Skip to content

ACRS

ACRS, the Agentic Capability Risk Score, is Gamut’s native method for classifying the capability exposure of an AI system or agentic workflow. It asks four practical questions:

  1. How dependent are operations, people or decisions on the AI?
  2. How much can it decide or do before authoritative human approval?
  3. Which data, tools, identities, systems and actions can it reach?
  4. How serious could the credible consequences of failure, misuse or compromise become?

The answers form a four-part vector and a product score. Gamut then applies conservative severity-floor rules so a mathematically modest product cannot under-route a system with severe harm, consequential autonomy, broad access or explicit high-risk characteristics.

ACRS is not a control-compliance score. It establishes the depth of assurance the system needs. The routed result feeds the GTSAF assessment plan and informs threat modelling, approval, evidence, testing, monitoring and governance attention.

If you need to…Read
Explain every score, vector, band, status and severity-floor ruleMethod, scoring and terminology
Assess dependency, autonomy, access and harm without leaving the screenDimension assessor playbooks
Understand system boundaries and how ACRS routes GTSAFSystem scope and GTSAF routing
Complete an ACRS assessment from intake to sign-offAssessment workflow
Know what evidence to request, how to test safely and when to raise findingsEvidence, testing and findings
Explain what AI Assist reads, produces, secures and cannot decideAI Assist and security
Explain reports, ownership, residual risk and reassessmentReporting and governance
Follow a realistic assessment with severity-floor routingWorked example
Look up fields, statuses, labels, formulas and assessor languageReference and glossary
PropertyGamut implementation
MethodologyVersioned Gamut-native capability-risk method
Primary assessment levelOne selected AI system intake
Dimensions4
Dimension levelsLow = 1, Medium = 2, High = 3
VectorDependency × Action autonomy × Access scope × Harm potential
Raw product1 to 81
Product bandsLow 1–8; Medium 9–36; High 37–81
Authoritative routeProduct band raised where a severity floor applies
Routed bandsLow, Medium or High
Scoring sourceStructured automatic inference plus explicit assessor override
ConfirmationOptional audited human sign-off, subject to validation
Downstream routeCumulative Baseline, Enhanced or Comprehensive GTSAF depth
Evidence boundaryEvidence, requests, tests and findings linked to the selected intake/system
AI supportStructured whole-system or single-dimension analysis
Workspace reportingPortfolio roll-up without replacing system-level records
IDDimensionCore questionHigh-level meaning
depOperational DependencyWhat stops, degrades or becomes unsafe if the AI is wrong, unavailable or withdrawn?The workflow is critical, tightly coupled or lacks a realistic fallback.
actAction AutonomyWhat can occur before authoritative human approval?The AI can take consequential, long-running, delegated or hard-to-reverse action.
accessAccess ScopeWhat can the AI identity and its tools actually reach?Access is privileged, broad, production, cross-system, sensitive or action-capable.
harmHarm PotentialWhat is the worst credible consequence?Severe safety, rights, legal, financial, security, service or systemic harm is plausible.

Each dimension is assessed independently. Do not reduce one because another is low. For example, strong human approval may reduce Action Autonomy, but it does not make broad production access disappear; a tested fallback may reduce Operational Dependency, but it does not reduce the severity of a rights-affecting decision if it occurs.

An ACRS result contains more than one number:

  • Dimension vector, for example dep:2, act:3, access:2, harm:3.
  • Raw product, calculated as 2 × 3 × 2 × 3 = 36.
  • Product tier, which is Medium for a raw product of 36.
  • Severity-floor rules, which explain why the route may need to be raised.
  • Routed tier, which is the authoritative Low, Medium or High assurance route.

In the example above, High harm combined with Medium-or-higher autonomy or access raises the route to High, even though the raw product sits at the top of the Medium product band.

Automatic inference and assessor judgement

Section titled “Automatic inference and assessor judgement”

ACRS starts from the selected system’s intake facts. Gamut infers a Low, Medium or High suggestion for each dimension using structured facts and bounded contextual signals, including:

  • Autonomy level and human-oversight arrangement.
  • Automated-decision and high-risk flags.
  • Personal and special-category data.
  • Internal or external retrieval.
  • Public-facing and community-impact characteristics.
  • Lifecycle and deployment context.
  • System purpose, users, affected people, data sources and regulatory exposure.
  • Descriptions of tools, production actions, critical services and high-impact domains.

The assessor may leave the inferred level in place or record an explicit level and rationale. Explicit assessor levels take precedence in the vector. Gamut preserves provenance so an inferred score never masquerades as assessor evidence.

A lower-than-inferred score requires a rationale before confirmation. Contradictory intake facts, such as High autonomy alongside human approval before every consequential action, must also be resolved before confirmation.

ACRS is bound to a selected system intake. When the assessor changes systems:

  • The vector, product, route and conclusion change to that system.
  • Linked evidence, evidence requests, tests and findings change to that system.
  • AI Assist uses the new system’s authorised, validated context.
  • Previously generated analysis is not presented as current for the new system.
  • A material change to the assessment basis invalidates prior confirmation and makes old analysis stale for the current basis.

This prevents a low-risk profile, strong evidence or favourable AI analysis for one system from spilling into another.

A defensible ACRS record should contain:

  • A selected, correctly described AI system and intake.
  • One level for each dimension, with visible inferred or assessor provenance.
  • A rationale for each assessor override, especially any reduction.
  • Resolution of contradictions and severity-floor warnings.
  • Linked, reviewed evidence appropriate to the claimed level.
  • Bounded test records with results and pass criteria.
  • Findings for material uncertainty, control weakness or unsafe exposure.
  • The authoritative vector, product tier, floor rules and routed tier.
  • An accountable assessment owner.
  • Confidence in the conclusion.
  • A residual-risk position.
  • A review date.
  • Reassessment triggers.
  • A concise assessor conclusion.
  • Optional audited confirmation by an authorised human.

ACRS in Gamut follows these rules:

  • Authoritative calculation: the product, band and route are derived from the recorded basis.
  • Zero trust: system scope, workspace access, roles and entitlements are verified for every use.
  • No entitlement spill: routing metadata selects assurance depth; it does not grant framework, AI, model or plan access.
  • Evidence over assertion: assessor rationale is not automatically converted into accepted evidence.
  • Defence in depth: severe harm, autonomy and access combinations receive conservative route floors.
  • Fail-safe change handling: material basis changes invalidate confirmation.
  • Safe testing: tests are bounded, authorised, reversible and non-destructive.
  • Human accountability: AI Assist cannot confirm ACRS, accept evidence or accept residual risk.
  1. Method, scoring and terminology
  2. Dimension assessor playbooks
  3. System scope and GTSAF routing
  4. Assessment workflow
  5. Evidence, testing and findings
  6. AI Assist and security
  7. Reporting and governance
  8. Worked example
  9. Reference and glossary