Reporting and governance
What the report should communicate
Section titled “What the report should communicate”A useful MAESTRO report explains:
- The selected system and architecture pattern.
- Assessment coverage.
- Highest-risk threats.
- Layer and cross-layer attack paths.
- Existing controls and evidence quality.
- Failed or missing tests.
- Treatment owners and dates.
- Monitoring and reassessment.
- Residual risk and decision required.
The number alone is not the conclusion.
System report
Section titled “System report”For the selected system, report:
- Threats assessed out of 55.
- Highest threat severity.
- High and Critical threats.
- Unscored applicable threats.
- Cross-layer chains.
- Open findings.
- Tests passed, partially passed, failed or not run.
- Treatment status.
- Accepted risks and expiry dates.
Workspace roll-up
Section titled “Workspace roll-up”The workspace view shows:
- Registered systems.
- Systems with a MAESTRO assessment.
- Worst-case system risk.
- Distribution of assessed systems by each system’s highest threat band.
This is a portfolio triage view. It does not prove that an unassessed system is Low risk.
AI-generated threat report
Section titled “AI-generated threat report”The generated narrative is instructed to cover:
- Executive threat summary.
- High and Critical exposures.
- Mitigation and monitoring adequacy.
- At least three cross-layer attack chains.
- Supporting ACRS context.
- MAESTRO-to-GTSAF mitigation mapping.
- Five red-team scenarios.
- Ownership, target-date and reassessment gaps.
It should distinguish recorded facts from recommendations and should not call a threat well controlled solely because its score is low.
Decision gates
Section titled “Decision gates”| Condition | Normal governance response |
|---|---|
| Critical risk | Contain or pause, urgent executive decision, remediation and adversarial validation |
| High risk | Treat before broader deployment or obtain explicit authorised acceptance |
| Failed test | Open finding, analyse root cause, remediate and retest |
| Missing owner | Assign accountable owner before accepting treatment |
| Cross-layer path with one control | Add independent break points and correlated detection |
| Unscored applicable threat | Complete assessment before claiming coverage |
| Expired acceptance | Reassess and renew or remediate |
Relationship to ACRS
Section titled “Relationship to ACRS”ACRS provides supporting capability-risk context:
- Operational dependency.
- Action autonomy.
- Access scope.
- Harm potential.
High autonomy, broad access and severe harm potential may increase MAESTRO likelihood, impact or treatment urgency, but ACRS does not calculate the MAESTRO score.
Relationship to GTSAF
Section titled “Relationship to GTSAF”MAESTRO threats should drive control verification:
- Foundation-model threats commonly connect to model governance, validation, robustness and supplier controls.
- Data threats connect to lineage, provenance, privacy, access and RAG security.
- Framework threats connect to secure development, dependencies, input validation and enforcement.
- Deployment threats connect to infrastructure, identity, segmentation and resilience.
- Observability threats connect to monitoring, logging, evidence integrity and incident response.
- Ecosystem threats connect to agent identity, tools, supply chain, contracts and non-repudiation.
Crosswalks identify candidate control relationships. Direct threat evidence and testing are still required.
Relationship to ATF
Section titled “Relationship to ATF”ATF governs agent trust and autonomy. MAESTRO findings may require:
- Lower autonomy.
- Stronger identity.
- Narrower tool scopes.
- Additional approval gates.
- Behavioural monitoring.
- Segmentation.
- Kill switch, revocation or rollback.
- Delayed promotion to a higher ATF level.
Risk-register integration
Section titled “Risk-register integration”Create a risk-register entry where the threat:
- Is High or Critical.
- Requires multi-team treatment.
- Exceeds appetite.
- Has material legal, safety or financial consequence.
- Is formally accepted or transferred.
- Depends on a supplier.
- Cannot be resolved within the assessment workflow.
The risk record should reference the MAESTRO threat ID, selected system, scenario, inherent and residual risk, controls, findings, owner, decision and review date.
Reporting cautions
Section titled “Reporting cautions”Avoid:
- Averaging away a Critical threat.
- Treating unscored threats as Low.
- Reporting workspace results as a system conclusion.
- Calling mitigation plans implemented.
- Calling a passed design review operating effectiveness.
- Claiming CSA certification or endorsement.
- Claiming regulatory compliance from a threat model.
- Publishing sensitive attack detail beyond the intended audience.
Board-level explanation
Section titled “Board-level explanation”MAESTRO decomposes each agentic AI system into seven architectural layers and models both layer-specific and cascading threats. Each applicable threat is scored by likelihood and impact. The reported posture uses the highest risk, not an average, so material exposure remains visible. Management decisions are supported by evidence, safe testing, treatment ownership and monitoring, with Critical and High risks requiring explicit action or authorised acceptance.
Reassessment governance
Section titled “Reassessment governance”Define:
- Routine review cadence.
- Event-driven triggers.
- Threat-intelligence owner.
- Model and dependency-change notification.
- Risk-acceptance expiry.
- Test recurrence.
- Report recipient and classification.
- Independent review expectations.
MAESTRO is iterative. A report is a time-bound view of one architecture and threat environment.