diff --git a/staging/batches/BATCH-2026-010/eligibility-check.json b/staging/batches/BATCH-2026-010/eligibility-check.json new file mode 100644 index 0000000..91c3d50 --- /dev/null +++ b/staging/batches/BATCH-2026-010/eligibility-check.json @@ -0,0 +1,101 @@ +{ + "batch_id": "BATCH-2026-010", + "prompt_id": "OEII-ROLE-COMPARISON", + "prompt_version": "2.0", + "topic": "Governed identities for AI agents", + "time_period": "2020-08-15 through 2026-08-15, with pre-2020 foundations only when directly applicable", + "selected_roles": [ + "role-ciso", + "role-cio", + "role-cto" + ], + "repository_configured_role_comparison_threshold": null, + "comparison_eligibility_floor": { + "status": "pre_registered_editorial_floor_for_this_batch_not_a_publication_threshold", + "per_role": { + "independently_checked_production_sources": 3, + "people_with_role_at_source_time": 2, + "organizations": 2, + "substantive_role_attributed_statements": 5 + }, + "requirements": [ + "Role at source time verified", + "Statement and proposition lineage complete", + "No single-source comparison", + "Sample and concentration disclosed" + ] + }, + "production_metrics": { + "role-ciso": { + "people": 0, + "sources": 0, + "statements": 0, + "organizations": 0, + "source_types": [], + "regions": [], + "industries": [], + "date_range": null, + "off_owned_source_share": null, + "vendor_source_share": null, + "consulting_source_share": null, + "role_at_source_time_evidence": 0, + "staging_relevance_tag_mentions": 46 + }, + "role-cio": { + "people": 0, + "sources": 0, + "statements": 0, + "organizations": 0, + "source_types": [], + "regions": [], + "industries": [], + "date_range": null, + "off_owned_source_share": null, + "vendor_source_share": null, + "consulting_source_share": null, + "role_at_source_time_evidence": 0, + "staging_relevance_tag_mentions": 46 + }, + "role-cto": { + "people": 0, + "sources": 0, + "statements": 0, + "organizations": 0, + "source_types": [], + "regions": [], + "industries": [], + "date_range": null, + "off_owned_source_share": null, + "vendor_source_share": null, + "consulting_source_share": null, + "role_at_source_time_evidence": 0, + "staging_relevance_tag_mentions": 46 + } + }, + "roles_meeting_floor": [], + "roles_below_floor": [ + "role-ciso", + "role-cio", + "role-cto" + ], + "comparison_status": "INELIGIBLE_ROLE_EVIDENCE_GAP_BRIEFING_ONLY", + "reason": "Canonical role, person, source, statement, proposition, and dossier directories contain no topic records. Staging statements are relevance-tagged for all selected roles but are authored by institutional, research, standards, editor, contributor, or author roles rather than by indexed CISO, CIO, or CTO speakers at source time.", + "source_concentration": { + "production_denominator": 0, + "off_owned_share": null, + "vendor_share": null, + "largest_source_share": null + }, + "staging_context_not_evidence": { + "shared_relevance_tag_count_per_role": 46, + "direct_ciso_role_at_source_time_statements": 0, + "direct_cio_role_at_source_time_statements": 0, + "direct_cto_role_at_source_time_statements": 0, + "current_cto_records_that_must_not_be_backfilled": 1, + "example_person_id": "person-BATCH-2026-005-luca-beurer-kellner", + "example_current_role": "Chief Technology Officer", + "example_role_at_source_time": "Author", + "use_restriction": "Research-gap and scope-correction planning only; not role evidence." + }, + "human_review_status": "pending" +} diff --git a/staging/batches/BATCH-2026-010/evidence-gap-table.csv b/staging/batches/BATCH-2026-010/evidence-gap-table.csv new file mode 100644 index 0000000..29db411 --- /dev/null +++ b/staging/batches/BATCH-2026-010/evidence-gap-table.csv @@ -0,0 +1,9 @@ +"gap_id","dimension","roles_affected","current_evidence","missing_evidence","recommended_batch" +"G-001","Role-at-source-time corpus","CISO; CIO; CTO","0 eligible records","Direct statements by people verified in each role at source time","Role-specific operator interview batch" +"G-002","Implementation ownership","CISO; CIO; CTO","0","Decision rights for inventory, identity platform, authorization policy, monitoring, incident response, and shutdown","Cross-functional operating-model case batch" +"G-003","Measurement","CISO; CIO; CTO","0","Comparable denominators for inventory, access, incident, utility, reliability, cost, and audit outcomes","Metrics and implementation study" +"G-004","Budget and incentives","CISO; CIO; CTO","0","Budget owner, buyer, signer, cost center, loss model, and resource tradeoffs","Executive budget and governance survey" +"G-005","Internal disagreement","CISO; CIO; CTO","0","Multiple independent sources within each role, including dissenting or failed approaches","Role-diversity and counterposition batch" +"G-006","Geography and industry","CISO; CIO; CTO","0","Role evidence across regions, regulation, organization sizes, and industries","Regional and industry role batch" +"G-007","Legal and data assumptions","CISO; CIO; CTO","0","Comparable legal, privacy, retention, and data-governance assumptions","Add general counsel and data leadership comparison" +"G-008","Production evidence promotion","CISO; CIO; CTO","No canonical sources, statements, or propositions","Named human review and