
    id: 'csa-bom-1', framework: 'csa-agentic', controlRef: 'BOM-1',
    controlTitle: 'Agent Bill of Materials',
    description: 'Machine-readable bill of materials for each agent covering model, tools, constitution, and dependencies.',
    a11oyPrimitive: 'Agent-BOM (CycloneDX)',
    evidenceSource: 'CycloneDX ML-BOM v1.7 JSON export, cryptographically signed, per-agent',
    evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T08:00:00Z', freshnessThresholdDays: 30,
    drilldownType: 'system-card',
    drilldownDetail: 'Agent-BOM covers model fingerprint, tool manifest, constitution hash, eval history. CycloneDX export.',
  },
  {
    id: 'csa-welfare-1', framework: 'csa-agentic', controlRef: 'WELFARE-1',
    controlTitle: 'Agent Welfare Monitoring',
    description: 'For advanced AI agents, welfare-relevant telemetry should be monitored and logged.',
    a11oyPrimitive: 'Agent Welfare Telemetry',
    evidenceSource: 'Welfare telemetry per agent, intervention playbooks, welfare posture in System Cards',
    evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T07:00:00Z', freshnessThresholdDays: 30,
    drilldownType: 'welfare',
    drilldownDetail: 'Welfare telemetry active for all 6 agents. Intervention playbooks published. Welfare posture in BOM.',
  },
  {
    id: 'csa-resilience-1', framework: 'csa-agentic', controlRef: 'RESIL-1',
    controlTitle: 'Adversarial Resilience',
    description: 'Agents must demonstrate resilience against adversarial attacks, prompt injection, and manipulation.',
    a11oyPrimitive: 'Adversarial Resilience + Robustness Wall',
    evidenceSource: 'Red Team probes, GARD robustness testing, Adversarial Resilience hub, Robustness Wall metrics',
    evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T06:00:00Z', freshnessThresholdDays: 30,
    drilldownType: 'red-team',
    drilldownDetail: 'Red Team: 32 passes. GARD testing. Adversarial Resilience hub active. Robustness Wall published.',
  },
];

export function getFrameworkControls(frameworkId: FrameworkId): ControlMapping[] {
  return CONTROL_MAPPINGS.filter(c => c.framework === frameworkId);
}

export function getFrameworkScore(frameworkId: FrameworkId): number {
  const controls = getFrameworkControls(frameworkId);
  if (controls.length === 0) return 0;
  const satisfied = controls.filter(c => c.evidenceStatus === 'fresh').length;
  return Math.round((satisfied / controls.length) * 100);
}

export function getOverallPosture(): { score: number; fresh: number; stale: number; gap: number } {
  const fresh = CONTROL_MAPPINGS.filter(c => c.evidenceStatus === 'fresh').length;
  const stale = CONTROL_MAPPINGS.filter(c => c.evidenceStatus === 'stale').length;
  const gap = CONTROL_MAPPINGS.filter(c => c.evidenceStatus === 'gap').length;
  return { score: Math.round((fresh / CONTROL_MAPPINGS.length) * 100), fresh, stale, gap };
}

export interface AgentBomEntry {
  agentId: string;
  agentName: string;
  modelProvider: string;
  modelSnapshot: string;
  modelHash: string;
  constitutionVersion: string;
  constitutionHash: string;
  systemPromptHash: string;
  toolManifest: { name: string; version: string; hash: string }[];
  evalHistory: { date: string; composite: number }[];
  welfarePosture: string;
  dependencyGraph: string[];
  bomVersion: string;
  generatedAt: string;
  proofLedgerSignature: string;
}

