Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
101 changes: 101 additions & 0 deletions staging/batches/BATCH-2026-010/eligibility-check.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,101 @@
{
"batch_id": "BATCH-2026-010",
"prompt_id": "OEII-ROLE-COMPARISON",
"prompt_version": "2.0",
"topic": "Governed identities for AI agents",
"time_period": "2020-08-15 through 2026-08-15, with pre-2020 foundations only when directly applicable",
"selected_roles": [
"role-ciso",
"role-cio",
"role-cto"
],
"repository_configured_role_comparison_threshold": null,
"comparison_eligibility_floor": {
"status": "pre_registered_editorial_floor_for_this_batch_not_a_publication_threshold",
"per_role": {
"independently_checked_production_sources": 3,
"people_with_role_at_source_time": 2,
"organizations": 2,
"substantive_role_attributed_statements": 5
},
"requirements": [
"Role at source time verified",
"Statement and proposition lineage complete",
"No single-source comparison",
"Sample and concentration disclosed"
]
},
"production_metrics": {
"role-ciso": {
"people": 0,
"sources": 0,
"statements": 0,
"organizations": 0,
"source_types": [],
"regions": [],
"industries": [],
"date_range": null,
"off_owned_source_share": null,
"vendor_source_share": null,
"consulting_source_share": null,
"role_at_source_time_evidence": 0,
"staging_relevance_tag_mentions": 46
},
"role-cio": {
"people": 0,
"sources": 0,
"statements": 0,
"organizations": 0,
"source_types": [],
"regions": [],
"industries": [],
"date_range": null,
"off_owned_source_share": null,
"vendor_source_share": null,
"consulting_source_share": null,
"role_at_source_time_evidence": 0,
"staging_relevance_tag_mentions": 46
},
"role-cto": {
"people": 0,
"sources": 0,
"statements": 0,
"organizations": 0,
"source_types": [],
"regions": [],
"industries": [],
"date_range": null,
"off_owned_source_share": null,
"vendor_source_share": null,
"consulting_source_share": null,
"role_at_source_time_evidence": 0,
"staging_relevance_tag_mentions": 46
}
},
"roles_meeting_floor": [],
"roles_below_floor": [
"role-ciso",
"role-cio",
"role-cto"
],
"comparison_status": "INELIGIBLE_ROLE_EVIDENCE_GAP_BRIEFING_ONLY",
"reason": "Canonical role, person, source, statement, proposition, and dossier directories contain no topic records. Staging statements are relevance-tagged for all selected roles but are authored by institutional, research, standards, editor, contributor, or author roles rather than by indexed CISO, CIO, or CTO speakers at source time.",
"source_concentration": {
"production_denominator": 0,
"off_owned_share": null,
"vendor_share": null,
"largest_source_share": null
},
"staging_context_not_evidence": {
"shared_relevance_tag_count_per_role": 46,
"direct_ciso_role_at_source_time_statements": 0,
"direct_cio_role_at_source_time_statements": 0,
"direct_cto_role_at_source_time_statements": 0,
"current_cto_records_that_must_not_be_backfilled": 1,
"example_person_id": "person-BATCH-2026-005-luca-beurer-kellner",
"example_current_role": "Chief Technology Officer",
"example_role_at_source_time": "Author",
"use_restriction": "Research-gap and scope-correction planning only; not role evidence."
},
"human_review_status": "pending"
}
9 changes: 9 additions & 0 deletions staging/batches/BATCH-2026-010/evidence-gap-table.csv
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
"gap_id","dimension","roles_affected","current_evidence","missing_evidence","recommended_batch"
"G-001","Role-at-source-time corpus","CISO; CIO; CTO","0 eligible records","Direct statements by people verified in each role at source time","Role-specific operator interview batch"
"G-002","Implementation ownership","CISO; CIO; CTO","0","Decision rights for inventory, identity platform, authorization policy, monitoring, incident response, and shutdown","Cross-functional operating-model case batch"
"G-003","Measurement","CISO; CIO; CTO","0","Comparable denominators for inventory, access, incident, utility, reliability, cost, and audit outcomes","Metrics and implementation study"
"G-004","Budget and incentives","CISO; CIO; CTO","0","Budget owner, buyer, signer, cost center, loss model, and resource tradeoffs","Executive budget and governance survey"
"G-005","Internal disagreement","CISO; CIO; CTO","0","Multiple independent sources within each role, including dissenting or failed approaches","Role-diversity and counterposition batch"
"G-006","Geography and industry","CISO; CIO; CTO","0","Role evidence across regions, regulation, organization sizes, and industries","Regional and industry role batch"
"G-007","Legal and data assumptions","CISO; CIO; CTO","0","Comparable legal, privacy, retention, and data-governance assumptions","Add general counsel and data leadership comparison"
"G-008","Production evidence promotion","CISO; CIO; CTO","No canonical sources, statements, or propositions","Named human review and production promotion","Human-review and publication-readiness batch"
22 changes: 22 additions & 0 deletions staging/batches/BATCH-2026-010/evidence-gaps.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
# Evidence gaps and recommended batches

All three selected roles are below the comparison floor. The gap is not a difference in source volume between roles; it is the absence of any production role-at-source-time corpus.