production promotion","Human-review and publication-readiness batch" diff --git a/staging/batches/BATCH-2026-010/evidence-gaps.md b/staging/batches/BATCH-2026-010/evidence-gaps.md new file mode 100644 index 0000000..ec65c99 --- /dev/null +++ b/staging/batches/BATCH-2026-010/evidence-gaps.md @@ -0,0 +1,22 @@ +# Evidence gaps and recommended batches + +All three selected roles are below the comparison floor. The gap is not a difference in source volume between roles; it is the absence of any production role-at-source-time corpus. + +## Priority gaps + +1. Recruit at least three independently checked sources, two people, two organizations, and five substantive statements for each role before comparison. +2. Record role at source time, not current role, and distinguish personal views from institutional positions. +3. Capture the same core questions across roles so responsibility and emphasis can be compared without false symmetry. +4. Add implementation evidence with denominators, failures, costs, and time horizons—not only recommendations. +5. Add general counsel, finance, board, and business-unit evidence before drawing conclusions about cross-functional governance. +6. Sample multiple industries and regions and preserve organization size, regulatory scope, and level of agent autonomy. +7. Seek internal counterpositions within each role; one interview cannot establish role literature. + +## Recommended sequence + +- **CISO operator batch:** inventory, access risk, incident response, monitoring, board reporting, and security budget. +- **CIO operator batch:** platform ownership, lifecycle operations, procurement, integration, reliability, and shared-service economics. +- **CTO operator batch:** architecture, identity granularity, delegation, developer controls, benchmark use, and shutdown design. +- **Cross-functional case batch:** interview CISO, CIO, and CTO participants from the same organization about one deployed agent. +- **Counterposition batch:** privacy, surveillance, over-control, user burden, innovation cost, and failed controls. +- **Human-review batch:** validate role attribution, exact locators, organization and geography fields, statement lineage, and publication readiness. diff --git a/staging/batches/BATCH-2026-010/existing-content-overlap.md b/staging/batches/BATCH-2026-010/existing-content-overlap.md new file mode 100644 index 0000000..a46d462 --- /dev/null +++ b/staging/batches/BATCH-2026-010/existing-content-overlap.md @@ -0,0 +1,10 @@ +# Existing content overlap + +Official OFF pages were checked on 2026-08-15 for research design and duplication only. + +- [Forum Select for CISOs](https://openfutureforum.com/for-cisos) lists AI security, governance, regulation, board reporting, and zero-trust discussion topics. It is a community description, not an indexed role-attributed corpus. +- The [CISO AI Leverage Report](https://openfutureforum.com/research/ciso-ai-leverage-report) contains potentially relevant role-tagged and mixed-room findings. It remains outside the repository corpus and requires verification of respondent classification, denominators, methods, exact locators, ownership, sponsorship, and advisory disclosures. +- [Forum Select for CTOs](https://openfutureforum.com/for-ctos) mentions production agent identity, authorization, audit trails, and CTO–CISO risk. It describes an agenda, not verified CTO positions. +- Some OFF buyer findings combine “CIO or CTO.” That category cannot distinguish CIO from CTO and must not be used for this comparison. + +No OFF page was counted as evidence. A future ingestion batch should preserve role-specific cuts and treat community, marketing, operator-research, and interview content as different source types. diff --git a/staging/batches/BATCH-2026-010/interview-questions.md b/staging/batches/BATCH-2026-010/interview-questions.md new file mode 100644 index 0000000..92aa95e --- /dev/null +++ b/staging/batches/BATCH-2026-010/interview-questions.md @@ -0,0 +1,29 @@ +# Proposed interview questions + +## Shared anchor + +**Think about the last production agent whose access or action created a decision you personally had to make. What was the decision, what evidence did you use, who else had authority, and what outcome did you measure?** + +## CISO + +1. Which agent identities and connections are visible to security today, and what denominator tells you coverage? +2. Which agent actions require policy enforcement, human approval, automated monitoring, or a hard prohibition? +3. When agent access becomes an incident, who owns containment, revocation, evidence preservation, and board reporting? +4. Which security measures justify budget: unauthorized actions, incident loss, coverage, response time, or something else? +5. Where has a security control blocked legitimate agent work or encouraged teams to route around it? + +## CIO + +1. Which platform owns agent inventory, identity issuance, lifecycle events, and integration with enterprise IAM? +2. How do you measure reliability, orphaned identities, revocation latency, and cross-system interoperability? +3. Where do business-unit autonomy and enterprise control conflict in agent deployment? +4. Who funds shared identity infrastructure when individual teams own