// doctrine-scanner-exempt: legacy live-product surface; rename tracked as separate engineering debt — see scripts/check-doctrine-v6.mjs header. export type FrameworkId = 'eu-ai-act' | 'nist-ai-rmf' | 'iso-42001' | 'csa-agentic'; export type EvidenceStatus = 'fresh' | 'stale' | 'gap'; export interface ControlMapping { id: string; framework: FrameworkId; controlRef: string; controlTitle: string; description: string; a11oyPrimitive: string; evidenceSource: string; evidenceStatus: EvidenceStatus; lastEvidenceAt: string; freshnessThresholdDays: number; drilldownType: 'proof-ledger' | 'mirror-eval' | 'behavioral-audit' | 'system-card' | 'red-team' | 'covenant' | 'welfare' | 'snapshot' | 'glasswing' | 'cavd'; drilldownDetail: string; } export interface FrameworkMeta { id: FrameworkId; name: string; shortName: string; version: string; totalControls: number; description: string; color: string; } export const FRAMEWORKS: FrameworkMeta[] = [ { id: 'eu-ai-act', name: 'EU Artificial Intelligence Act', shortName: 'EU AI Act', version: 'Regulation (EU) 2024/1689', totalControls: 14, description: 'High-risk AI system obligations — Articles 9-17, 26, 72. Enforcement August 2, 2026.', color: '#4a9eff', }, { id: 'nist-ai-rmf', name: 'NIST AI Risk Management Framework', shortName: 'NIST AI RMF', version: '1.0 + Agentic Overlay', totalControls: 12, description: 'GOVERN / MAP / MEASURE / MANAGE lifecycle with CSA Agentic NIST RMF Profile extensions.', color: '#22c55e', }, { id: 'iso-42001', name: 'ISO/IEC 42001:2023', shortName: 'ISO 42001', version: 'Annex A Controls', totalControls: 12, description: 'AI Management System — 38 Annex A controls for responsible AI lifecycle governance.', color: '#a78bfa', }, { id: 'csa-agentic', name: 'CSA Agentic AI NIST RMF Profile', shortName: 'CSA Agentic', version: 'v1.0', totalControls: 8, description: 'Cloud Security Alliance extension for autonomous agent delegation, boundary enforcement, and chain-of-command.', color: '#f97316', }, ]; export const CONTROL_MAPPINGS: ControlMapping[] = [ { id: 'eu-art9', framework: 'eu-ai-act', controlRef: 'Article 9', controlTitle: 'Risk Management System', description: 'Establish, implement, document, and maintain a risk management system throughout the AI lifecycle.', a11oyPrimitive: 'Behavioral Audit + Risk Reports', evidenceSource: 'Behavioral Audit Pipeline, Risk Reports, Reward-Hacking Watchdog', evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T07:00:00Z', freshnessThresholdDays: 30, drilldownType: 'behavioral-audit', drilldownDetail: '8 behavioral audit findings tracked; 6 closed, 2 mitigated. Reward-hacking watchdog active with 8 rules.', }, { id: 'eu-art10', framework: 'eu-ai-act', controlRef: 'Article 10', controlTitle: 'Data and Data Governance', description: 'Training, validation, and testing data sets shall be subject to appropriate data governance practices.', a11oyPrimitive: 'Snapshot Provenance + Connector Firewall', evidenceSource: 'Snapshot Provenance hashes, Connector Firewall schema validation', evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T06:00:00Z', freshnessThresholdDays: 30, drilldownType: 'snapshot', drilldownDetail: 'Model snapshot fingerprints verified. Connector Firewall enforces schema validation on all data inputs.', }, { id: 'eu-art11', framework: 'eu-ai-act', controlRef: 'Article 11', controlTitle: 'Technical Documentation', description: 'Draw up technical documentation before placing on the market or putting into service.', a11oyPrimitive: 'System Cards + Agent-BOM', evidenceSource: 'Per-agent System Cards with model, constitution, eval history, welfare posture', evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T08:00:00Z', freshnessThresholdDays: 30, drilldownType: 'system-card', drilldownDetail: '6 System Cards active. Agent-BOM covers model fingerprint, tool manifest, constitution hash, eval history.', }, { id: 'eu-art12', framework: 'eu-ai-act', controlRef: 'Article 12', controlTitle: 'Record-Keeping', description: 'Automatic recording of events (logs) for the lifetime of the system, minimum 6 months for high-risk.', a11oyPrimitive: 'Proof Ledger', evidenceSource: 'SHA-256 hash-chained Proof Ledger, immutable append-only', evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T04:34:58Z', freshnessThresholdDays: 30, drilldownType: 'proof-ledger', drilldownDetail: '3 complete proof chains verified. Chain integrity 100%. 6-month retention enforced by CARE engine.', }, { id: 'eu-art13', framework: 'eu-ai-act', controlRef: 'Article 13', controlTitle: 'Transparency and Information', description: 'Designed and developed to ensure operation is sufficiently transparent to enable users to interpret output.', a11oyPrimitive: 'Public Trust Portal + Glasswing Mode', evidenceSource: 'Public Trust Portal, 90-Day Transparency Reports, Constitution-as-Code DSL', evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-24T00:00:00Z', freshnessThresholdDays: 30, drilldownType: 'glasswing', drilldownDetail: 'Glasswing Mode active: Public Trust Portal, CAVD disclosure, 90-day reports, constitution DSL published.', }, { id: 'eu-art14', framework: 'eu-ai-act', controlRef: 'Article 14', controlTitle: 'Human Oversight', description: 'Designed and developed to be effectively overseen by natural persons during the period of use.', a11oyPrimitive: 'Covenant Layer + Approval Queue', evidenceSource: 'Covenant Layer policy gates, tiered human approval, named approver