Approach — our framework
Chain of Intent
Governance frameworks usually list controls. Ours lists failures, because a firm recognises a failure it has seen more readily than a control it has not.
Five failure modes, grouped into three stages.
Intention
Purpose, Permission
Is there an approved purpose, and are the permissions bounded to it?
Execution
Practice, Proof
What is actually happening day to day, and can you prove it afterwards?
Persistence
Persistence
Does it still do what it was approved to do, six months later?
Five things you already do for a new hire
What a new hire gets
- PurposeA job description
- PermissionA pass to the parts of the building they need
- PracticeYou can see what they do at their desk
- ProofEmails, tickets, files — a paper trail
- PersistenceA six-month review
What an AI agent gets
- PurposeUsually nothing written down
- PermissionWhatever the integration happened to grant
- PracticeNobody is watching
- ProofOften no log at all
- PersistenceNever revisited
You do all five for a person you pay a salary. Most firms have done none of them for a system that touches the entire client database and works at three in the morning.
We tested the framework against the failure it was built to address.Read the research