the agents? +5. Which responsibility is regularly assigned to the CIO but cannot be delivered without the CISO or CTO? + +## CTO + +1. At what granularity do you identify agents—class, deployment, instance, session, or task—and why? +2. How does authority attenuate when an agent delegates to tools or subagents? +3. Which security controls materially reduce task utility, latency, or developer velocity? +4. What benchmark or production evidence changes a model, architecture, or deployment decision? +5. Who can stop an agent and its descendants, and how is that authority tested? diff --git a/staging/batches/BATCH-2026-010/limitations.md b/staging/batches/BATCH-2026-010/limitations.md new file mode 100644 index 0000000..7c7b867 --- /dev/null +++ b/staging/batches/BATCH-2026-010/limitations.md @@ -0,0 +1,14 @@ +# Limitations + +- The production topic corpus and each selected role corpus are empty. +- The repository has no configured numeric role-comparison threshold; the operational floor is explicitly batch-specific and requires human review. +- Staging relevance tags identify potential audience, not speaker role. +- Current roles cannot be backfilled into historical sources. +- Staging sources and statements remain human-review pending and were not used as role evidence. +- No canonical proposition or stance record exists for proposition-by-role comparison. +- No sample supports internal disagreement, role alignment, role emphasis, responsibility, risk tolerance, incentive, or time-horizon findings. +- Production source-concentration shares are undefined with a zero denominator. +- OFF web content was checked for overlap only and has not been ingested or independently verified in the repository. +- Proposed dimensions, metrics, interviews, and roundtable questions are research designs, not findings. +- The CISO/CIO/CTO selection omits general counsel, CFO, CEO, board, data, business-unit, and product roles that may materially shape governance. +- All outputs are machine-produced and human-review pending. diff --git a/staging/batches/BATCH-2026-010/manifest.yml b/staging/batches/BATCH-2026-010/manifest.yml new file mode 100644 index 0000000..78e1915 --- /dev/null +++ b/staging/batches/BATCH-2026-010/manifest.yml @@ -0,0 +1,54 @@ +batch_id: BATCH-2026-010 +prompt_id: OEII-ROLE-COMPARISON +prompt_version: "2.0" +topic: Governed identities for AI agents +topic_slug: governed-agent-identities +roles: [role-ciso, role-cio, role-cto] +time_period: 2020-08-15 through 2026-08-15, with pre-2020 foundations only when directly applicable +branch: analysis/role-comparison-governed-agent-identities-BATCH-2026-010 +base_branch: research/people-BATCH-2026-007 +execution_date: 2026-08-15 +execution_completed_at: 2026-08-15T17:30:00-07:00 +agent_or_researcher: OpenAI Codex; machine-assisted role eligibility, source-time attribution, scope correction, and research-gap design; named human review pending +model_disclosure: AI-assisted canonical inventory, role-at-source-time audit, gap briefing, matrix and question drafting, OFF overlap search, and validation; no role finding or human approval was inferred. +comparison_status: INELIGIBLE_ROLE_EVIDENCE_GAP_BRIEFING_ONLY +roles_meeting_floor: 0 +roles_below_floor: 3 +ciso_people: 0 +ciso_sources: 0 +ciso_statements: 0 +cio_people: 0 +cio_sources: 0 +cio_statements: 0 +cto_people: 0 +cto_sources: 0 +cto_statements: 0 +shared_staging_relevance_tags_per_role: 46 +eligible_role_at_source_time_statements_per_role: 0 +scope_mismatches_corrected: 7 +human_review_status: pending +output_files: + - manifest.yml + - eligibility-check.json + - role-evidence-gap-briefing.md + - role-comparison.json + - role-evidence-table.csv + - role-source-distribution.csv + - role-proposition-matrix.csv + - risk-framing-matrix.csv + - measurement-matrix.csv + - scope-mismatch-review.csv + - evidence-gap-table.csv + - evidence-gaps.md + - interview-questions.md + - roundtable-questions.md + - existing-content-overlap.md + - limitations.md + - validation-results.md +validation_required: + - role at source time and role eligibility + - sample-size and concentration disclosure + - scope mismatch and unsupported generalization + - proposition and statement lineage + - existing content overlap + - structured data, staging isolation, public build diff --git a/staging/batches/BATCH-2026-010/measurement-matrix.csv b/staging/batches/BATCH-2026-010/measurement-matrix.csv new file mode 100644 index 0000000..aa5a95e --- /dev/null +++ b/staging/batches/BATCH-2026-010/measurement-matrix.csv @@ -0,0 +1,9 @@ +"measurement_dimension","ciso_evidence","cio_evidence","cto_evidence","status","proposed_comparable_measure" +"Agent inventory coverage","none","none","none","gap","Known agents divided by independently discovered agents, with scope stated" +"Identity and principal traceability","none","none","none","gap","Share of sampled actions resolving to agent instance and delegating principal" +"Authorization quality","none","none","none","gap","Unauthorized-action rate and legitimate-task denial rate" +"Credential lifecycle","none","none","none","gap","Issuance, rotation, revocation latency, orphaned credentials, and task failure" +"Security and utility","none","none","none","gap","Benign