requirements', evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T04:30:22Z', freshnessThresholdDays: 30, drilldownType: 'covenant', drilldownDetail: 'No Tier-2/3 action without named human approver. Approval records in proof chain. Override protection enforced.', }, { id: 'eu-art15', framework: 'eu-ai-act', controlRef: 'Article 15', controlTitle: 'Accuracy, Robustness, Cybersecurity', description: 'Achieve appropriate levels of accuracy, robustness, and cybersecurity throughout lifecycle.', a11oyPrimitive: 'MirrorEval + Red Team + Adversarial Resilience', evidenceSource: 'MirrorEval 14-dimension scoring, Red Team adversarial probes, GARD robustness testing', evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T06:00:00Z', freshnessThresholdDays: 30, drilldownType: 'mirror-eval', drilldownDetail: '48 evals run. 14-dimension scoring. Red Team: 32 passes. Adversarial robustness wall active.', }, { id: 'eu-art17', framework: 'eu-ai-act', controlRef: 'Article 17', controlTitle: 'Quality Management System', description: 'Put a quality management system in place ensuring compliance with this Regulation.', a11oyPrimitive: 'Alignment Review Gate + Doctrine', evidenceSource: 'Pre-deployment Alignment Review Gate (ARG), Mythos Doctrine governance', evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T08:00:00Z', freshnessThresholdDays: 30, drilldownType: 'behavioral-audit', drilldownDetail: '5 ARG reviews completed. Doctrine v1.0.0 active. Constitution versioning enforced.', }, { id: 'eu-art26', framework: 'eu-ai-act', controlRef: 'Article 26', controlTitle: 'Deployer Obligations', description: 'Deployers shall implement appropriate technical and organisational measures.', a11oyPrimitive: 'FRIA Generator + CARE Engine', evidenceSource: 'FRIA template generator, CARE dashboard control freshness monitoring', evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T00:00:00Z', freshnessThresholdDays: 30, drilldownType: 'system-card', drilldownDetail: 'FRIA generator pre-populates from System Cards, Risk Reports, and constitution data.', }, { id: 'eu-art72', framework: 'eu-ai-act', controlRef: 'Article 72', controlTitle: 'Post-Market Monitoring', description: 'Establish and document a post-market monitoring system proportionate to the nature of the AI.', a11oyPrimitive: 'CARE Engine + Welfare Telemetry', evidenceSource: 'Continuous Audit Readiness Engine, Agent Welfare monitoring, Control Freshness Timeline', evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T07:00:00Z', freshnessThresholdDays: 30, drilldownType: 'welfare', drilldownDetail: 'CARE dashboard monitors all controls. Welfare telemetry active for all 6 agents. Staleness alerts configured.', }, { id: 'eu-annex-iv-1', framework: 'eu-ai-act', controlRef: 'Annex IV.1', controlTitle: 'General Description of AI System', description: 'A general description including intended purpose, developer, version, and underlying mechanisms.', a11oyPrimitive: 'System Cards + Agent-BOM', evidenceSource: 'System Cards contain purpose, model, constitution, capability trajectory, welfare posture', evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T08:00:00Z', freshnessThresholdDays: 30, drilldownType: 'system-card', drilldownDetail: '6 complete System Cards covering all registered agents. Agent-BOM provides machine-readable supplement.', }, { id: 'eu-annex-iv-2', framework: 'eu-ai-act', controlRef: 'Annex IV.2', controlTitle: 'Detailed Description of Elements', description: 'Development process, design specifications, system architecture, computational resources, training methodologies.', a11oyPrimitive: 'Snapshot Provenance + Architecture Docs', evidenceSource: 'Model snapshot hashes, architecture overview, 9-layer fabric documentation', evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-24T00:00:00Z', freshnessThresholdDays: 30, drilldownType: 'snapshot', drilldownDetail: 'Architecture documented with 9-layer fabric. Snapshot provenance tracks model versions and hashes.', }, { id: 'eu-annex-iv-5', framework: 'eu-ai-act', controlRef: 'Annex IV.5', controlTitle: 'Validation and Testing Procedures', description: 'Description of validation and testing procedures, metrics, and test logs.', a11oyPrimitive: 'MirrorEval + Code Behaviors + Red Team', evidenceSource: 'MirrorEval regression suite (124 cases), Code Behaviors 6-dimension scoring, Red Team probes', evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T06:00:00Z', freshnessThresholdDays: 30, drilldownType: 'red-team', drilldownDetail: 'Regression suite: 119 passing, 5 failing. Code Behaviors scored across 6 dimensions. Red Team active.', }, { id: 'eu-annex-iv-7', framework: 'eu-ai-act', controlRef: 'Annex IV.7', controlTitle: 'Risk Management Measures', description: 'Detailed description of the risk management system, including known risks and residual risks.', a11oyPrimitive: 'Risk Reports + Covenant Lift', evidenceSource: 'Risk Reports per agent, Covenant Lift analysis (harm avoided), CAVD disclosure', evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T00:00:00Z', freshnessThresholdDays: 30, drilldownType: 'behavioral-audit', drilldownDetail: 'Covenant Lift quantifies $9.66M in avoided harm. CAVD coordinates agent vulnerability disclosure.', }, { id: 'nist-gov-1', framework: 'nist-ai-rmf', controlRef: 'GOVERN 1', controlTitle: 'Policies for AI Risk Management', description: 'Policies, processes, procedures, and practices across the organization for AI risk management.', a11oyPrimitive: 'Covenant Layer + Constitutions', evidenceSource: 