Skip to content

Reference and glossary

ItemValue
Full nameAgentic Capability Risk Score
OwnerGamut-native methodology
Current methodologyACRS-1.1-secure-system-scope
Dimensions4
LevelsLow = 1, Medium = 2, High = 3
ProductDependency × Action × Access × Harm
Minimum / maximum1 / 81
Product bandsLow 1–8; Medium 9–36; High 37–81
Authoritative bandRouted tier after severity floors
ACRS bandsLow, Medium, High
Primary scopeOne selected AI system intake
ConfirmationOptional audited human sign-off
IDDimensionShort explanation
depOperational DependencyReliance on the AI and practical fallback.
actAction AutonomyConsequential action before authoritative approval.
accessAccess ScopeEffective reach across data, tools, identities and systems.
harmHarm PotentialSeverity, scale and reversibility of credible adverse outcomes.

Narrow, contained, readily reversible or genuinely optional exposure.

Material but bounded exposure with enforceable limits, practical intervention or recovery.

Critical, privileged, consequential, severe, broad, systemic or hard-to-reverse exposure.

The ordered four-dimension result:

dep:<level>, act:<level>, access:<level>, harm:<level>

Example:

dep:1, act:2, access:3, harm:2

The multiplication of the four levels.

1 × 2 × 3 × 2 = 12

The raw product is a risk-exposure value, not a percentage.

The Low, Medium or High band produced by the raw product before severity floors.

The authoritative assurance route after applying severity floors. This is the tier used for downstream GTSAF depth.

A rule that sets a minimum routed tier when a severe or dangerous asymmetric condition is present. It prevents multiplication from averaging down a critical factor.

ConditionMinimum route
Harm = 3Medium
Action = 3 and Access = 3High
Harm = 3 and Action ≥ 2High
Harm = 3 and Access ≥ 2High
Action = 3 and Access ≥ 2High
Explicit high-risk intake flagHigh
Automated consequential decisions plus special-category data or high-impact domainHigh

The system-generated dimension level derived from the selected intake. It remains active where the assessor has not saved an explicit level.

An explicit Low, Medium or High level saved by the assessor. It takes precedence over inference.

The recorded source of the active dimension level:

  • Inferred
  • Assessor

Provenance does not mean evidence strength.

A validation warning produced when an assessor selects a level below the intake-implied suggestion without recording a rationale. It blocks confirmation until justified.

Do not confuse this with a route severity floor. A below-floor review concerns an assessor override; a severity floor concerns the authoritative routed tier.

Two or more recorded facts that cannot confidently support the same assessment, such as:

  • High autonomy with approval before every consequential action.
  • Low Access with special-category or external access.
  • Low Harm with an explicit high-risk flag.

Contradictions must be resolved before confirmation.

The system-binding facts and assessor decisions used for the current ACRS result. A material change creates a new basis, invalidates prior confirmation and makes old AI analysis stale.

User-facing meaningStored statusExplanation
Pending confirmationevidence_complete_pending_confirmationThe score is usable, but no current human sign-off exists.
Contradiction review requiredcontradiction_review_requiredConflicts or unjustified reductions block confirmation.
Confirmed by assessorconfirmed_by_assessorAn authorised human signed the current basis.

The accountable AI system or risk owner responsible for the ACRS conclusion.

The assessor’s confidence in the completeness and reliability of the assessment basis:

  • Low
  • Medium
  • High

Confidence does not change the dimension levels or route.

The remaining risk after current controls, evidence, limitations and open findings are considered. Residual risk is separate from capability exposure.

The date by which the assessment should be reviewed even if no trigger has occurred.

A specific change or event that requires review before the normal review date, such as new tools, increased autonomy, sensitive data, incidents or supplier change.

The human-authored statement connecting the vector, product, floor rules, routed tier, evidence, uncertainty, findings, restrictions and governance decision.

The cumulative GTSAF assurance depths routed by ACRS:

  • Baseline: Low route.
  • Baseline + Enhanced: Medium route.
  • Baseline + Enhanced + Comprehensive: High route.

These labels describe required assessment depth, not current assurance outcome.

An evidence record that has been linked, reviewed and accepted according to the evidence process. Gamut requires artefact references and a reviewed date before an evidence request can be overstated as accepted, reviewed, closed or Strong.

A request for an artefact or operating record needed to support a dimension claim.

A bounded procedure with expected result, pass criteria, safety limits and an actual result.

A recorded gap, failed test, unsupported assumption or unsafe exposure requiring containment, remediation, risk decision or further evidence.

Structured AI assistance covering all four dimensions, route, evidence, governance actions, monitoring, unacceptable-risk indicators and caveats for the selected system.

Structured AI assistance limited to one selected dimension.

The AI Assist label reminding the user that AI output cannot select final levels, confirm ACRS, accept evidence, close findings or accept residual risk.

An ACRS record for an individual agent in Agentic CISO. It uses the same four dimensions and authoritative product/route logic, but is distinct from the selected system-intake ACRS.

  • Critical.
  • Assured.
  • Partial.
  • Gap.
  • Gate fail.
  • Compliant.
  • Certified.

Those labels belong to other governance or assessment concepts.

No. It classifies capability exposure and routes assurance depth. GTSAF assesses controls.

It means the capability is consequential and requires comprehensive assurance. A legitimately High system can still be well controlled.

Yes, where an explicit high-risk fact or severity-floor combination requires it.

Can the assessor override automatic scoring?

Section titled “Can the assessor override automatic scoring?”

Yes. The explicit level becomes active. A lower-than-inferred level needs rationale before confirmation.

It removes assessor overrides and conclusion fields. Automatic inference remains active.

Does confirmation freeze the score forever?

Section titled “Does confirmation freeze the score forever?”

No. A material basis change invalidates confirmation.

Does AI Assist see another system’s evidence?

Section titled “Does AI Assist see another system’s evidence?”

It should receive only records linked to the selected system scope. A system switch changes the analysis scope.

Can AI Assist lower the authoritative route?

Section titled “Can AI Assist lower the authoritative route?”

No. Gamut protects the authoritative tier and floor reasons.

No. Authentication, workspace access, roles, framework entitlement, AI entitlement, model entitlement, quota and rate limits are still enforced.

No. Routing metadata never changes plan or feature entitlements.

ACRS is Gamut’s system-scoped capability-risk method: it scores dependency, action autonomy, effective access and credible harm from 1 to 3, multiplies them, applies conservative severity floors and routes the cumulative GTSAF assurance depth while preserving human accountability, evidence integrity and tenant entitlements.