utility, utility under attack, attack success, and production incident linkage" +"Monitoring performance","none","none","none","gap","Missed-event, false-positive, review-latency, privacy, and cost measures" +"Economic framing","none","none","none","gap","Control cost, incident loss, implementation time, and budget ownership" +"Governance performance","none","none","none","gap","Decision-right clarity, exception age, unresolved ownership, and audit closure time" diff --git a/staging/batches/BATCH-2026-010/risk-framing-matrix.csv b/staging/batches/BATCH-2026-010/risk-framing-matrix.csv new file mode 100644 index 0000000..6415dbe --- /dev/null +++ b/staging/batches/BATCH-2026-010/risk-framing-matrix.csv @@ -0,0 +1,8 @@ +"risk_dimension","ciso_finding","cio_finding","cto_finding","status","research_needed" +"Unauthorized access","not determinable","not determinable","not determinable","gap","Ask each role who owns inventory, access policy, enforcement, and incident response." +"Credential compromise and lifecycle","not determinable","not determinable","not determinable","gap","Compare security control, platform operations, and architecture responsibilities." +"Delegation and principal traceability","not determinable","not determinable","not determinable","gap","Test accountability and privacy tradeoffs with all three roles." +"Agent reliability and availability","not determinable","not determinable","not determinable","gap","Compare risk thresholds and service-level measures." +"Monitoring, audit, and shutdown","not determinable","not determinable","not determinable","gap","Map operational ownership and escalation paths." +"Legal and regulatory exposure","not determinable","not determinable","not determinable","gap","Add general-counsel evidence to prevent a technology-only comparison." +"Budget and organizational incentives","not determinable","not determinable","not determinable","gap","Record budget owner, procurement signer, control cost, and loss framing." diff --git a/staging/batches/BATCH-2026-010/role-comparison.json b/staging/batches/BATCH-2026-010/role-comparison.json new file mode 100644 index 0000000..3c02a0d --- /dev/null +++ b/staging/batches/BATCH-2026-010/role-comparison.json @@ -0,0 +1,351 @@ +{ + "comparison_id": "role-comparison-BATCH-2026-010-001", + "batch_id": "BATCH-2026-010", + "topic": "Governed identities for AI agents", + "roles": [ + "role-ciso", + "role-cio", + "role-cto" + ], + "time_period": "2020-08-15 through 2026-08-15, with pre-2020 foundations only when directly applicable", + "status": "role_evidence_gap_only", + "role_metrics": { + "role-ciso": { + "people": 0, + "sources": 0, + "statements": 0, + "organizations": 0, + "source_types": [], + "regions": [], + "industries": [], + "date_range": null, + "off_owned_source_share": null, + "vendor_source_share": null, + "consulting_source_share": null, + "role_at_source_time_evidence": 0, + "staging_relevance_tag_mentions": 46 + }, + "role-cio": { + "people": 0, + "sources": 0, + "statements": 0, + "organizations": 0, + "source_types": [], + "regions": [], + "industries": [], + "date_range": null, + "off_owned_source_share": null, + "vendor_source_share": null, + "consulting_source_share": null, + "role_at_source_time_evidence": 0, + "staging_relevance_tag_mentions": 46 + }, + "role-cto": { + "people": 0, + "sources": 0, + "statements": 0, + "organizations": 0, + "source_types": [], + "regions": [], + "industries": [], + "date_range": null, + "off_owned_source_share": null, + "vendor_source_share": null, + "consulting_source_share": null, + "role_at_source_time_evidence": 0, + "staging_relevance_tag_mentions": 46 + } + }, + "analysis_dimensions": { + "problem_definition": { + "role-ciso": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + }, + "role-cio": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + }, + "role-cto": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + } + }, + "strategic_priority": { + "role-ciso": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + }, + "role-cio": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + }, + "role-cto": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + } + }, + "desired_outcomes": { + "role-ciso": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + }, + "role-cio": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + }, + "role-cto": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + } + }, + "risk_concerns": { + "role-ciso": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + }, + "role-cio": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + }, + "role-cto": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + } + }, + "control_concerns": { + "role-ciso": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + }, + "role-cio": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + }, + "role-cto": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + } + }, + "measurement_approach": { + "role-ciso": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + }, + "role-cio": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + }, + "role-cto": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + } + }, + "budget_and_economic_framing": { + "role-ciso": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + }, + "role-cio": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + }, + "role-cto": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + } + }, + "time_horizon": { + "role-ciso": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + }, + "role-cio": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + }, + "role-cto": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + } + }, + "governance_model": { + "role-ciso": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + }, + "role-cio": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + }, + "role-cto": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + } + }, + "implementation_ownership": { + "role-ciso": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + }, + "role-cio": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + }, + "role-cto": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + } + }, + "technology_assumptions": { + "role-ciso": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + }, + "role-cio": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + }, + "role-cto": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + } + }, + "legal_assumptions": { + "role-ciso": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + }, + "role-cio": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + }, + "role-cto": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + } + }, + "data_assumptions": { + "role-ciso": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + }, + "role-cio": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + }, + "role-cto": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + } + }, + "talent_assumptions": { + "role-ciso": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + }, + "role-cio": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + }, + "role-cto": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + } + }, + "evidence_used": { + "role-ciso": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + }, + "role-cio": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + }, + "role-cto": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + } + }, + "common_vocabulary": { + "role-ciso": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + }, + "role-cio": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + }, + "role-cto": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + } + }, + "common_frameworks": { + "role-ciso": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + }, + "role-cio": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + }, + "role-cto": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + } + }, + "missing_issues": { + "role-ciso": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + }, + "role-cio": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + }, + "role-cto": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + } + }, + "internal_disagreement": { + "role-ciso": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + }, + "role-cio": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + }, + "role-cto": { + "finding": null, + "status": "insufficient_role_at_source_time_evidence" + } + } + }, + "comparison_findings": { + "genuine_alignment": null, + "genuine_disagreement": null, + "different_emphasis": null, + "different_responsibility": null, + "different_time_horizon": null, + "different_evidence_standard": null, + "different_risk_tolerance": null, + "different_organizational_incentives": null, + "overlooked_issues": null, + "scope_corrected_apparent_disagreement": "No comparison was attempted. Shared relevance tags and current job titles were excluded from role attribution." + }, + "included_source_ids": [], + "included_statement_ids": [], + "included_proposition_ids": [], + "strongest_alignment": "not_determinable", + "strongest_disagreement": "not_determinable", + "largest_scope_mismatch": "Forty-six staging statements are tagged as relevant to each selected role, but zero are attributed to a CISO, CIO, or CTO speaking in that role at source time.", + "largest_evidence_gap": "No production operator evidence connects executive role responsibility to agent identity, authorization, budget, implementation, measurement, or accountability decisions.", + "workflow_status": "candidate", + "machine_review_status": "ready_for_human_review", + "human_review_status": "pending", + "reviewed_by": null, + "reviewed_at": null +} diff --git a/staging/batches/BATCH-2026-010/role-evidence-gap-briefing.md b/staging/batches/BATCH-2026-010/role-evidence-gap-briefing.md new file mode 100644 index 0000000..60fe086 --- /dev/null +++ b/staging/batches/BATCH-2026-010/role-evidence-gap-briefing.md @@ -0,0 +1,57 @@ +# Role-evidence-gap briefing: CISO, CIO, and CTO framing of governed identities for AI agents + +Status: **Comparison ineligible; no role findings produced.