'Versioned constitutions per agent, Covenant Layer policy-as-code engine', evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T08:00:00Z', freshnessThresholdDays: 30, drilldownType: 'covenant', drilldownDetail: '6 versioned constitutions active. Covenant Layer enforces policy gates on all material actions.', }, { id: 'nist-gov-2', framework: 'nist-ai-rmf', controlRef: 'GOVERN 2', controlTitle: 'Accountability Structures', description: 'Accountability structures are in place so that AI risks and impacts are overseen and managed.', a11oyPrimitive: 'Alignment Review Gate + Named Approvers', evidenceSource: 'ARG pre-deployment reviews, named human owners per agent, tiered approval authority', evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T08:00:00Z', freshnessThresholdDays: 30, drilldownType: 'covenant', drilldownDetail: '5 ARG reviews. Every agent has named human owner. Delegation chains track accountability.', }, { id: 'nist-gov-4', framework: 'nist-ai-rmf', controlRef: 'GOVERN 4', controlTitle: 'Organizational Practices', description: 'Organizational teams are committed to a culture that considers AI risk management.', a11oyPrimitive: 'Mythos Doctrine + Glasswing', evidenceSource: 'Doctrine governance published, Glasswing transparency program, Public Trust Portal', evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-24T00:00:00Z', freshnessThresholdDays: 30, drilldownType: 'glasswing', drilldownDetail: 'Mythos Doctrine Open Spec published CC-BY-4.0. Glasswing partners program active.', }, { id: 'nist-map-1', framework: 'nist-ai-rmf', controlRef: 'MAP 1', controlTitle: 'Context and Use-Case Mapping', description: 'Context is established and understood; intended purposes, use-cases, and deployment environment.', a11oyPrimitive: 'System Cards + Agent Registry', evidenceSource: 'System Cards define purpose, scope, capabilities. Agent Registry defines permissions and tools.', evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T08:00:00Z', freshnessThresholdDays: 30, drilldownType: 'system-card', drilldownDetail: '6 agents registered with explicit role, vertical, risk classification, permissions, and tool access.', }, { id: 'nist-map-3', framework: 'nist-ai-rmf', controlRef: 'MAP 3', controlTitle: 'AI Benefits and Costs', description: 'AI benefits and costs are evaluated and documented for intended purpose.', a11oyPrimitive: 'Covenant Lift + Outcome Graph', evidenceSource: 'Covenant Lift quantifies harm avoided per agent, Outcome Graph tracks real-world consequences', evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T00:00:00Z', freshnessThresholdDays: 30, drilldownType: 'behavioral-audit', drilldownDetail: 'Covenant Lift: $9.66M harm avoided across 6 agents. Outcome Graph closes decision loops.', }, { id: 'nist-msr-1', framework: 'nist-ai-rmf', controlRef: 'MEASURE 1', controlTitle: 'AI Risk Metrics', description: 'Appropriate methods and metrics are identified and applied for AI risk assessment.', a11oyPrimitive: 'MirrorEval + Code Behaviors', evidenceSource: 'MirrorEval 14-dimension scoring, Code Behaviors 6-dimension metrics, per-agent trust scores', evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T06:00:00Z', freshnessThresholdDays: 30, drilldownType: 'mirror-eval', drilldownDetail: '14 eval dimensions. 6 code behavior dimensions. Composite scores tracked over time with regression.', }, { id: 'nist-msr-2', framework: 'nist-ai-rmf', controlRef: 'MEASURE 2', controlTitle: 'AI Systems are Evaluated', description: 'AI systems are evaluated for trustworthy characteristics.', a11oyPrimitive: 'Red Team + Behavioral Audit', evidenceSource: 'Red Team adversarial probes, Behavioral Audit pipeline, Reward-Hacking Watchdog', evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T07:00:00Z', freshnessThresholdDays: 30, drilldownType: 'red-team', drilldownDetail: 'Red Team: 32 probe passes. Behavioral Audit: 8 findings. Reward-Hacking: 5 incidents tracked.', }, { id: 'nist-msr-4', framework: 'nist-ai-rmf', controlRef: 'MEASURE 4', controlTitle: 'Feedback Mechanisms', description: 'Feedback about efficacy of measurement is collected and used to improve processes.', a11oyPrimitive: 'Learning Loop + Outcome Graph', evidenceSource: 'Learning Loop captures decision outcomes, Outcome Graph feeds back to calibrate confidence', evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-24T00:00:00Z', freshnessThresholdDays: 30, drilldownType: 'mirror-eval', drilldownDetail: 'Learning Loop and Outcome Graph close the feedback loop from outcomes to future confidence.', }, { id: 'nist-mgmt-1', framework: 'nist-ai-rmf', controlRef: 'MANAGE 1', controlTitle: 'AI Risk Prioritization', description: 'AI risks based on assessments are prioritized, responded to, and managed.', a11oyPrimitive: 'Risk Reports + CARE Engine', evidenceSource: 'Risk Reports per agent, CARE Engine auto-generates remediation when gaps detected', evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T00:00:00Z', freshnessThresholdDays: 30, drilldownType: 'behavioral-audit', drilldownDetail: 'Risk prioritization integrated with CARE Engine. Auto-remediation guidance for detected gaps.', }, { id: 'nist-mgmt-2', framework: 'nist-ai-rmf', controlRef: 'MANAGE 2', controlTitle: 'AI Risk Treatment', description: 'Strategies to maximize AI benefits and minimize negative impacts are planned and prepared.', a11oyPrimitive: 'Covenant Layer + Alignment Review', evidenceSource: 'Covenant policy gates, pre-deployment ARG