Reference and glossary
Quick reference
Section titled “Quick reference”| Item | Value |
|---|---|
| Full name | Agentic Capability Risk Score |
| Owner | Gamut-native methodology |
| Current methodology | ACRS-1.1-secure-system-scope |
| Dimensions | 4 |
| Levels | Low = 1, Medium = 2, High = 3 |
| Product | Dependency × Action × Access × Harm |
| Minimum / maximum | 1 / 81 |
| Product bands | Low 1–8; Medium 9–36; High 37–81 |
| Authoritative band | Routed tier after severity floors |
| ACRS bands | Low, Medium, High |
| Primary scope | One selected AI system intake |
| Confirmation | Optional audited human sign-off |
Dimension identifiers
Section titled “Dimension identifiers”| ID | Dimension | Short explanation |
|---|---|---|
dep | Operational Dependency | Reliance on the AI and practical fallback. |
act | Action Autonomy | Consequential action before authoritative approval. |
access | Access Scope | Effective reach across data, tools, identities and systems. |
harm | Harm Potential | Severity, scale and reversibility of credible adverse outcomes. |
Level labels
Section titled “Level labels”Low / 1
Section titled “Low / 1”Narrow, contained, readily reversible or genuinely optional exposure.
Medium / 2
Section titled “Medium / 2”Material but bounded exposure with enforceable limits, practical intervention or recovery.
High / 3
Section titled “High / 3”Critical, privileged, consequential, severe, broad, systemic or hard-to-reverse exposure.
Vector
Section titled “Vector”The ordered four-dimension result:
dep:<level>, act:<level>, access:<level>, harm:<level>Example:
dep:1, act:2, access:3, harm:2Raw product
Section titled “Raw product”The multiplication of the four levels.
1 × 2 × 3 × 2 = 12The raw product is a risk-exposure value, not a percentage.
Product tier
Section titled “Product tier”The Low, Medium or High band produced by the raw product before severity floors.
Routed tier
Section titled “Routed tier”The authoritative assurance route after applying severity floors. This is the tier used for downstream GTSAF depth.
Severity floor
Section titled “Severity floor”A rule that sets a minimum routed tier when a severe or dangerous asymmetric condition is present. It prevents multiplication from averaging down a critical factor.
Floor table
Section titled “Floor table”| Condition | Minimum route |
|---|---|
| Harm = 3 | Medium |
| Action = 3 and Access = 3 | High |
| Harm = 3 and Action ≥ 2 | High |
| Harm = 3 and Access ≥ 2 | High |
| Action = 3 and Access ≥ 2 | High |
| Explicit high-risk intake flag | High |
| Automated consequential decisions plus special-category data or high-impact domain | High |
Inferred
Section titled “Inferred”The system-generated dimension level derived from the selected intake. It remains active where the assessor has not saved an explicit level.
Assessor override
Section titled “Assessor override”An explicit Low, Medium or High level saved by the assessor. It takes precedence over inference.
Provenance
Section titled “Provenance”The recorded source of the active dimension level:
- Inferred
- Assessor
Provenance does not mean evidence strength.
Below-floor review
Section titled “Below-floor review”A validation warning produced when an assessor selects a level below the intake-implied suggestion without recording a rationale. It blocks confirmation until justified.
Do not confuse this with a route severity floor. A below-floor review concerns an assessor override; a severity floor concerns the authoritative routed tier.
Contradiction
Section titled “Contradiction”Two or more recorded facts that cannot confidently support the same assessment, such as:
- High autonomy with approval before every consequential action.
- Low Access with special-category or external access.
- Low Harm with an explicit high-risk flag.
Contradictions must be resolved before confirmation.
Assessment basis
Section titled “Assessment basis”The system-binding facts and assessor decisions used for the current ACRS result. A material change creates a new basis, invalidates prior confirmation and makes old AI analysis stale.
Confirmation statuses
Section titled “Confirmation statuses”| User-facing meaning | Stored status | Explanation |
|---|---|---|
| Pending confirmation | evidence_complete_pending_confirmation | The score is usable, but no current human sign-off exists. |
| Contradiction review required | contradiction_review_required | Conflicts or unjustified reductions block confirmation. |
| Confirmed by assessor | confirmed_by_assessor | An authorised human signed the current basis. |
Assessment owner
Section titled “Assessment owner”The accountable AI system or risk owner responsible for the ACRS conclusion.
Confidence
Section titled “Confidence”The assessor’s confidence in the completeness and reliability of the assessment basis:
- Low
- Medium
- High
Confidence does not change the dimension levels or route.