** + +## Decision + +The production index contains no topic sources, people, statements, propositions, or role-at-source-time records for CISO, CIO, or CTO. Each role therefore has zero people, sources, statements, organizations, source types, regions, industries, and date coverage. Ownership and vendor shares are undefined because every denominator is zero. + +The repository has no configured publication threshold specifically for a role comparison. Before examining the evidence, this batch set a minimal comparison floor of three independently checked production sources, two people, two organizations, and five substantive role-attributed statements per role. This is an editorial comparison floor, not a new repository publication threshold. All three roles fail it. + +## Why the staged corpus cannot substitute + +All 46 staged statements from BATCH-2026-006 carry CISO, CIO, and CTO relevance tags. Those tags identify likely executive usefulness; they do not identify the role that expressed the statement. The actual source-time labels are institutional author, research author, standards author, editor, or contributor. Counting the same 46 records under each role would manufacture identical samples and then mistake shared tagging for alignment. + +One staged person illustrates the prohibited current-role backfill. Luca Beurer-Kellner has a current CTO record, but his role in the indexed AgentDojo paper is Author. His statements cannot enter a CTO sample unless a separate source records him speaking as CTO at that source time. The same rule applies even when a current title appears highly relevant. + +## Evidence by role + +| Role | People | Sources | Statements | Organizations | Source types | Regions | Industries | Role-at-source-time evidence | +|---|---:|---:|---:|---:|---:|---:|---:|---:| +| CISO | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | +| CIO | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | +| CTO | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | + +## What cannot yet be compared + +The index cannot determine how any selected role defines the problem, prioritizes outcomes, frames risk, chooses controls, measures performance, allocates budget, sets a time horizon, assigns implementation ownership, or treats technical, legal, data, and talent assumptions. It also cannot identify internal disagreement within a role. Filling those cells with expected job responsibilities would be role stereotyping, not evidence synthesis. + +There is no verified alignment or disagreement. The shared relevance tags establish only that agent identity governance may matter to all three roles. They do not show agreement on responsibility, design, risk tolerance, evidence standards, incentives, or time horizon. + +## Largest scope mismatch + +The largest mismatch is 46-to-zero: each of the 46 staged statements is tagged as relevant to CISO, CIO, and CTO readers, while none is spoken in an indexed CISO, CIO, or CTO role at source time. Other corrected mismatches include current CTO status versus Author at source time, institutional guidance versus executive testimony, academic security results versus executive priorities, and combined “CIO or CTO” survey categories versus role-specific evidence. + +## What a valid comparison needs + +A valid sample should ask the same core questions of each role while allowing role-specific follow-ups. It should record a concrete deployed agent, the decision the person made, their authority, other responsible roles, the evidence used, the denominator, the outcome, organization and industry context, geography, regulation, and time horizon. It should include failed or abandoned approaches and more than one position within each role. + +The strongest design is a matched organizational case: interview a CISO, CIO, and CTO about the same agent deployment. That would distinguish responsibility from disagreement. A CISO emphasizing unauthorized access and a CTO emphasizing task utility may be answering different questions; only the shared case and decision point reveal whether their positions actually conflict. + +## Research questions by role + +For CISOs, the missing evidence concerns inventory coverage, access risk, policy enforcement, incident response, monitoring, audit, legal exposure, board reporting, and security budget. For CIOs, it concerns platform ownership, lifecycle operations, identity integration, reliability, procurement, service economics, and business-unit coordination. For CTOs, it concerns architecture, agent identity granularity, delegation, developer controls, interoperability, benchmark use, task utility, and shutdown design. These are research targets—not findings about the roles. + +## Existing OFF content + +OFF publishes relevant CISO operator research and CISO and CTO community pages. They were reviewed only to avoid duplicating an existing agenda. They are not indexed production evidence. The CISO report’s mixed-room and role-specific cuts need exact ingestion and disclosure; the CTO page is a community agenda; combined “CIO or CTO” buyer results cannot support a CIO–CTO comparison. + +## Recommended interviews and roundtable + +The shared interview anchor is: **Think about the last production agent whose access or action created a decision you personally had to make. What was the decision, what evidence did you use, who else had authority, and what outcome did you measure?** + +The primary OFF roundtable question is: **When an agent’s access becomes the incident, which seat owns the inventory, authorization policy, budget, containment, and accountability—and where do those handoffs fail today?