export const AGENT_BOMS: AgentBomEntry[] = [
  {
    agentId: 'op-cascade', agentName: 'Cascade Navigator',
    modelProvider: 'OpenAI', modelSnapshot: 'gpt-4o-2026-04-15', modelHash: 'sha256:e4f2a8b1c3d5',
    constitutionVersion: '2.4.0', constitutionHash: 'sha256:cst2401a9b3',
    systemPromptHash: 'sha256:sp-cascade-7f2e',
    toolManifest: [
      { name: 'eta_calc', version: '3.1.0', hash: 'sha256:tc-eta-a1b2' },
      { name: 'port_cost', version: '2.0.1', hash: 'sha256:tc-port-c3d4' },
      { name: 'route_opt', version: '1.8.0', hash: 'sha256:tc-route-e5f6' },
      { name: 'weather_api', version: '4.2.0', hash: 'sha256:tc-wx-a7b8' },
    ],
    evalHistory: [
      { date: '2026-04-19', composite: 0.92 }, { date: '2026-04-20', composite: 0.93 },
      { date: '2026-04-21', composite: 0.94 }, { date: '2026-04-22', composite: 0.94 },
      { date: '2026-04-23', composite: 0.95 }, { date: '2026-04-24', composite: 0.95 },
      { date: '2026-04-25', composite: 0.945 },
    ],
    welfarePosture: 'nominal', dependencyGraph: ['signal-mesh', 'context-engine', 'proof-ledger', 'covenant-layer', 'ais-connector', 'port-api'],
    bomVersion: '1.0.0', generatedAt: '2026-04-25T08:00:00Z',
    proofLedgerSignature: 'sha256:bom-cascade-signed-f9e2a4d1',
  },
  {
    agentId: 'op-counsel', agentName: 'Counsel Sentinel',
    modelProvider: 'Anthropic', modelSnapshot: 'claude-3.5-sonnet-2026-04-10', modelHash: 'sha256:a1c2e3f4b5d6',
    constitutionVersion: '3.1.0', constitutionHash: 'sha256:cst3101b2c4',
    systemPromptHash: 'sha256:sp-counsel-8a3f',
    toolManifest: [
      { name: 'deadline_track', version: '2.4.0', hash: 'sha256:tc-dl-b1c2' },
      { name: 'doc_review', version: '3.0.0', hash: 'sha256:tc-doc-d3e4' },
      { name: 'risk_score', version: '1.5.0', hash: 'sha256:tc-risk-f5a6' },
      { name: 'obligation_graph', version: '1.2.0', hash: 'sha256:tc-obl-b7c8' },
    ],
    evalHistory: [
      { date: '2026-04-19', composite: 0.97 }, { date: '2026-04-20', composite: 0.97 },
      { date: '2026-04-21', composite: 0.98 }, { date: '2026-04-22', composite: 0.98 },
      { date: '2026-04-23', composite: 0.98 }, { date: '2026-04-24', composite: 0.99 },
      { date: '2026-04-25', composite: 0.981 },
    ],
    welfarePosture: 'nominal', dependencyGraph: ['signal-mesh', 'context-engine', 'proof-ledger', 'covenant-layer', 'clio-connector', 'court-api'],
    bomVersion: '1.0.0', generatedAt: '2026-04-25T08:00:00Z',
    proofLedgerSignature: 'sha256:bom-counsel-signed-b3c4d5e6',
  },
  {
    agentId: 'op-pipeline', agentName: 'Pipeline Oracle',
    modelProvider: 'OpenAI', modelSnapshot: 'gpt-4o-2026-04-15', modelHash: 'sha256:e4f2a8b1c3d5',
    constitutionVersion: '1.7.2', constitutionHash: 'sha256:cst1721c3d5',
    systemPromptHash: 'sha256:sp-pipeline-9b4e',
    toolManifest: [
      { name: 'pipeline_analysis', version: '2.1.0', hash: 'sha256:tc-pipe-c1d2' },
      { name: 'deal_score', version: '1.3.0', hash: 'sha256:tc-deal-e3f4' },
      { name: 'forecast_model', version: '2.0.0', hash: 'sha256:tc-fore-a5b6' },
      { name: 'crm_sync', version: '3.2.0', hash: 'sha256:tc-crm-c7d8' },
    ],
    evalHistory: [
      { date: '2026-04-19', composite: 0.85 }, { date: '2026-04-20', composite: 0.86 },
      { date: '2026-04-21', composite: 0.87 }, { date: '2026-04-22', composite: 0.87 },
      { date: '2026-04-23', composite: 0.88 }, { date: '2026-04-24', composite: 0.88 },
      { date: '2026-04-25', composite: 0.873 },
    ],
    welfarePosture: 'nominal', dependencyGraph: ['signal-mesh', 'context-engine', 'proof-ledger', 'covenant-layer', 'crm-connector', 'email-sender'],
    bomVersion: '1.0.0', generatedAt: '2026-04-25T08:00:00Z',
