Agent risk and ATF Control Tower
Agent Risk Tiering prioritises governance based on capability, access, autonomy and potential impact. ATF Control Tower brings together per-agent maturity, control evidence and operational signals. Neither view grants runtime access.
Risk tiering
Section titled “Risk tiering”Assess the actual deployment, not the agent’s intended personality or job title. Consider tool and data reach, independence, delegation, persistence, external communication, reversibility, privilege, scale and affected people. Record evidence and uncertainty for each judgement.
Use the resulting tier to set approval, testing, monitoring, review and escalation depth. Do not lower the tier merely because controls are planned; evaluate residual exposure after tested controls separately.
ATF Control Tower
Section titled “ATF Control Tower”Use the Control Tower to identify agents below target maturity, stale evidence, failed promotion gates, overdue reviews, incidents and runtime-control weaknesses. Drill into the agent and requirement before assigning remediation.
ATF readiness is per agent. Portfolio averages can hide one highly privileged unready agent. Promotion requires the evidence and elapsed operating experience specified by the assessment, plus human confirmation.
Decision use
Section titled “Decision use”Combine risk tier, ATF result, MAESTRO threats, runtime tests, incidents, open findings and policy scope. Record the human decision and reassessment trigger. A green dashboard is not permission to operate without the exact runtime authority chain.