** + +## Human-review requirement + +No record in this package is human approved. A named reviewer should confirm the selected roles, the editorial comparison floor, the role-at-source-time exclusions, the OFF overlap treatment, and the proposed research instruments before fieldwork or publication. diff --git a/staging/batches/BATCH-2026-010/role-evidence-table.csv b/staging/batches/BATCH-2026-010/role-evidence-table.csv new file mode 100644 index 0000000..a0829fc --- /dev/null +++ b/staging/batches/BATCH-2026-010/role-evidence-table.csv @@ -0,0 +1,4 @@ +"role_id","production_evidence","what_can_be_said","what_cannot_be_said","minimum_missing_sample" +"role-ciso","none","The indexed production corpus cannot determine CISO framing.","Problem, risk, control, budget, ownership, measurement, or board-reporting emphasis.","3 independent sources; 2 people; 2 organizations; 5 role-attributed statements" +"role-cio","none","The indexed production corpus cannot determine CIO framing.","Platform ownership, integration, lifecycle operations, procurement, service reliability, or inventory emphasis.","3 independent sources; 2 people; 2 organizations; 5 role-attributed statements" +"role-cto","none","The indexed production corpus cannot determine CTO framing.","Architecture, developer controls, protocol choices, deployment tradeoffs, interoperability, or shutdown design emphasis.","3 independent sources; 2 people; 2 organizations; 5 role-attributed statements" diff --git a/staging/batches/BATCH-2026-010/role-proposition-matrix.csv b/staging/batches/BATCH-2026-010/role-proposition-matrix.csv new file mode 100644 index 0000000..1c0c844 --- /dev/null +++ b/staging/batches/BATCH-2026-010/role-proposition-matrix.csv @@ -0,0 +1,10 @@ +"candidate_id","candidate_idea","canonical_proposition","ciso_role_attributed_support","cio_role_attributed_support","cto_role_attributed_support","comparison_use" +"proposition-candidate-BATCH-2026-006-001","Agents should have stable identities distinct from the principals they represent.","no","0","0","0","excluded; candidate-only and not role-attributed" +"proposition-candidate-BATCH-2026-006-002","Delegated authority should preserve both principal and agent context.","no","0","0","0","excluded; candidate-only and not role-attributed" +"proposition-candidate-BATCH-2026-006-003","Agent permissions should be bounded by least privilege and attenuated across delegation.","no","0","0","0","excluded; candidate-only and not role-attributed" +"proposition-candidate-BATCH-2026-006-004","Agent identity governance should include provisioning, rotation, revocation, and de-provisioning.","no","0","0","0","excluded; candidate-only and not role-attributed" +"proposition-candidate-BATCH-2026-006-005","Auditability depends on traceable identity and authorization context.","no","0","0","0","excluded; candidate-only and not role-attributed" +"proposition-candidate-BATCH-2026-006-006","Agent systems need layered evaluation, authorization controls, and monitoring.","no","0","0","0","excluded; candidate-only and not role-attributed" +"proposition-candidate-BATCH-2026-006-007","Users and deployers need reliable mechanisms to interrupt agents and their subagents.","no","0","0","0","excluded; candidate-only and not role-attributed" +"proposition-candidate-BATCH-2026-006-008","Synthetic security benchmarks demonstrate capabilities but do not estimate production prevalence.","no","0","0","0","excluded; candidate-only and not role-attributed" +"proposition-candidate-BATCH-2026-006-009","Multi-agent coordination can increase cybersecurity capability and associated governance risk.","no","0","0","0","excluded; candidate-only and not role-attributed" diff --git a/staging/batches/BATCH-2026-010/role-source-distribution.csv b/staging/batches/BATCH-2026-010/role-source-distribution.csv new file mode 100644 index 0000000..d8525e5 --- /dev/null +++ b/staging/batches/BATCH-2026-010/role-source-distribution.csv @@ -0,0 +1,4 @@ +"role_id","role_label","people","sources","statements","organizations","source_types","regions","industries","date_range","off_owned_source_share","vendor_source_share","role_at_source_time_evidence","staging_relevance_tags","eligibility" +"role-ciso","Chief Information Security Officer","0","0","0","0","none","none","none","not available","undefined (0 denominator)","undefined (0 denominator)","0","46","below floor" +"role-cio","Chief Information Officer","0","0","0","0","none","none","none","not available","undefined (0 denominator)","undefined (0 denominator)","0","46","below floor" +"role-cto","Chief Technology Officer","0","0","0","0","none","none","none","not available","undefined (0 denominator)","undefined (0 denominator)","0","46","below floor" diff --git a/staging/batches/BATCH-2026-010/roundtable-questions.md b/staging/batches/BATCH-2026-010/roundtable-questions.md new file mode 100644 index 0000000..b1eddfb --- /dev/null +++ b/staging/batches/BATCH-2026-010/roundtable-questions.md @@ -0,0 +1,20 @@ +# Proposed OFF roundtable questions + +## Primary question + +**When an agent’s access becomes the incident, which seat owns the inventory, authorization policy, budget, containment, and accountability—and where do those handoffs fail today?