Residual risk
Section titled “Residual risk”The remaining risk after current controls, evidence, limitations and open findings are considered. Residual risk is separate from capability exposure.
Review due
Section titled “Review due”The date by which the assessment should be reviewed even if no trigger has occurred.
Reassessment trigger
Section titled “Reassessment trigger”A specific change or event that requires review before the normal review date, such as new tools, increased autonomy, sensitive data, incidents or supplier change.
Assessor conclusion
Section titled “Assessor conclusion”The human-authored statement connecting the vector, product, floor rules, routed tier, evidence, uncertainty, findings, restrictions and governance decision.
Baseline, Enhanced and Comprehensive
Section titled “Baseline, Enhanced and Comprehensive”The cumulative GTSAF assurance depths routed by ACRS:
- Baseline: Low route.
- Baseline + Enhanced: Medium route.
- Baseline + Enhanced + Comprehensive: High route.
These labels describe required assessment depth, not current assurance outcome.
Accepted evidence
Section titled “Accepted evidence”An evidence record that has been linked, reviewed and accepted according to the evidence process. Gamut requires artefact references and a reviewed date before an evidence request can be overstated as accepted, reviewed, closed or Strong.
Evidence request
Section titled “Evidence request”A request for an artefact or operating record needed to support a dimension claim.
Control test
Section titled “Control test”A bounded procedure with expected result, pass criteria, safety limits and an actual result.
Finding
Section titled “Finding”A recorded gap, failed test, unsupported assumption or unsafe exposure requiring containment, remediation, risk decision or further evidence.
Whole-system AI analysis
Section titled “Whole-system AI analysis”Structured AI assistance covering all four dimensions, route, evidence, governance actions, monitoring, unacceptable-risk indicators and caveats for the selected system.
Dimension AI analysis
Section titled “Dimension AI analysis”Structured AI assistance limited to one selected dimension.
Human approval required
Section titled “Human approval required”The AI Assist label reminding the user that AI output cannot select final levels, confirm ACRS, accept evidence, close findings or accept residual risk.
Agent-level ACRS
Section titled “Agent-level ACRS”An ACRS record for an individual agent in Agentic CISO. It uses the same four dimensions and authoritative product/route logic, but is distinct from the selected system-intake ACRS.
Terms not to use as ACRS bands
Section titled “Terms not to use as ACRS bands”- Critical.
- Assured.
- Partial.
- Gap.
- Gate fail.
- Compliant.
- Certified.
Those labels belong to other governance or assessment concepts.
Frequently asked questions
Section titled “Frequently asked questions”Is ACRS a control framework?
Section titled “Is ACRS a control framework?”No. It classifies capability exposure and routes assurance depth. GTSAF assesses controls.
Is a High ACRS result bad?
Section titled “Is a High ACRS result bad?”It means the capability is consequential and requires comprehensive assurance. A legitimately High system can still be well controlled.
Can a Low product route High?
Section titled “Can a Low product route High?”Yes, where an explicit high-risk fact or severity-floor combination requires it.
Can the assessor override automatic scoring?
Section titled “Can the assessor override automatic scoring?”Yes. The explicit level becomes active. A lower-than-inferred level needs rationale before confirmation.
Does reset remove ACRS?
Section titled “Does reset remove ACRS?”It removes assessor overrides and conclusion fields. Automatic inference remains active.
Does confirmation freeze the score forever?
Section titled “Does confirmation freeze the score forever?”No. A material basis change invalidates confirmation.
Does AI Assist see another system’s evidence?
Section titled “Does AI Assist see another system’s evidence?”It should receive only records linked to the selected system scope. A system switch changes the analysis scope.
Can AI Assist lower the authoritative route?
Section titled “Can AI Assist lower the authoritative route?”No. Gamut protects the authoritative tier and floor reasons.
Does an API key grant AI Assist?
Section titled “Does an API key grant AI Assist?”No. Authentication, workspace access, roles, framework entitlement, AI entitlement, model entitlement, quota and rate limits are still enforced.
Does High ACRS grant a higher plan?
Section titled “Does High ACRS grant a higher plan?”No. Routing metadata never changes plan or feature entitlements.
Safe one-sentence explanation
Section titled “Safe one-sentence explanation”ACRS is Gamut’s system-scoped capability-risk method: it scores dependency, action autonomy, effective access and credible harm from 1 to 3, multiplies them, applies conservative severity floors and routes the cumulative GTSAF assurance depth while preserving human accountability, evidence integrity and tenant entitlements.