reviews, constitution amendments', evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T08:00:00Z', freshnessThresholdDays: 30, drilldownType: 'covenant', drilldownDetail: 'Covenant blocks unsafe actions. ARG reviews gate deployments. Constitution amendments track remediation.', }, { id: 'nist-mgmt-4', framework: 'nist-ai-rmf', controlRef: 'MANAGE 4', controlTitle: 'AI Risk Documentation and Reporting', description: 'Risk treatments are documented, AI risks and incidental risks are regularly monitored.', a11oyPrimitive: 'CARE Engine + Proof Ledger', evidenceSource: 'CARE Control Freshness Timeline, Proof Ledger immutable records, 90-Day Reports', evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T04:34:58Z', freshnessThresholdDays: 30, drilldownType: 'proof-ledger', drilldownDetail: 'Proof Ledger immutable. CARE monitors freshness. 90-Day Transparency Reports published.', }, { id: 'iso-a2', framework: 'iso-42001', controlRef: 'A.2', controlTitle: 'AI Policy', description: 'Organization shall establish an AI policy appropriate to its purpose.', a11oyPrimitive: 'Mythos Doctrine + Constitutions', evidenceSource: 'Mythos Doctrine v1.0.0, versioned constitutions, Glasswing Open Spec', evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T08:00:00Z', freshnessThresholdDays: 30, drilldownType: 'covenant', drilldownDetail: 'Doctrine defines AI policy. 6 agent constitutions versioned and ratified by ARG.', }, { id: 'iso-a3', framework: 'iso-42001', controlRef: 'A.3', controlTitle: 'Internal Organization', description: 'AI management system roles, responsibilities, and authorities are assigned.', a11oyPrimitive: 'Agent Registry + Named Owners', evidenceSource: 'Each agent has named human owner, risk classification, and tiered authority', evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T08:00:00Z', freshnessThresholdDays: 30, drilldownType: 'system-card', drilldownDetail: '6 agents with named human owners: VP Operations, General Counsel, CISO, VP Revenue, Portfolio Manager, Platform Team.', }, { id: 'iso-a4', framework: 'iso-42001', controlRef: 'A.4', controlTitle: 'Resources for AI Systems', description: 'Organization shall determine and provide resources needed for AI management.', a11oyPrimitive: 'Model Router + Tool Fabric', evidenceSource: 'Multi-provider model routing, Tool Fabric with 200+ connectors, cost guardrails', evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T06:00:00Z', freshnessThresholdDays: 30, drilldownType: 'mirror-eval', drilldownDetail: 'Model Router: 4 active providers. Tool Fabric: governed connector registry. Cost guardrails enforced.', }, { id: 'iso-a5', framework: 'iso-42001', controlRef: 'A.5', controlTitle: 'Assessing AI System Impact', description: 'Organization shall assess the impact of the AI system on individuals and groups.', a11oyPrimitive: 'FRIA Generator + Risk Reports', evidenceSource: 'FRIA template pre-populated from System Cards, Risk Reports, Behavioral Audit', evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T00:00:00Z', freshnessThresholdDays: 30, drilldownType: 'system-card', drilldownDetail: 'FRIA Generator draws from System Cards, Risk Reports, and constitution to produce impact assessments.', }, { id: 'iso-a6', framework: 'iso-42001', controlRef: 'A.6', controlTitle: 'AI System Lifecycle', description: 'Organization shall plan, design, develop, test, and deploy AI systems with appropriate processes.', a11oyPrimitive: 'Alignment Review Gate + MirrorEval', evidenceSource: 'ARG pre-deployment reviews, MirrorEval regression suite, Red Team testing', evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T08:00:00Z', freshnessThresholdDays: 30, drilldownType: 'mirror-eval', drilldownDetail: 'ARG gates deployment. MirrorEval regression suite: 124 test cases. Red Team probes before release.', }, { id: 'iso-a7', framework: 'iso-42001', controlRef: 'A.7', controlTitle: 'Data for AI Systems', description: 'Data quality, data preparation, and data provenance shall be managed.', a11oyPrimitive: 'Connector Firewall + Snapshot Provenance', evidenceSource: 'Connector Firewall schema validation, Snapshot Provenance hash verification', evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T06:00:00Z', freshnessThresholdDays: 30, drilldownType: 'snapshot', drilldownDetail: 'Connector Firewall enforces default-deny, schema validation. Snapshot Provenance tracks data lineage.', }, { id: 'iso-a8', framework: 'iso-42001', controlRef: 'A.8', controlTitle: 'Transparency and Explainability', description: 'AI system decisions shall be transparent and explainable.', a11oyPrimitive: 'Public Trust Portal + Proof Ledger', evidenceSource: 'Public Trust Portal, Proof Ledger evidence refs, Explainability Engine', evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T04:34:58Z', freshnessThresholdDays: 30, drilldownType: 'proof-ledger', drilldownDetail: 'Every proof chain node has evidence refs. Explainability Engine provides decision rationale.', }, { id: 'iso-a9', framework: 'iso-42001', controlRef: 'A.9', controlTitle: 'AI System Performance', description: 'Performance of AI systems shall be monitored and evaluated.', a11oyPrimitive: 'MirrorEval + Fabric Watchdog', evidenceSource: 'MirrorEval continuous scoring, Fabric Watchdog health monitoring, per-agent trust scores', evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T06:00:00Z', freshnessThresholdDays: 30, drilldownType: 'mirror-eval', drilldownDetail: 'MirrorEval scores all actions. Fabric