Approach — our framework

Chain of Intent

Governance frameworks usually list controls. Ours lists failures, because a firm recognises a failure it has seen more readily than a control it has not.

Five failure modes, grouped into three stages.

Intention

Purpose, Permission

Is there an approved purpose, and are the permissions bounded to it?

Execution

Practice, Proof

What is actually happening day to day, and can you prove it afterwards?

Persistence

Persistence

Does it still do what it was approved to do, six months later?

Five things you already do for a new hire

What a new hire gets

  • PurposeA job description
  • PermissionA pass to the parts of the building they need
  • PracticeYou can see what they do at their desk
  • ProofEmails, tickets, files — a paper trail
  • PersistenceA six-month review

What an AI agent gets

  • PurposeUsually nothing written down
  • PermissionWhatever the integration happened to grant
  • PracticeNobody is watching
  • ProofOften no log at all
  • PersistenceNever revisited

You do all five for a person you pay a salary. Most firms have done none of them for a system that touches the entire client database and works at three in the morning.

We tested the framework against the failure it was built to address.
Read the research