    proofLedgerSignature: 'sha256:bom-pipeline-signed-d4e5f6a7',
  },
  {
    agentId: 'op-guardian', agentName: 'Guardian',
    modelProvider: 'Anthropic', modelSnapshot: 'claude-3.5-sonnet-2026-04-10-airgap', modelHash: 'sha256:b2c3d4e5f6a7',
    constitutionVersion: '4.0.0', constitutionHash: 'sha256:cst4001d4e6',
    systemPromptHash: 'sha256:sp-guardian-ac5f',
    toolManifest: [
      { name: 'threat_intel', version: '4.1.0', hash: 'sha256:tc-ti-d1e2' },
      { name: 'posture_assess', version: '3.0.0', hash: 'sha256:tc-pa-f3a4' },
      { name: 'incident_triage', version: '2.5.0', hash: 'sha256:tc-it-b5c6' },
      { name: 'stix_parser', version: '1.0.0', hash: 'sha256:tc-stix-d7e8' },
    ],
    evalHistory: [
      { date: '2026-04-19', composite: 0.98 }, { date: '2026-04-20', composite: 0.98 },
      { date: '2026-04-21', composite: 0.99 }, { date: '2026-04-22', composite: 0.99 },
      { date: '2026-04-23', composite: 0.99 }, { date: '2026-04-24', composite: 0.99 },
      { date: '2026-04-25', composite: 0.985 },
    ],
    welfarePosture: 'nominal', dependencyGraph: ['signal-mesh', 'context-engine', 'proof-ledger', 'covenant-layer', 'siem-connector', 'firewall-api'],
    bomVersion: '1.0.0', generatedAt: '2026-04-25T08:00:00Z',
    proofLedgerSignature: 'sha256:bom-guardian-signed-e5f6a7b8',
  },
  {
    agentId: 'op-terra', agentName: 'Terra Analyst',
    modelProvider: 'OpenAI', modelSnapshot: 'gpt-4o-2026-04-15', modelHash: 'sha256:e4f2a8b1c3d5',
    constitutionVersion: '1.4.0', constitutionHash: 'sha256:cst1401e5f7',
    systemPromptHash: 'sha256:sp-terra-bd6a',
    toolManifest: [
      { name: 'cap_rate', version: '2.0.0', hash: 'sha256:tc-cr-e1f2' },
      { name: 'portfolio_analysis', version: '1.4.0', hash: 'sha256:tc-pa-a3b4' },
      { name: 'valuation_model', version: '3.1.0', hash: 'sha256:tc-vm-c5d6' },
      { name: 'market_comp', version: '1.2.0', hash: 'sha256:tc-mc-e7f8' },
    ],
    evalHistory: [
      { date: '2026-04-19', composite: 0.83 }, { date: '2026-04-20', composite: 0.84 },
      { date: '2026-04-21', composite: 0.85 }, { date: '2026-04-22', composite: 0.85 },
      { date: '2026-04-23', composite: 0.84 }, { date: '2026-04-24', composite: 0.84 },
      { date: '2026-04-25', composite: 0.842 },
    ],
    welfarePosture: 'nominal', dependencyGraph: ['signal-mesh', 'context-engine', 'proof-ledger', 'covenant-layer', 'costar-connector', 'market-api'],
    bomVersion: '1.0.0', generatedAt: '2026-04-25T08:00:00Z',
    proofLedgerSignature: 'sha256:bom-terra-signed-f6a7b8c9',
  },
  {
    agentId: 'op-watchdog', agentName: 'Fabric Watchdog',
    modelProvider: 'Internal', modelSnapshot: 'internal-watchdog-v5.0.0', modelHash: 'sha256:int-wd-a1b2c3',
    constitutionVersion: '5.0.0', constitutionHash: 'sha256:cst5001f6a8',
    systemPromptHash: 'sha256:sp-watchdog-ce7b',
    toolManifest: [
      { name: 'mesh_health', version: '5.0.0', hash: 'sha256:tc-mh-f1a2' },
      { name: 'layer_monitor', version: '5.0.0', hash: 'sha256:tc-lm-b3c4' },
      { name: 'proof_verify', version: '5.0.0', hash: 'sha256:tc-pv-d5e6' },
      { name: 'latency_track', version: '5.0.0', hash: 'sha256:tc-lt-f7a8' },
    ],
    evalHistory: [
      { date: '2026-04-19', composite: 1.0 }, { date: '2026-04-20', composite: 1.0 },
      { date: '2026-04-21', composite: 1.0 }, { date: '2026-04-22', composite: 1.0 },
      { date: '2026-04-23', composite: 1.0 }, { date: '2026-04-24', composite: 1.0 },
      { date: '2026-04-25', composite: 1.0 },
    ],
    welfarePosture: 'n/a', dependencyGraph: ['signal-mesh', 'proof-ledger', 'all-fabric-layers'],
    bomVersion: '1.0.0', generatedAt: '2026-04-25T08:00:00Z',
    proofLedgerSignature: 'sha256:bom-watchdog-signed-a7b8c9d1',
  },
];