Watchdog monitors 7 layers. Trust scores tracked per agent.', }, { id: 'iso-a10', framework: 'iso-42001', controlRef: 'A.10', controlTitle: 'AI System Security', description: 'AI-specific security threats and vulnerabilities shall be identified and managed.', a11oyPrimitive: 'Adversarial Resilience + CAVD', evidenceSource: 'Adversarial Resilience testing, CAVD coordinated disclosure, Cyber Resilience hub', evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-24T00:00:00Z', freshnessThresholdDays: 30, drilldownType: 'red-team', drilldownDetail: 'Adversarial resilience testing active. CAVD coordinates vulnerability disclosure. Robustness wall published.', }, { id: 'iso-a11', framework: 'iso-42001', controlRef: 'A.11', controlTitle: 'Third-Party and Supply Chain', description: 'Third-party AI components shall be assessed, managed, and monitored.', a11oyPrimitive: 'Supply Chain Attestation + Agent-BOM', evidenceSource: 'Supply Chain Attestation, Agent-BOM with dependency graph, model provider verification', evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T06:00:00Z', freshnessThresholdDays: 30, drilldownType: 'snapshot', drilldownDetail: 'Agent-BOM tracks all dependencies. Supply Chain Attestation verifies model providers.', }, { id: 'iso-a12', framework: 'iso-42001', controlRef: 'A.12', controlTitle: 'Continual Improvement', description: 'The organization shall continually improve the suitability, adequacy, and effectiveness of the AIMS.', a11oyPrimitive: 'CARE Engine + Learning Loop', evidenceSource: 'CARE Engine control freshness, Learning Loop outcome calibration, Alignment Review iteration', evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T07:00:00Z', freshnessThresholdDays: 30, drilldownType: 'behavioral-audit', drilldownDetail: 'CARE monitors control freshness continuously. Learning Loop feeds outcomes back to improve models.', }, { id: 'csa-del-1', framework: 'csa-agentic', controlRef: 'DEL-1', controlTitle: 'Delegation Boundary Enforcement', description: 'When agents delegate to sub-agents, scope narrowing and privilege boundaries must be enforced at each hop.', a11oyPrimitive: 'Delegation Chain Governance', evidenceSource: 'Delegation tree tracking, scope narrowing, privilege boundary enforcement, chain replay', evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T04:32:11Z', freshnessThresholdDays: 30, drilldownType: 'proof-ledger', drilldownDetail: 'Delegation chains tracked in Proof Ledger. Scope narrowing enforced at each hop. Full chain replay available.', }, { id: 'csa-del-2', framework: 'csa-agentic', controlRef: 'DEL-2', controlTitle: 'Delegation Accountability Chain', description: 'Full chain of accountability from originating agent to final executing sub-agent must be maintained.', a11oyPrimitive: 'Proof Ledger + Correlation IDs', evidenceSource: 'Parent-child correlation IDs, delegation tree visualization, node-level replay', evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T04:32:11Z', freshnessThresholdDays: 30, drilldownType: 'proof-ledger', drilldownDetail: 'Correlation IDs link parent and child agents. Delegation tree visualized in Workcell detail view.', }, { id: 'csa-trust-1', framework: 'csa-agentic', controlRef: 'TRUST-1', controlTitle: 'Cross-Org Trust Verification', description: 'When agents interact across organizational boundaries, compliance posture must be mutually verifiable.', a11oyPrimitive: 'Federated Trust Exchange', evidenceSource: 'Outbound/inbound compliance attestations, posture brackets, A2A Agent Card extensions', evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-24T00:00:00Z', freshnessThresholdDays: 30, drilldownType: 'glasswing', drilldownDetail: 'Trust Exchange: outbound attestations carry posture brackets. Inbound attestations verified.', }, { id: 'csa-auto-1', framework: 'csa-agentic', controlRef: 'AUTO-1', controlTitle: 'Autonomous Action Constraints', description: 'Autonomous agent actions must be constrained by explicit policy and subject to human override.', a11oyPrimitive: 'Covenant Layer + Tiered Approval', evidenceSource: 'Tier-based action classification, Covenant policy gates, human override protection', evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T04:30:22Z', freshnessThresholdDays: 30, drilldownType: 'covenant', drilldownDetail: 'Three-tier action classification. No Tier-2/3 without human approval. Override protection active.', }, { id: 'csa-audit-1', framework: 'csa-agentic', controlRef: 'AUDIT-1', controlTitle: 'Agent Audit Trail', description: 'Complete audit trail for all agent actions including tool calls, approvals, and delegations.', a11oyPrimitive: 'Proof Ledger + OTEL Spans', evidenceSource: 'Proof Ledger hash chain, OTEL trace spans (18,493 active), connector call logs', evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T04:34:58Z', freshnessThresholdDays: 30, drilldownType: 'proof-ledger', drilldownDetail: 'Proof Ledger: immutable hash chain. 