## Priority gaps

1. Recruit at least three independently checked sources, two people, two organizations, and five substantive statements for each role before comparison.
2. Record role at source time, not current role, and distinguish personal views from institutional positions.
3. Capture the same core questions across roles so responsibility and emphasis can be compared without false symmetry.
4. Add implementation evidence with denominators, failures, costs, and time horizons—not only recommendations.
5. Add general counsel, finance, board, and business-unit evidence before drawing conclusions about cross-functional governance.
6. Sample multiple industries and regions and preserve organization size, regulatory scope, and level of agent autonomy.
7. Seek internal counterpositions within each role; one interview cannot establish role literature.

## Recommended sequence

- **CISO operator batch:** inventory, access risk, incident response, monitoring, board reporting, and security budget.
- **CIO operator batch:** platform ownership, lifecycle operations, procurement, integration, reliability, and shared-service economics.
- **CTO operator batch:** architecture, identity granularity, delegation, developer controls, benchmark use, and shutdown design.
- **Cross-functional case batch:** interview CISO, CIO, and CTO participants from the same organization about one deployed agent.
- **Counterposition batch:** privacy, surveillance, over-control, user burden, innovation cost, and failed controls.
- **Human-review batch:** validate role attribution, exact locators, organization and geography fields, statement lineage, and publication readiness.
10 changes: 10 additions & 0 deletions staging/batches/BATCH-2026-010/existing-content-overlap.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
# Existing content overlap

Official OFF pages were checked on 2026-08-15 for research design and duplication only.

- [Forum Select for CISOs](https://openfutureforum.com/for-cisos) lists AI security, governance, regulation, board reporting, and zero-trust discussion topics. It is a community description, not an indexed role-attributed corpus.
- The [CISO AI Leverage Report](https://openfutureforum.com/research/ciso-ai-leverage-report) contains potentially relevant role-tagged and mixed-room findings. It remains outside the repository corpus and requires verification of respondent classification, denominators, methods, exact locators, ownership, sponsorship, and advisory disclosures.
- [Forum Select for CTOs](https://openfutureforum.com/for-ctos) mentions production agent identity, authorization, audit trails, and CTO–CISO risk. It describes an agenda, not verified CTO positions.
- Some OFF buyer findings combine “CIO or CTO.” That category cannot distinguish CIO from CTO and must not be used for this comparison.

No OFF page was counted as evidence. A future ingestion batch should preserve role-specific cuts and treat community, marketing, operator-research, and interview content as different source types.
29 changes: 29 additions & 0 deletions staging/batches/BATCH-2026-010/interview-questions.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,29 @@
# Proposed interview questions

## Shared anchor

**Think about the last production agent whose access or action created a decision you personally had to make. What was the decision, what evidence did you use, who else had authority, and what outcome did you measure?**

## CISO

1. Which agent identities and connections are visible to security today, and what denominator tells you coverage?
2. Which agent actions require policy enforcement, human approval, automated monitoring, or a hard prohibition?
3. When agent access becomes an incident, who owns containment, revocation, evidence preservation, and board reporting?
4. Which security measures justify budget: unauthorized actions, incident loss, coverage, response time, or something else?
5. Where has a security control blocked legitimate agent work or encouraged teams to route around it?

## CIO

1. Which platform owns agent inventory, identity issuance, lifecycle events, and integration with enterprise IAM?
2. How do you measure reliability, orphaned identities, revocation latency, and cross-system interoperability?
3. Where do business-unit autonomy and enterprise control conflict in agent deployment?
4. Who funds shared identity infrastructure when individual teams own the agents?
5. Which responsibility is regularly assigned to the CIO but cannot be delivered without the CISO or CTO?

## CTO

1. At what granularity do you identify agents—class, deployment, instance, session, or task—and why?
2. How does authority attenuate when an agent delegates to tools or subagents?
3. Which security controls materially reduce task utility, latency, or developer velocity?
4. What benchmark or production evidence changes a model, architecture, or deployment decision?
5. Who can stop an agent and its descendants, and how is that authority tested?
14 changes: 14 additions & 0 deletions staging/batches/BATCH-2026-010/limitations.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
# Limitations

