Skip to content

Reporting and governance

A useful MAESTRO report explains:

  • The selected system and architecture pattern.
  • Assessment coverage.
  • Highest-risk threats.
  • Layer and cross-layer attack paths.
  • Existing controls and evidence quality.
  • Failed or missing tests.
  • Treatment owners and dates.
  • Monitoring and reassessment.
  • Residual risk and decision required.

The number alone is not the conclusion.

For the selected system, report:

  • Threats assessed out of 55.
  • Highest threat severity.
  • High and Critical threats.
  • Unscored applicable threats.
  • Cross-layer chains.
  • Open findings.
  • Tests passed, partially passed, failed or not run.
  • Treatment status.
  • Accepted risks and expiry dates.

The workspace view shows:

  • Registered systems.
  • Systems with a MAESTRO assessment.
  • Worst-case system risk.
  • Distribution of assessed systems by each system’s highest threat band.

This is a portfolio triage view. It does not prove that an unassessed system is Low risk.

The generated narrative is instructed to cover:

  1. Executive threat summary.
  2. High and Critical exposures.
  3. Mitigation and monitoring adequacy.
  4. At least three cross-layer attack chains.
  5. Supporting ACRS context.
  6. MAESTRO-to-GTSAF mitigation mapping.
  7. Five red-team scenarios.
  8. Ownership, target-date and reassessment gaps.

It should distinguish recorded facts from recommendations and should not call a threat well controlled solely because its score is low.

ConditionNormal governance response
Critical riskContain or pause, urgent executive decision, remediation and adversarial validation
High riskTreat before broader deployment or obtain explicit authorised acceptance
Failed testOpen finding, analyse root cause, remediate and retest
Missing ownerAssign accountable owner before accepting treatment
Cross-layer path with one controlAdd independent break points and correlated detection
Unscored applicable threatComplete assessment before claiming coverage
Expired acceptanceReassess and renew or remediate

ACRS provides supporting capability-risk context:

  • Operational dependency.
  • Action autonomy.
  • Access scope.
  • Harm potential.

High autonomy, broad access and severe harm potential may increase MAESTRO likelihood, impact or treatment urgency, but ACRS does not calculate the MAESTRO score.

MAESTRO threats should drive control verification:

  • Foundation-model threats commonly connect to model governance, validation, robustness and supplier controls.
  • Data threats connect to lineage, provenance, privacy, access and RAG security.
  • Framework threats connect to secure development, dependencies, input validation and enforcement.
  • Deployment threats connect to infrastructure, identity, segmentation and resilience.
  • Observability threats connect to monitoring, logging, evidence integrity and incident response.
  • Ecosystem threats connect to agent identity, tools, supply chain, contracts and non-repudiation.

Crosswalks identify candidate control relationships. Direct threat evidence and testing are still required.

ATF governs agent trust and autonomy. MAESTRO findings may require:

  • Lower autonomy.
  • Stronger identity.
  • Narrower tool scopes.
  • Additional approval gates.
  • Behavioural monitoring.
  • Segmentation.
  • Kill switch, revocation or rollback.
  • Delayed promotion to a higher ATF level.

Create a risk-register entry where the threat:

  • Is High or Critical.
  • Requires multi-team treatment.
  • Exceeds appetite.
  • Has material legal, safety or financial consequence.
  • Is formally accepted or transferred.
  • Depends on a supplier.
  • Cannot be resolved within the assessment workflow.

The risk record should reference the MAESTRO threat ID, selected system, scenario, inherent and residual risk, controls, findings, owner, decision and review date.

Avoid:

  • Averaging away a Critical threat.
  • Treating unscored threats as Low.
  • Reporting workspace results as a system conclusion.
  • Calling mitigation plans implemented.
  • Calling a passed design review operating effectiveness.
  • Claiming CSA certification or endorsement.
  • Claiming regulatory compliance from a threat model.
  • Publishing sensitive attack detail beyond the intended audience.

MAESTRO decomposes each agentic AI system into seven architectural layers and models both layer-specific and cascading threats. Each applicable threat is scored by likelihood and impact. The reported posture uses the highest risk, not an average, so material exposure remains visible. Management decisions are supported by evidence, safe testing, treatment ownership and monitoring, with Critical and High risks requiring explicit action or authorised acceptance.

Define:

  • Routine review cadence.
  • Event-driven triggers.
  • Threat-intelligence owner.
  • Model and dependency-change notification.
  • Risk-acceptance expiry.
  • Test recurrence.
  • Report recipient and classification.
  • Independent review expectations.

MAESTRO is iterative. A report is a time-bound view of one architecture and threat environment.