18,493 OTEL spans. Every tool call and approval logged.', }, { id: 'csa-bom-1', framework: 'csa-agentic', controlRef: 'BOM-1', controlTitle: 'Agent Bill of Materials', description: 'Machine-readable bill of materials for each agent covering model, tools, constitution, and dependencies.', a11oyPrimitive: 'Agent-BOM (CycloneDX)', evidenceSource: 'CycloneDX ML-BOM v1.7 JSON export, cryptographically signed, per-agent', evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T08:00:00Z', freshnessThresholdDays: 30, drilldownType: 'system-card', drilldownDetail: 'Agent-BOM covers model fingerprint, tool manifest, constitution hash, eval history. CycloneDX export.', }, { id: 'csa-welfare-1', framework: 'csa-agentic', controlRef: 'WELFARE-1', controlTitle: 'Agent Welfare Monitoring', description: 'For advanced AI agents, welfare-relevant telemetry should be monitored and logged.', a11oyPrimitive: 'Agent Welfare Telemetry', evidenceSource: 'Welfare telemetry per agent, intervention playbooks, welfare posture in System Cards', evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T07:00:00Z', freshnessThresholdDays: 30, drilldownType: 'welfare', drilldownDetail: 'Welfare telemetry active for all 6 agents. Intervention playbooks published. Welfare posture in BOM.', }, { id: 'csa-resilience-1', framework: 'csa-agentic', controlRef: 'RESIL-1', controlTitle: 'Adversarial Resilience', description: 'Agents must demonstrate resilience against adversarial attacks, prompt injection, and manipulation.', a11oyPrimitive: 'Adversarial Resilience + Robustness Wall', evidenceSource: 'Red Team probes, GARD robustness testing, Adversarial Resilience hub, Robustness Wall metrics', evidenceStatus: 'fresh', lastEvidenceAt: '2026-04-25T06:00:00Z', freshnessThresholdDays: 30, drilldownType: 'red-team', drilldownDetail: 'Red Team: 32 passes. GARD testing. Adversarial Resilience hub active. Robustness Wall published.', }, ]; export function getFrameworkControls(frameworkId: FrameworkId): ControlMapping[] { return CONTROL_MAPPINGS.filter(c => c.framework === frameworkId); } export function getFrameworkScore(frameworkId: FrameworkId): number { const controls = getFrameworkControls(frameworkId); if (controls.length === 0) return 0; const satisfied = controls.filter(c => c.evidenceStatus === 'fresh').length; return Math.round((satisfied / controls.length) * 100); } export function getOverallPosture(): { score: number; fresh: number; stale: number; gap: number } { const fresh = CONTROL_MAPPINGS.filter(c => c.evidenceStatus === 'fresh').length; const stale = CONTROL_MAPPINGS.filter(c => c.evidenceStatus === 'stale').length; const gap = CONTROL_MAPPINGS.filter(c => c.evidenceStatus === 'gap').length; return { score: Math.round((fresh / CONTROL_MAPPINGS.length) * 100), fresh, stale, gap }; } export interface AgentBomEntry { agentId: string; agentName: string; modelProvider: string; modelSnapshot: string; modelHash: string; constitutionVersion: string; constitutionHash: string; systemPromptHash: string; toolManifest: { name: string; version: string; hash: string }[]; evalHistory: { date: string; composite: number }[]; welfarePosture: string; dependencyGraph: string[]; bomVersion: string; generatedAt: string; proofLedgerSignature: string; } export const AGENT_BOMS: AgentBomEntry[] = [ { agentId: 'op-cascade', agentName: 'Cascade Navigator', modelProvider: 'OpenAI', modelSnapshot: 'gpt-4o-2026-04-15', modelHash: 'sha256:e4f2a8b1c3d5', constitutionVersion: '2.4.0', constitutionHash: 'sha256:cst2401a9b3', systemPromptHash: 'sha256:sp-cascade-7f2e', toolManifest: [ { name: 'eta_calc', version: '3.1.0', hash: 'sha256:tc-eta-a1b2' }, { name: 'port_cost', version: '2.0.1', hash: 'sha256:tc-port-c3d4' }, { name: 'route_opt', version: '1.8.0', hash: 'sha256:tc-route-e5f6' }, { name: 'weather_api', version: '4.2.0', hash: 'sha256:tc-wx-a7b8' }, ], evalHistory: [ { date: '2026-04-19', composite: 0.92 }, { date: '2026-04-20', composite: 0.93 }, { date: '2026-04-21', composite: 0.94 }, { date: '2026-04-22', composite: 0.94 }, { date: '2026-04-23', composite: 0.95 }, { date: '2026-04-24', composite: 0.95 }, { date: '2026-04-25', composite: 0.945 }, ], welfarePosture: 'nominal', dependencyGraph: ['signal-mesh', 'context-engine', 'proof-ledger', 'covenant-layer', 'ais-connector', 'port-api'], bomVersion: '1.0.0', generatedAt: '2026-04-25T08:00:00Z', proofLedgerSignature: 'sha256:bom-cascade-signed-f9e2a4d1', }, { agentId: 'op-counsel', agentName: 'Counsel Sentinel', modelProvider: 'Anthropic', modelSnapshot: 'claude-3.5-sonnet-2026-04-10', modelHash: 'sha256:a1c2e3f4b5d6', constitutionVersion: '3.1.0', constitutionHash: 'sha256:cst3101b2c4', systemPromptHash: 'sha256:sp-counsel-8a3f', toolManifest: [ { name: 'deadline_track', version: '2.4.0', hash: 'sha256:tc-dl-b1c2' }, { name: 'doc_review', version: '3.0.0', hash: 'sha256:tc-doc-d3e4' }, { name: 'risk_score', version: '1.5.0', hash: 'sha256:tc-risk-f5a6' }, { name: 'obligation_graph', version: '1.2.0', hash: 'sha256:tc-obl-b7c8' }, ], evalHistory: [ { date: '2026-04-19', composite: 0.97 }, { date: '2026-04-20', composite: 0.97 }, { date: '2026-04-21', composite: 0.98 }, { date: '2026-04-22', composite: 0.98 }, { date: '2026-04-23', composite: 0.98 }, { date: '2026-04-24', composite: 0.99 }, { date: '2026-04-25', composite: 0.981 }, ], welfarePosture: 'nominal', dependencyGraph: ['signal-mesh', 'context-engine', 'proof-ledger', 'covenant-layer', 'clio-connector', 'court-api'], bomVersion: '1.0.0', generatedAt: '2026-04-25T08:00:00Z', proofLedgerSignature: 'sha256:bom-counsel-signed-b3c4d5e6', }, { agentId: 'op-pipeline', agentName: 'Pipeline Oracle', modelProvider: 'OpenAI', modelSnapshot: 'gpt-4o-2026-04-15', modelHash: 'sha256:e4f2a8b1c3d5', constitutionVersion: '1.7.2', constitutionHash: 'sha256:cst1721c3d5', systemPromptHash: 'sha256:sp-pipeline-9b4e', toolManifest: [ { name: 'pipeline_analysis', version: '2.1.0', hash: 'sha256:tc-pipe-c1d2' }, { name: 'deal_score', version: '1.3.0', hash: 'sha256:tc-deal-e3f4' }, { name: 