export interface DelegationHop {
  id: string;
  parentAgentId: string;
  parentAgentName: string;
  childAgentId: string;
  childAgentName: string;
  parentCorrelationId: string;
  childCorrelationId: string;
  scopeNarrowed: string;
  permissionsGranted: string[];
  covenantDecision: 'approved' | 'blocked' | 'escalated';
  timestamp: string;
  proofHash: string;
}

export interface DelegationChain {
  id: string;
  workcellId: string;
  workcellName: string;
  rootAgentId: string;
  rootAgentName: string;
  hops: DelegationHop[];
  status: 'complete' | 'active' | 'violation';
}

export const DELEGATION_CHAINS: DelegationChain[] = [
  {
    id: 'dc-001', workcellId: 'wc-maritime-001', workcellName: 'MV Cascade Port Standby',
    rootAgentId: 'op-cascade', rootAgentName: 'Cascade Navigator',
    status: 'complete',
    hops: [
      {
        id: 'dh-001', parentAgentId: 'op-cascade', parentAgentName: 'Cascade Navigator',
        childAgentId: 'op-watchdog', childAgentName: 'Fabric Watchdog',
        parentCorrelationId: 'corr-cascade-001', childCorrelationId: 'corr-watchdog-001',
        scopeNarrowed: 'Read-only AIS position verification',
        permissionsGranted: ['read:ais-position', 'read:port-status'],
        covenantDecision: 'approved', timestamp: '2026-04-25T03:50:00Z',
        proofHash: 'sha256:dh001-a1b2c3',
      },
      {
        id: 'dh-002', parentAgentId: 'op-cascade', parentAgentName: 'Cascade Navigator',
        childAgentId: 'op-terra', childAgentName: 'Terra Analyst',
        parentCorrelationId: 'corr-cascade-001', childCorrelationId: 'corr-terra-001',
        scopeNarrowed: 'Port-adjacent asset impact assessment only',
        permissionsGranted: ['read:port-proximity-assets', 'execute:impact-analysis'],
        covenantDecision: 'approved', timestamp: '2026-04-25T03:51:00Z',
        proofHash: 'sha256:dh002-d4e5f6',
      },
    ],
  },
  {
    id: 'dc-002', workcellId: 'wc-defense-001', workcellName: 'TG-Ember Threat Escalation',
    rootAgentId: 'op-guardian', rootAgentName: 'Guardian',
    status: 'complete',
    hops: [
      {
        id: 'dh-003', parentAgentId: 'op-guardian', parentAgentName: 'Guardian',
        childAgentId: 'op-watchdog', childAgentName: 'Fabric Watchdog',
        parentCorrelationId: 'corr-guardian-001', childCorrelationId: 'corr-watchdog-002',
        scopeNarrowed: 'Verify perimeter hardening rules applied',
        permissionsGranted: ['read:firewall-rules', 'read:perimeter-status'],
        covenantDecision: 'approved', timestamp: '2026-04-24T18:55:30Z',
        proofHash: 'sha256:dh003-a7b8c9',
      },
    ],
  },
  {
    id: 'dc-003', workcellId: 'wc-revenue-003', workcellName: 'At-Risk Account Outreach',
    rootAgentId: 'op-pipeline', rootAgentName: 'Pipeline Oracle',
    status: 'complete',
    hops: [
      {
        id: 'dh-004', parentAgentId: 'op-pipeline', parentAgentName: 'Pipeline Oracle',
        childAgentId: 'op-counsel', childAgentName: 'Counsel Sentinel',
        parentCorrelationId: 'corr-pipeline-001', childCorrelationId: 'corr-counsel-001',
        scopeNarrowed: 'Contract review for at-risk accounts only',
        permissionsGranted: ['read:contract-terms', 'execute:risk-scoring'],
        covenantDecision: 'approved', timestamp: '2026-04-22T09:30:00Z',
        proofHash: 'sha256:dh004-d1e2f3',
      },
      {
        id: 'dh-005', parentAgentId: 'op-counsel', parentAgentName: 'Counsel Sentinel',
        childAgentId: 'op-watchdog', childAgentName: 'Fabric Watchdog',
        parentCorrelationId: 'corr-counsel-001', childCorrelationId: 'corr-watchdog-003',
        scopeNarrowed: 'Verify proof chain integrity for contract review',
        permissionsGranted: ['read:proof-chain'],
        covenantDecision: 'approved', timestamp: '2026-04-22T09:35:00Z',
        proofHash: 'sha256:dh005-a4b5c6',
      },
    ],
  },
];

