ACRS
ACRS, the Agentic Capability Risk Score, is Gamut’s native method for classifying the capability exposure of an AI system or agentic workflow. It asks four practical questions:
- How dependent are operations, people or decisions on the AI?
- How much can it decide or do before authoritative human approval?
- Which data, tools, identities, systems and actions can it reach?
- How serious could the credible consequences of failure, misuse or compromise become?
The answers form a four-part vector and a product score. Gamut then applies conservative severity-floor rules so a mathematically modest product cannot under-route a system with severe harm, consequential autonomy, broad access or explicit high-risk characteristics.
ACRS is not a control-compliance score. It establishes the depth of assurance the system needs. The routed result feeds the GTSAF assessment plan and informs threat modelling, approval, evidence, testing, monitoring and governance attention.
Start here
Section titled “Start here”| If you need to… | Read |
|---|---|
| Explain every score, vector, band, status and severity-floor rule | Method, scoring and terminology |
| Assess dependency, autonomy, access and harm without leaving the screen | Dimension assessor playbooks |
| Understand system boundaries and how ACRS routes GTSAF | System scope and GTSAF routing |
| Complete an ACRS assessment from intake to sign-off | Assessment workflow |
| Know what evidence to request, how to test safely and when to raise findings | Evidence, testing and findings |
| Explain what AI Assist reads, produces, secures and cannot decide | AI Assist and security |
| Explain reports, ownership, residual risk and reassessment | Reporting and governance |
| Follow a realistic assessment with severity-floor routing | Worked example |
| Look up fields, statuses, labels, formulas and assessor language | Reference and glossary |
ACRS at a glance
Section titled “ACRS at a glance”| Property | Gamut implementation |
|---|---|
| Methodology | Versioned Gamut-native capability-risk method |
| Primary assessment level | One selected AI system intake |
| Dimensions | 4 |
| Dimension levels | Low = 1, Medium = 2, High = 3 |
| Vector | Dependency × Action autonomy × Access scope × Harm potential |
| Raw product | 1 to 81 |
| Product bands | Low 1–8; Medium 9–36; High 37–81 |
| Authoritative route | Product band raised where a severity floor applies |
| Routed bands | Low, Medium or High |
| Scoring source | Structured automatic inference plus explicit assessor override |
| Confirmation | Optional audited human sign-off, subject to validation |
| Downstream route | Cumulative Baseline, Enhanced or Comprehensive GTSAF depth |
| Evidence boundary | Evidence, requests, tests and findings linked to the selected intake/system |
| AI support | Structured whole-system or single-dimension analysis |
| Workspace reporting | Portfolio roll-up without replacing system-level records |
The four dimensions
Section titled “The four dimensions”| ID | Dimension | Core question | High-level meaning |
|---|---|---|---|
dep | Operational Dependency | What stops, degrades or becomes unsafe if the AI is wrong, unavailable or withdrawn? | The workflow is critical, tightly coupled or lacks a realistic fallback. |
act | Action Autonomy | What can occur before authoritative human approval? | The AI can take consequential, long-running, delegated or hard-to-reverse action. |
access | Access Scope | What can the AI identity and its tools actually reach? | Access is privileged, broad, production, cross-system, sensitive or action-capable. |
harm | Harm Potential | What is the worst credible consequence? | Severe safety, rights, legal, financial, security, service or systemic harm is plausible. |
Each dimension is assessed independently. Do not reduce one because another is low. For example, strong human approval may reduce Action Autonomy, but it does not make broad production access disappear; a tested fallback may reduce Operational Dependency, but it does not reduce the severity of a rights-affecting decision if it occurs.
The authoritative result
Section titled “The authoritative result”An ACRS result contains more than one number:
- Dimension vector, for example
dep:2, act:3, access:2, harm:3. - Raw product, calculated as
2 × 3 × 2 × 3 = 36. - Product tier, which is Medium for a raw product of 36.
- Severity-floor rules, which explain why the route may need to be raised.
- Routed tier, which is the authoritative Low, Medium or High assurance route.
In the example above, High harm combined with Medium-or-higher autonomy or access raises the route to High, even though the raw product sits at the top of the Medium product band.
Automatic inference and assessor judgement
Section titled “Automatic inference and assessor judgement”ACRS starts from the selected system’s intake facts. Gamut infers a Low, Medium or High suggestion for each dimension using structured facts and bounded contextual signals, including:
- Autonomy level and human-oversight arrangement.
- Automated-decision and high-risk flags.
- Personal and special-category data.
- Internal or external retrieval.
- Public-facing and community-impact characteristics.
- Lifecycle and deployment context.
- System purpose, users, affected people, data sources and regulatory exposure.
- Descriptions of tools, production actions, critical services and high-impact domains.
The assessor may leave the inferred level in place or record an explicit level and rationale. Explicit assessor levels take precedence in the vector. Gamut preserves provenance so an inferred score never masquerades as assessor evidence.
A lower-than-inferred score requires a rationale before confirmation. Contradictory intake facts, such as High autonomy alongside human approval before every consequential action, must also be resolved before confirmation.
Why system scope matters
Section titled “Why system scope matters”ACRS is bound to a selected system intake. When the assessor changes systems:
- The vector, product, route and conclusion change to that system.
- Linked evidence, evidence requests, tests and findings change to that system.
- AI Assist uses the new system’s authorised, validated context.
- Previously generated analysis is not presented as current for the new system.
- A material change to the assessment basis invalidates prior confirmation and makes old analysis stale for the current basis.
This prevents a low-risk profile, strong evidence or favourable AI analysis for one system from spilling into another.
What a complete assessment records
Section titled “What a complete assessment records”A defensible ACRS record should contain:
- A selected, correctly described AI system and intake.
- One level for each dimension, with visible inferred or assessor provenance.
- A rationale for each assessor override, especially any reduction.
- Resolution of contradictions and severity-floor warnings.
- Linked, reviewed evidence appropriate to the claimed level.
- Bounded test records with results and pass criteria.
- Findings for material uncertainty, control weakness or unsafe exposure.
- The authoritative vector, product tier, floor rules and routed tier.
- An accountable assessment owner.
- Confidence in the conclusion.
- A residual-risk position.
- A review date.
- Reassessment triggers.
- A concise assessor conclusion.
- Optional audited confirmation by an authorised human.
Security and assurance principles
Section titled “Security and assurance principles”ACRS in Gamut follows these rules:
- Authoritative calculation: the product, band and route are derived from the recorded basis.
- Zero trust: system scope, workspace access, roles and entitlements are verified for every use.
- No entitlement spill: routing metadata selects assurance depth; it does not grant framework, AI, model or plan access.
- Evidence over assertion: assessor rationale is not automatically converted into accepted evidence.
- Defence in depth: severe harm, autonomy and access combinations receive conservative route floors.
- Fail-safe change handling: material basis changes invalidate confirmation.
- Safe testing: tests are bounded, authorised, reversible and non-destructive.
- Human accountability: AI Assist cannot confirm ACRS, accept evidence or accept residual risk.