Skip to content

Method, scoring and terminology

ACRS classifies capability exposure, not control maturity. A higher result means the selected AI system requires deeper assurance, stronger evidence, tighter testing and more accountable oversight.

Inherent exposure versus control effectiveness

Section titled “Inherent exposure versus control effectiveness”

The assessor should score the capability as it actually operates in the assessed context:

  • The business dependency that exists.
  • The actions that can occur.
  • The effective access available.
  • The credible harm that can result.

Do not lower a dimension merely because a control is planned. A control may reduce the probability, blast radius or residual risk, but the ACRS dimension still needs to describe the deployed capability accurately.

Examples:

  • An agent with production write permission remains High Access even if logs are enabled.
  • A payment agent remains High Action Autonomy if it can release payments before approval, even if a human reviews a daily report.
  • A clinical workflow can remain High Harm even when the model is accurate, because Harm describes consequence severity rather than model-error probability.
  • A tested manual process can reduce Dependency where it genuinely sustains safe operation at realistic demand.

Each of the four dimensions receives an integer level:

LevelLabelMeaning
1LowNarrow, contained, readily reversible or genuinely optional exposure.
2MediumMaterial but bounded exposure with practical limits, intervention or recovery.
3HighCritical, privileged, consequential, severe, broad or hard-to-reverse exposure.

The displayed vector uses stable dimension IDs:

dep:<1-3>, act:<1-3>, access:<1-3>, harm:<1-3>

Example:

dep:2, act:3, access:2, harm:3

The raw product is:

Operational Dependency × Action Autonomy × Access Scope × Harm Potential

The minimum is 1 × 1 × 1 × 1 = 1. The maximum is 3 × 3 × 3 × 3 = 81.

Raw productProduct tierNormal assurance direction
1–8LowBaseline GTSAF controls and proportionate review.
9–36MediumEnhanced controls, validation, monitoring and oversight.
37–81HighComprehensive relevant controls, independent challenge and continuous monitoring.

Because every input is an integer, only discrete products occur. The product should therefore be reported as a whole number, not as a percentage, maturity score or compliance score.

The product tier is the band produced by the multiplication alone.

The routed tier is the authoritative assurance route after severity floors are applied.

The routed tier can equal the product tier or be higher. It cannot be lowered below the product tier. This distinction matters in reports and explanations:

Raw product 36, product tier Medium, routed tier High because severe harm is combined with consequential autonomy and material access.

Gamut applies the following conservative floors:

ConditionMinimum routed tierWhy
Harm = 3MediumSevere or potentially irreversible harm cannot route Low.
Action = 3 and Access = 3HighHigh autonomy with broad or privileged reach needs comprehensive assurance.
Harm = 3 and Action ≥ 2HighSevere harm plus material or high autonomy cannot remain Medium.
Harm = 3 and Access ≥ 2HighSevere harm plus material or broad access cannot remain Medium.
Action = 3 and Access ≥ 2HighConsequential pre-approval action with material access needs a High route.
Intake explicitly identifies high riskHighAn accepted structured high-risk fact cannot be averaged down.
Automated consequential decisions plus special-category data or a high-impact domainHighRights-affecting or similarly consequential automated decisions need comprehensive assurance.

High-impact domains include contexts such as employment, recruitment, credit, insurance, health, medical care, education, benefits, legal services, surveillance, children and public administration. The exact result is determined by Gamut from the recorded intake.

Multiple floor reasons may be recorded. They explain the route; they are not additional points.

Multiplication makes combinations matter. Four Low values remain Low, while several Medium or High values increase the score rapidly.

However, multiplication alone can still hide a severe asymmetric condition. For example:

1 × 1 × 1 × 3 = 3

The product is Low, but Harm is High. The harm floor raises the route to at least Medium. This is why the severity-floor layer is necessary.

When a system intake is selected, Gamut derives a suggested level for every dimension. Structured fields are the primary basis; bounded contextual text is used as a secondary signal.

Typical inputs include:

DimensionImportant inference signals
DependencyCritical or production workflow, customer service, payments, claims, clinical or security operations, public exposure and operational lifecycle.
ActionRecorded autonomy level, human-oversight type, automated-decision flag and descriptions of execution, writing, approval, transactions, tools or workflow automation.
AccessPersonal or special-category data, external retrieval, APIs, databases, privileged or production access, financial, identity, biometric, health or customer data.
HarmHigh-risk and automated-decision flags, public or community impact and high-impact domains affecting safety, rights, livelihood or essential services.