** + +## Follow-ups + +1. What is the smallest useful unit of agent identity in your environment? +2. Which action can an agent take today that no single executive believes they own? +3. What evidence would persuade security to permit, IT to operate, and engineering to scale the same agent? +4. Where does least privilege become operationally unusable? +5. Which approval is meaningful, and which approval has become ceremonial? +6. What is your denominator for agent inventory coverage? +7. Who pays for the shared control layer when product teams capture the benefit? +8. Which legal or privacy requirement conflicts with principal traceability? +9. What failed implementation should peers learn from? +10. What result would change your governance model during the next 12 months? + +Responses should be captured with role at source time, organization type, industry, geography, production status, denominator, and permission for attribution or anonymized use. diff --git a/staging/batches/BATCH-2026-010/scope-mismatch-review.csv b/staging/batches/BATCH-2026-010/scope-mismatch-review.csv new file mode 100644 index 0000000..a14c49c --- /dev/null +++ b/staging/batches/BATCH-2026-010/scope-mismatch-review.csv @@ -0,0 +1,8 @@ +"review_id","record_or_claim","apparent_role","actual_scope","decision","false_comparison_prevented","human_review_status" +"SM-001","All 46 BATCH-2026-006 statements carry role-ciso, role-cio, and role-cto relevance tags","CISO/CIO/CTO","Executive relevance only; author roles are institutional, research, standards, editor, contributor, or author","Exclude from role-attributed evidence","yes","pending" +"SM-002","person-BATCH-2026-005-luca-beurer-kellner current role is Chief Technology Officer","CTO","Role at indexed AgentDojo source time is Author; current role cannot be backfilled","Exclude from CTO sample","yes","pending" +"SM-003","NIST and standards recommendations concern security, technology, and information functions","CISO/CIO/CTO","Institutional-author positions, not executive-role testimony","Retain only as future topic evidence after review","yes","pending" +"SM-004","Academic authors evaluate agent attacks and defenses","CTO or CISO","Research evidence; author role does not establish executive responsibility or priorities","Exclude from role comparison","yes","pending" +"SM-005","OFF CISO report describes a mixed security room and a smaller security-leader cut","CISO","External OFF content not ingested; mixed-room results cannot be assigned wholesale to CISOs","Future verification must use role-tagged respondent denominators","yes","pending" +"SM-006","OFF buyer results combine CIO or CTO","CIO versus CTO","Combined response category cannot distinguish the two roles","Do not use for CIO–CTO comparison","yes","pending" +"SM-007","OFF CTO community page lists identity, authorization, and audit topics","CTO","Community agenda and marketing description, not a verified statement sample","Overlap only; not role evidence","yes","pending" diff --git a/staging/batches/BATCH-2026-010/validation-results.md b/staging/batches/BATCH-2026-010/validation-results.md new file mode 100644 index 0000000..6a46cfe --- /dev/null +++ b/staging/batches/BATCH-2026-010/validation-results.md @@ -0,0 +1,33 @@ +# Validation results + +Overall: **PASS** + +| Check | Status | Detail | +|---|---|---| +| Structured data checks | PASS | JSON and YAML records parse successfully. | +| Role-at-source-time checks | PASS | Current title and relevance tags are excluded; source-time role controls attribution. | +| Role threshold checks | PASS | All three roles fail the pre-registered editorial comparison floor. | +| Sample-size disclosure checks | PASS | Every role denominator is disclosed as zero. | +| Source concentration checks | PASS | Shares remain null rather than 0% for empty denominators. | +| Scope mismatch checks | PASS | Seven mismatches were explicitly corrected. | +| Unsupported generalization checks | PASS | Role stereotypes and universal claims are absent. | +| Proposition lineage checks | PASS | No candidate proposition is treated as role evidence. | +| Statement lineage checks | PASS | No staging statement is included in the comparison corpus. | +| Existing content overlap checks | PASS | OFF content is overlap-only and combined role categories are excluded. | +| Comparison withholding checks | PASS | No alignment or disagreement is fabricated. | +| Question deliverable checks | PASS | Interview and roundtable instruments are present. | +| Matrix completeness checks | PASS | All requested evidence, proposition, risk, measurement, distribution, and gap matrices exist. | +| Staging isolation checks | PASS | No production content or canonical comparison record was created. | +| Human review checks | PASS | No machine output is marked human approved. | +| Near-duplicate checks | PASS | 16 substantive paragraphs are unique. | + +## Repository-wide checks + +Executed on 2026-08-15 after the dedicated batch checks: + +- Canonical data, provenance, review-status, publication, and content validations: PASS +- External-link audit: PASS +- Repository tests: 24 passed across 4 test files +- Public build: PASS; 28 static pages generated +- Search index and post-build artifact generation: PASS +- Git whitespace/error check: PASS