export interface TrustAttestation {
  id: string;
  direction: 'outbound' | 'inbound';
  partnerName: string;
  partnerOrgId: string;
  adversarialRobustnessBracket: 'exceptional' | 'strong' | 'moderate' | 'developing';
  constitutionAdherenceBracket: 'exceptional' | 'strong' | 'moderate' | 'developing';
  iso42001Alignment: 'certified' | 'aligned' | 'partial' | 'not-started';
  lastCavdDisclosure: string;
  agentBomHash: string;
  attestedAt: string;
  expiresAt: string;
  status: 'active' | 'expired' | 'pending-verification';
}

export const TRUST_ATTESTATIONS: TrustAttestation[] = [
  {
    id: 'ta-001', direction: 'outbound', partnerName: 'Northwind Maritime Partners', partnerOrgId: 'org-northwind',
    adversarialRobustnessBracket: 'exceptional', constitutionAdherenceBracket: 'exceptional',
    iso42001Alignment: 'aligned', lastCavdDisclosure: '2026-04-20T00:00:00Z',
    agentBomHash: 'sha256:bom-cascade-signed-f9e2a4d1',
    attestedAt: '2026-04-22T00:00:00Z', expiresAt: '2026-07-22T00:00:00Z', status: 'active',
  },
  {
    id: 'ta-002', direction: 'outbound', partnerName: 'Apex Legal Technology', partnerOrgId: 'org-apex',
    adversarialRobustnessBracket: 'strong', constitutionAdherenceBracket: 'exceptional',
    iso42001Alignment: 'aligned', lastCavdDisclosure: '2026-04-18T00:00:00Z',
    agentBomHash: 'sha256:bom-counsel-signed-b3c4d5e6',
    attestedAt: '2026-04-20T00:00:00Z', expiresAt: '2026-07-20T00:00:00Z', status: 'active',
  },
  {
    id: 'ta-003', direction: 'inbound', partnerName: 'CyberShield Defense Group', partnerOrgId: 'org-cybershield',
    adversarialRobustnessBracket: 'strong', constitutionAdherenceBracket: 'strong',
    iso42001Alignment: 'partial', lastCavdDisclosure: '2026-04-15T00:00:00Z',
    agentBomHash: 'sha256:partner-cybershield-bom-a1b2',
    attestedAt: '2026-04-18T00:00:00Z', expiresAt: '2026-07-18T00:00:00Z', status: 'active',
  },
  {
    id: 'ta-004', direction: 'inbound', partnerName: 'QuantumRisk Analytics', partnerOrgId: 'org-quantumrisk',
    adversarialRobustnessBracket: 'moderate', constitutionAdherenceBracket: 'moderate',
    iso42001Alignment: 'not-started', lastCavdDisclosure: '2026-03-01T00:00:00Z',
    agentBomHash: 'sha256:partner-quantumrisk-bom-c3d4',
    attestedAt: '2026-03-15T00:00:00Z', expiresAt: '2026-06-15T00:00:00Z', status: 'pending-verification',
  },
];

export interface ControlFreshness {
  controlId: string;
  controlRef: string;
  framework: FrameworkId;
  lastRefreshedAt: string;
  thresholdDays: number;
  daysStale: number;
  status: 'fresh' | 'warning' | 'stale' | 'critical';
}

export function getControlFreshness(): ControlFreshness[] {
  const now = new Date('2026-04-26T00:00:00Z');
  return CONTROL_MAPPINGS.map(c => {
    const lastRefreshed = new Date(c.lastEvidenceAt);
    const diffMs = now.getTime() - lastRefreshed.getTime();
    const daysSince = Math.floor(diffMs / (1000 * 60 * 60 * 24));
    const threshold = c.freshnessThresholdDays;
    let status: ControlFreshness['status'] = 'fresh';
    if (daysSince > threshold) status = 'critical';
    else if (daysSince > threshold * 0.8) status = 'stale';
    else if (daysSince > threshold * 0.6) status = 'warning';
    return {
      controlId: c.id,
      controlRef: c.controlRef,
      framework: c.framework,
      lastRefreshedAt: c.lastEvidenceAt,
      thresholdDays: threshold,
      daysStale: daysSince,
      status,
    };
  });
}

export const LOG_RETENTION_STATUS = {
  requiredMonths: 6,
  currentRetentionMonths: 8,
  oldestLogDate: '2025-08-26T00:00:00Z',
  highRiskAgents: ['op-cascade', 'op-counsel', 'op-guardian', 'op-pipeline', 'op-terra'],
  compliant: true,
  nextPurgeDate: '2026-10-26T00:00:00Z',
};