Automatic scoring remains active if the assessor resets their overrides. It is not deleted merely because an assessment has not been confirmed.

For each dimension, the assessor may:

  • Accept the inferred level by leaving the explicit level unset.
  • Select an explicit Low, Medium or High level.
  • Record a rationale explaining the system facts, evidence and judgement.

An explicit level takes precedence in the vector. The saved record preserves whether the active value came from inference or the assessor.

An explicit score below the inferred suggestion requires a rationale before confirmation. The rationale should explain:

  • Which inference input overstates the effective exposure.
  • Which boundary is technically enforced.
  • Which evidence and test demonstrate that boundary.
  • Why the lower anchor is met in the deployed environment.
  • Which change would invalidate that judgement.

“The team considers it low risk” is not sufficient.

The assessor may raise a score when the intake understates the deployment or when evidence reveals a broader capability. A rationale is still good practice because it improves traceability and helps future reassessment.

Gamut identifies inconsistent facts that must be reviewed. Examples include:

  • Special-category data marked Yes while personal data is No.
  • External retrieval recorded in one field and denied in another.
  • Assistive autonomy combined with automated consequential decisions.
  • High Action Autonomy combined with approval before every consequential action.
  • Low Access despite sensitive or external access.
  • Low Harm while the intake explicitly identifies high risk.

A contradiction does not automatically decide which field is wrong. It prevents confident confirmation until the assessor resolves the record.

Each dimension has one of two active provenance states:

ProvenanceMeaning
InferredThe automatically generated level is active because no explicit assessor level is saved.
AssessorAn explicit assessor level is active and takes precedence.

Provenance is not evidence strength. An assessor-entered score can still be weakly supported, and an inferred score can still be directionally correct.

The user-facing state is derived from the validated assessment:

StatusMeaning
Pending confirmationThe vector is usable for routing, but an authorised assessor has not signed it off.
Contradiction review requiredConflicting facts or an unjustified lower-than-inferred level prevent confirmation.
Confirmed by assessorAn authorised human confirmed the current assessment basis.

The score is always computable because inference supplies any unset dimension. Confirmation is an optional sign-off, not a prerequisite for seeing the vector.

Assessment-basis change and stale confirmation

Section titled “Assessment-basis change and stale confirmation”

Gamut binds confirmation to the material fields that drive the ACRS result, including dimension overrides and rationales, autonomy, oversight, data, retrieval, impact and deployment.

If a material basis field changes:

  • The assessment basis changes.
  • Prior confirmation is invalidated.
  • The route returns to a pending state.
  • Previously generated AI analysis is no longer current for the new basis.
  • The assessor must review the changed facts and reconfirm where appropriate.

This prevents a signed Low or Medium result from surviving a later increase in autonomy, access or harm.

Confirmation records an audited human sign-off for the current basis. It is allowed only when:

  • Contradictions are resolved.
  • Every lower-than-inferred override has a rationale.
  • The selected system scope is valid.
  • The user has the required role and entitlement.

Confirmation does not:

  • Accept evidence automatically.
  • Approve deployment.
  • Accept residual risk.
  • Prove GTSAF conformance.
  • Prevent future reassessment.

Agentic CISO can also record ACRS for an individual agent. Gamut infers agent levels from capabilities such as tool calling, memory, delegation, external action, code modification, spending authority and access to customer or confidential data.

Gamut recomputes the agent product and route. If a manually submitted agent level differs from the system suggestion, an override rationale is required. Agent-level scoring and system-intake ACRS use the same four dimensions and route logic, but they remain separate records with different scope.

  • Treating ACRS as a maturity score where higher is better.
  • Averaging the four dimensions.
  • Reporting the product as a percentage.
  • Ignoring severity floors.
  • Lowering Harm because probability is low.
  • Lowering Access because the intended workflow is narrow while permissions are broad.
  • Calling post-action notification “human approval”.
  • Treating a supplier SLA as proof of a tested fallback.
  • Copying one system’s vector to another.
  • Treating an assessor rationale or AI recommendation as accepted evidence.