- The production topic corpus and each selected role corpus are empty.
- The repository has no configured numeric role-comparison threshold; the operational floor is explicitly batch-specific and requires human review.
- Staging relevance tags identify potential audience, not speaker role.
- Current roles cannot be backfilled into historical sources.
- Staging sources and statements remain human-review pending and were not used as role evidence.
- No canonical proposition or stance record exists for proposition-by-role comparison.
- No sample supports internal disagreement, role alignment, role emphasis, responsibility, risk tolerance, incentive, or time-horizon findings.
- Production source-concentration shares are undefined with a zero denominator.
- OFF web content was checked for overlap only and has not been ingested or independently verified in the repository.
- Proposed dimensions, metrics, interviews, and roundtable questions are research designs, not findings.
- The CISO/CIO/CTO selection omits general counsel, CFO, CEO, board, data, business-unit, and product roles that may materially shape governance.
- All outputs are machine-produced and human-review pending.
54 changes: 54 additions & 0 deletions staging/batches/BATCH-2026-010/manifest.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,54 @@
batch_id: BATCH-2026-010
prompt_id: OEII-ROLE-COMPARISON
prompt_version: "2.0"
topic: Governed identities for AI agents
topic_slug: governed-agent-identities
roles: [role-ciso, role-cio, role-cto]
time_period: 2020-08-15 through 2026-08-15, with pre-2020 foundations only when directly applicable
branch: analysis/role-comparison-governed-agent-identities-BATCH-2026-010
base_branch: research/people-BATCH-2026-007
execution_date: 2026-08-15
execution_completed_at: 2026-08-15T17:30:00-07:00
agent_or_researcher: OpenAI Codex; machine-assisted role eligibility, source-time attribution, scope correction, and research-gap design; named human review pending
model_disclosure: AI-assisted canonical inventory, role-at-source-time audit, gap briefing, matrix and question drafting, OFF overlap search, and validation; no role finding or human approval was inferred.
comparison_status: INELIGIBLE_ROLE_EVIDENCE_GAP_BRIEFING_ONLY
roles_meeting_floor: 0
roles_below_floor: 3
ciso_people: 0
ciso_sources: 0
ciso_statements: 0
cio_people: 0
cio_sources: 0
cio_statements: 0
cto_people: 0
cto_sources: 0
cto_statements: 0
shared_staging_relevance_tags_per_role: 46
eligible_role_at_source_time_statements_per_role: 0
scope_mismatches_corrected: 7
human_review_status: pending
output_files:
- manifest.yml
- eligibility-check.json
- role-evidence-gap-briefing.md
- role-comparison.json
- role-evidence-table.csv
- role-source-distribution.csv
- role-proposition-matrix.csv
- risk-framing-matrix.csv
- measurement-matrix.csv
- scope-mismatch-review.csv
- evidence-gap-table.csv
- evidence-gaps.md
- interview-questions.md
- roundtable-questions.md
- existing-content-overlap.md
- limitations.md
- validation-results.md
validation_required:
- role at source time and role eligibility
- sample-size and concentration disclosure
- scope mismatch and unsupported generalization
- proposition and statement lineage
- existing content overlap
- structured data, staging isolation, public build
9 changes: 9 additions & 0 deletions staging/batches/BATCH-2026-010/measurement-matrix.csv
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
"measurement_dimension","ciso_evidence","cio_evidence","cto_evidence","status","proposed_comparable_measure"
"Agent inventory coverage","none","none","none","gap","Known agents divided by independently discovered agents, with scope stated"
"Identity and principal traceability","none","none","none","gap","Share of sampled actions resolving to agent instance and delegating principal"
"Authorization quality","none","none","none","gap","Unauthorized-action rate and legitimate-task denial rate"
"Credential lifecycle","none","none","none","gap","Issuance, rotation, revocation latency, orphaned credentials, and task failure"
"Security and utility","none","none","none","gap","Benign utility, utility under attack, attack success, and production incident linkage"
"Monitoring performance","none","none","none","gap","Missed-event, false-positive, review-latency, privacy, and cost measures"
"Economic framing","none","none","none","gap","Control cost, incident loss, implementation time, and budget ownership"
"Governance performance","none","none","none","gap","Decision-right clarity, exception age, unresolved ownership, and audit closure time"
8 changes: 8 additions & 0 deletions staging/batches/BATCH-2026-010/risk-framing-matrix.csv
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
"risk_dimension","ciso_finding","cio_finding","cto_finding","status","research_needed"
"Unauthorized access","not determinable","not determinable","not determinable","gap","Ask each role who owns inventory, access policy, enforcement, and incident response."
"Credential compromise and lifecycle","not determinable","not determinable","not determinable","gap","Compare security control, platform operations, and architecture responsibilities."
"Delegation and principal traceability","not determinable","not determinable","not determinable","gap","Test accountability and privacy tradeoffs with all three roles."
"Agent reliability and availability","not determinable","not determinable","not determinable","gap","Compare risk thresholds and service-level measures."
"Monitoring, audit, and shutdown","not determinable","not determinable","not determinable","gap","Map operational ownership and escalation paths."
"Legal and regulatory exposure","not determinable","not determinable","not determinable","gap","Add general-counsel evidence to prevent a technology-only comparison."
"Budget and organizational incentives","not determinable","not determinable","not determinable","gap","Record budget owner, procurement signer, control cost, and loss framing."
Loading
Loading