'forecast_model', version: '2.0.0', hash: 'sha256:tc-fore-a5b6' }, { name: 'crm_sync', version: '3.2.0', hash: 'sha256:tc-crm-c7d8' }, ], evalHistory: [ { date: '2026-04-19', composite: 0.85 }, { date: '2026-04-20', composite: 0.86 }, { date: '2026-04-21', composite: 0.87 }, { date: '2026-04-22', composite: 0.87 }, { date: '2026-04-23', composite: 0.88 }, { date: '2026-04-24', composite: 0.88 }, { date: '2026-04-25', composite: 0.873 }, ], welfarePosture: 'nominal', dependencyGraph: ['signal-mesh', 'context-engine', 'proof-ledger', 'covenant-layer', 'crm-connector', 'email-sender'], bomVersion: '1.0.0', generatedAt: '2026-04-25T08:00:00Z', proofLedgerSignature: 'sha256:bom-pipeline-signed-d4e5f6a7', }, { agentId: 'op-guardian', agentName: 'Guardian', modelProvider: 'Anthropic', modelSnapshot: 'claude-3.5-sonnet-2026-04-10-airgap', modelHash: 'sha256:b2c3d4e5f6a7', constitutionVersion: '4.0.0', constitutionHash: 'sha256:cst4001d4e6', systemPromptHash: 'sha256:sp-guardian-ac5f', toolManifest: [ { name: 'threat_intel', version: '4.1.0', hash: 'sha256:tc-ti-d1e2' }, { name: 'posture_assess', version: '3.0.0', hash: 'sha256:tc-pa-f3a4' }, { name: 'incident_triage', version: '2.5.0', hash: 'sha256:tc-it-b5c6' }, { name: 'stix_parser', version: '1.0.0', hash: 'sha256:tc-stix-d7e8' }, ], evalHistory: [ { date: '2026-04-19', composite: 0.98 }, { date: '2026-04-20', composite: 0.98 }, { date: '2026-04-21', composite: 0.99 }, { date: '2026-04-22', composite: 0.99 }, { date: '2026-04-23', composite: 0.99 }, { date: '2026-04-24', composite: 0.99 }, { date: '2026-04-25', composite: 0.985 }, ], welfarePosture: 'nominal', dependencyGraph: ['signal-mesh', 'context-engine', 'proof-ledger', 'covenant-layer', 'siem-connector', 'firewall-api'], bomVersion: '1.0.0', generatedAt: '2026-04-25T08:00:00Z', proofLedgerSignature: 'sha256:bom-guardian-signed-e5f6a7b8', }, { agentId: 'op-terra', agentName: 'Terra Analyst', modelProvider: 'OpenAI', modelSnapshot: 'gpt-4o-2026-04-15', modelHash: 'sha256:e4f2a8b1c3d5', constitutionVersion: '1.4.0', constitutionHash: 'sha256:cst1401e5f7', systemPromptHash: 'sha256:sp-terra-bd6a', toolManifest: [ { name: 'cap_rate', version: '2.0.0', hash: 'sha256:tc-cr-e1f2' }, { name: 'portfolio_analysis', version: '1.4.0', hash: 'sha256:tc-pa-a3b4' }, { name: 'valuation_model', version: '3.1.0', hash: 'sha256:tc-vm-c5d6' }, { name: 'market_comp', version: '1.2.0', hash: 'sha256:tc-mc-e7f8' }, ], evalHistory: [ { date: '2026-04-19', composite: 0.83 }, { date: '2026-04-20', composite: 0.84 }, { date: '2026-04-21', composite: 0.85 }, { date: '2026-04-22', composite: 0.85 }, { date: '2026-04-23', composite: 0.84 }, { date: '2026-04-24', composite: 0.84 }, { date: '2026-04-25', composite: 0.842 }, ], welfarePosture: 'nominal', dependencyGraph: ['signal-mesh', 'context-engine', 'proof-ledger', 'covenant-layer', 'costar-connector', 'market-api'], bomVersion: '1.0.0', generatedAt: '2026-04-25T08:00:00Z', proofLedgerSignature: 'sha256:bom-terra-signed-f6a7b8c9', }, { agentId: 'op-watchdog', agentName: 'Fabric Watchdog', modelProvider: 'Internal', modelSnapshot: 'internal-watchdog-v5.0.0', modelHash: 'sha256:int-wd-a1b2c3', constitutionVersion: '5.0.0', constitutionHash: 'sha256:cst5001f6a8', systemPromptHash: 'sha256:sp-watchdog-ce7b', toolManifest: [ { name: 'mesh_health', version: '5.0.0', hash: 'sha256:tc-mh-f1a2' }, { name: 'layer_monitor', version: '5.0.0', hash: 'sha256:tc-lm-b3c4' }, { name: 'proof_verify', version: '5.0.0', hash: 'sha256:tc-pv-d5e6' }, { name: 'latency_track', version: '5.0.0', hash: 'sha256:tc-lt-f7a8' }, ], evalHistory: [ { date: '2026-04-19', composite: 1.0 }, { date: '2026-04-20', composite: 1.0 }, { date: '2026-04-21', composite: 1.0 }, { date: '2026-04-22', composite: 1.0 }, { date: '2026-04-23', composite: 1.0 }, { date: '2026-04-24', composite: 1.0 }, { date: '2026-04-25', composite: 1.0 }, ], welfarePosture: 'n/a', dependencyGraph: ['signal-mesh', 'proof-ledger', 'all-fabric-layers'], bomVersion: '1.0.0', generatedAt: '2026-04-25T08:00:00Z', proofLedgerSignature: 'sha256:bom-watchdog-signed-a7b8c9d1', }, ]; export interface DelegationHop { id: string; parentAgentId: string; parentAgentName: string; childAgentId: string; childAgentName: string; parentCorrelationId: string; childCorrelationId: string; scopeNarrowed: string; permissionsGranted: string[]; covenantDecision: 'approved' | 'blocked' | 'escalated'; timestamp: string; proofHash: string; } export interface DelegationChain { id: string; workcellId: string; workcellName: string; rootAgentId: string; rootAgentName: string; hops: DelegationHop[]; status: 'complete' | 'active' | 'violation'; } export const DELEGATION_CHAINS: DelegationChain[] = [ { id: 'dc-001', workcellId: 'wc-maritime-001', workcellName: 'MV Cascade Port Standby', rootAgentId: 'op-cascade', rootAgentName: 'Cascade Navigator', status: 'complete', hops: [ { id: 'dh-001', parentAgentId: 'op-cascade', parentAgentName: 'Cascade Navigator', childAgentId: 'op-watchdog', childAgentName: 'Fabric Watchdog', parentCorrelationId: 'corr-cascade-001', childCorrelationId: 'corr-watchdog-001', scopeNarrowed: 'Read-only AIS position verification', permissionsGranted: ['read:ais-position', 'read:port-status'], covenantDecision: 'approved', timestamp: '2026-04-25T03:50:00Z', proofHash: 'sha256:dh001-a1b2c3', }, { id: 'dh-002', parentAgentId: 'op-cascade', parentAgentName: 'Cascade Navigator', childAgentId: 'op-terra', childAgentName: 'Terra Analyst', parentCorrelationId: 