YARN Studiopack-driven assessments · Agile Insights · v0.1.0

Agentic AI governance (framework self-assessment) v0.1.0

framework-agentic · 1 sections

⚡ Generate from source material ⬇ Export .yarnpack.json
Advanced: raw JSON

Metadata

Scales, categories & audiences

Scales: maturity5 (5 levels) · Categories: define identity bound observe · Audiences: lead owner exec

Edit these in the raw JSON editor below — they change rarely and carry structure (levels, signals, deep-dive wiring) that a form would mangle.

Agentic elements core

Everyone answers these. The named accountable owner of each agent, whoever runs identity and access (the ISMS team), the engineering lead who built the agents, and the executive who will answer ‘who authorised this?’.

IdQuestionTypeCategoryScale
agentic-def Walk me through what your most autonomous system can actually do on its own. If it drafted something wrong right now, would a person catch it before it went out, or would it already be sent? scored_text · scored define maturity5
agentic-register How many agents are running in your organisation right now, and who owns each one? If I picked one at random, who would answer for what it did last week? scored_text · scored define maturity5
agentic-identity When one of your agents does something, what name does it show up as in your logs? Is that its own identity, or does it borrow a person’s login or a shared account? scored_text · scored identity maturity5
agentic-privilege If one of your agents was compromised this afternoon, what could the attacker reach with its credentials, and for how long before they stopped working? scored_text · scored identity maturity5
agentic-tools Can you list the tools each agent is allowed to call? If someone stood up a new MCP server tomorrow, could an agent in production start using it without anyone signing off? scored_text · scored identity maturity5
agentic-sandbox Where does the agent’s code actually run? If it generated a command to reach a system you never gave it, what stops that from working? scored_text · scored identity maturity5
agentic-limits What is the most an agent could do in an hour if it got stuck in a loop: how many actions, how much money, how many messages? Where is that limit set, and has it ever tripped? scored_text · scored bound maturity5
agentic-approvals When an agent needs a person to say yes, what does that person actually see? Is it something the agent wrote, or something pulled from a source the agent cannot touch? scored_text · scored bound maturity5
agentic-memory What does your agent remember from one run to the next, where does that come from, and could someone plant something in it that changed how it behaved next week? scored_text · scored bound maturity5
agentic-traces Pick an agent and a day last week. Can you show me every tool it called, in order, and who it was acting for? How long would that take to pull? scored_text · scored observe maturity5
agentic-kill If an agent started doing something wrong at 2 am on a Sunday, who could stop it, how would they be reached, and when did you last prove the stop actually works? scored_text · scored observe maturity5
+ Add question to “Agentic elements”

Add section

Advanced — raw JSON

Full pack document, validated on save (schema yarn-pack/2). This is where scales, audiences, structured conditions and adaptive config live.