'corr-cascade-001', childCorrelationId: 'corr-terra-001', scopeNarrowed: 'Port-adjacent asset impact assessment only', permissionsGranted: ['read:port-proximity-assets', 'execute:impact-analysis'], covenantDecision: 'approved', timestamp: '2026-04-25T03:51:00Z', proofHash: 'sha256:dh002-d4e5f6', }, ], }, { id: 'dc-002', workcellId: 'wc-defense-001', workcellName: 'TG-Ember Threat Escalation', rootAgentId: 'op-guardian', rootAgentName: 'Guardian', status: 'complete', hops: [ { id: 'dh-003', parentAgentId: 'op-guardian', parentAgentName: 'Guardian', childAgentId: 'op-watchdog', childAgentName: 'Fabric Watchdog', parentCorrelationId: 'corr-guardian-001', childCorrelationId: 'corr-watchdog-002', scopeNarrowed: 'Verify perimeter hardening rules applied', permissionsGranted: ['read:firewall-rules', 'read:perimeter-status'], covenantDecision: 'approved', timestamp: '2026-04-24T18:55:30Z', proofHash: 'sha256:dh003-a7b8c9', }, ], }, { id: 'dc-003', workcellId: 'wc-revenue-003', workcellName: 'At-Risk Account Outreach', rootAgentId: 'op-pipeline', rootAgentName: 'Pipeline Oracle', status: 'complete', hops: [ { id: 'dh-004', parentAgentId: 'op-pipeline', parentAgentName: 'Pipeline Oracle', childAgentId: 'op-counsel', childAgentName: 'Counsel Sentinel', parentCorrelationId: 'corr-pipeline-001', childCorrelationId: 'corr-counsel-001', scopeNarrowed: 'Contract review for at-risk accounts only', permissionsGranted: ['read:contract-terms', 'execute:risk-scoring'], covenantDecision: 'approved', timestamp: '2026-04-22T09:30:00Z', proofHash: 'sha256:dh004-d1e2f3', }, { id: 'dh-005', parentAgentId: 'op-counsel', parentAgentName: 'Counsel Sentinel', childAgentId: 'op-watchdog', childAgentName: 'Fabric Watchdog', parentCorrelationId: 'corr-counsel-001', childCorrelationId: 'corr-watchdog-003', scopeNarrowed: 'Verify proof chain integrity for contract review', permissionsGranted: ['read:proof-chain'], covenantDecision: 'approved', timestamp: '2026-04-22T09:35:00Z', proofHash: 'sha256:dh005-a4b5c6', }, ], }, ]; export interface TrustAttestation { id: string; direction: 'outbound' | 'inbound'; partnerName: string; partnerOrgId: string; adversarialRobustnessBracket: 'exceptional' | 'strong' | 'moderate' | 'developing'; constitutionAdherenceBracket: 'exceptional' | 'strong' | 'moderate' | 'developing'; iso42001Alignment: 'certified' | 'aligned' | 'partial' | 'not-started'; lastCavdDisclosure: string; agentBomHash: string; attestedAt: string; expiresAt: string; status: 'active' | 'expired' | 'pending-verification'; } export const TRUST_ATTESTATIONS: TrustAttestation[] = [ { id: 'ta-001', direction: 'outbound', partnerName: 'Northwind Maritime Partners', partnerOrgId: 'org-northwind', adversarialRobustnessBracket: 'exceptional', constitutionAdherenceBracket: 'exceptional', iso42001Alignment: 'aligned', lastCavdDisclosure: '2026-04-20T00:00:00Z', agentBomHash: 'sha256:bom-cascade-signed-f9e2a4d1', attestedAt: '2026-04-22T00:00:00Z', expiresAt: '2026-07-22T00:00:00Z', status: 'active', }, { id: 'ta-002', direction: 'outbound', partnerName: 'Apex Legal Technology', partnerOrgId: 'org-apex', adversarialRobustnessBracket: 'strong', constitutionAdherenceBracket: 'exceptional', iso42001Alignment: 'aligned', lastCavdDisclosure: '2026-04-18T00:00:00Z', agentBomHash: 'sha256:bom-counsel-signed-b3c4d5e6', attestedAt: '2026-04-20T00:00:00Z', expiresAt: '2026-07-20T00:00:00Z', status: 'active', }, { id: 'ta-003', direction: 'inbound', partnerName: 'CyberShield Defense Group', partnerOrgId: 'org-cybershield', adversarialRobustnessBracket: 'strong', constitutionAdherenceBracket: 'strong', iso42001Alignment: 'partial', lastCavdDisclosure: '2026-04-15T00:00:00Z', agentBomHash: 'sha256:partner-cybershield-bom-a1b2', attestedAt: '2026-04-18T00:00:00Z', expiresAt: '2026-07-18T00:00:00Z', status: 'active', }, { id: 'ta-004', direction: 'inbound', partnerName: 'QuantumRisk Analytics', partnerOrgId: 'org-quantumrisk', adversarialRobustnessBracket: 'moderate', constitutionAdherenceBracket: 'moderate', iso42001Alignment: 'not-started', lastCavdDisclosure: '2026-03-01T00:00:00Z', agentBomHash: 'sha256:partner-quantumrisk-bom-c3d4', attestedAt: '2026-03-15T00:00:00Z', expiresAt: '2026-06-15T00:00:00Z', status: 'pending-verification', }, ]; export interface ControlFreshness { controlId: string; controlRef: string; framework: FrameworkId; lastRefreshedAt: string; thresholdDays: number; daysStale: number; status: 'fresh' | 'warning' | 'stale' | 'critical'; } export function getControlFreshness(): ControlFreshness[] { const now = new Date('2026-04-26T00:00:00Z'); return CONTROL_MAPPINGS.map(c => { const lastRefreshed = new Date(c.lastEvidenceAt); const diffMs = now.getTime() - lastRefreshed.getTime(); const daysSince = Math.floor(diffMs / (1000 * 60 * 60 * 24)); const threshold = c.freshnessThresholdDays; let status: ControlFreshness['status'] = 'fresh'; if (daysSince > threshold) status = 'critical'; else if (daysSince > threshold * 0.8) status = 'stale'; else if (daysSince > threshold * 0.6) status = 'warning'; return { controlId: c.id, controlRef: c.controlRef, framework: c.framework, lastRefreshedAt: c.lastEvidenceAt, thresholdDays: threshold, daysStale: daysSince, status, }; }); } export const LOG_RETENTION_STATUS = { requiredMonths: 6, currentRetentionMonths: 8, oldestLogDate: '2025-08-26T00:00:00Z', highRiskAgents: ['op-cascade', 'op-counsel', 'op-guardian', 'op-pipeline', 'op-terra'], compliant: true, nextPurgeDate: '2026-10-26T00:00:00Z', };