{
  "schemaVersion": 1,
  "initiative": "EVE_SOTA_GAP_CLOSURE",
  "task": "0.4",
  "asOf": "2026-09-01",
  "retrievedAt": "2026-09-01T17:12:02Z",
  "status": "point-in-time-crosswalk",
  "sourcePolicy": {
    "authority": "Only publisher-controlled publication pages, versioned specification sites, tagged repositories, and byte-identical publisher artifacts are authoritative. Search results, SDK behavior, local type names, and secondary summaries are not source evidence.",
    "hashing": "Every downloaded document and every version-defining repository file is pinned with SHA-256 over the exact retrieved bytes. Repository-backed sources also pin tag and full commit.",
    "refresh": "Task 18.3 must re-fetch all sources, resolve current releases and errata, compare hashes and normative language, and issue a replacement dated record. Mutable development snapshots require an explicit adoption pin before implementation claims compatibility.",
    "claimBoundary": "A local control proves only the behavior named in its evidence entry. Similar names or shapes do not prove protocol, accessibility, security-framework, or telemetry conformance."
  },
  "classificationPolicy": {
    "externalNormativity": {
      "GUIDANCE": "Voluntary or community risk guidance; no external MUST is created.",
      "MUST_IF_ADOPTED": "Normative protocol requirement that binds only an implementation claiming the named protocol/version and applicable capability.",
      "SHOULD_IF_ADOPTED": "Normative recommendation whose applicability begins only after the named protocol/version and capability are adopted.",
      "NORMATIVE_RECOMMENDATION": "Normative W3C Recommendation content; a conformance claim is optional, but the named criteria bind a claim once made.",
      "OPTIONAL_PATTERN": "Compatibility pattern being evaluated; it is not an initiative requirement unless a later ADR adopts it.",
      "DEVELOPMENT_CONVENTION": "Unstable semantic convention snapshot; useful design input, not a stable compliance target."
    },
    "initiativeDisposition": {
      "adopted-risk-guidance": "The initiative uses the risk/action as internal planning input without claiming external certification.",
      "conditional-protocol-requirement": "The requirement becomes an initiative MUST only if the protocol/version/capability is admitted by the named downstream decision.",
      "optional-compatibility-decision": "The downstream task must decide adopt, adapt, or remain bespoke; compatibility is not presumed.",
      "required-wcag-aa": "The initiative has independently adopted WCAG 2.2 Level AA as an internal release gate; this record does not claim that gate is already met or establish legal compliance.",
      "optional-observability-alignment": "The downstream task may adopt and pin the convention where useful; current bespoke telemetry is not labeled conformant."
    }
  },
  "sources": [
    {
      "id": "nist-ai-rmf-1.0",
      "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0)",
      "publisher": "National Institute of Standards and Technology",
      "version": "NIST AI 100-1",
      "publishedAt": "2023-01-26",
      "canonicalUrl": "https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10",
      "artifactUrl": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf",
      "externalForce": "voluntary-guidance",
      "artifact": {
        "sha256": "7576edb531d9848825814ee88e28b1795d3a84b435b4b797d3670eafdc4a89f1",
        "bytes": 1946127,
        "mediaType": "application/pdf"
      },
      "note": "The publication describes itself as voluntary. NIST is revising the framework; this record intentionally pins 1.0 rather than projecting future text."
    },
    {
      "id": "nist-genai-profile-600-1",
      "title": "Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile",
      "publisher": "National Institute of Standards and Technology",
      "version": "NIST AI 600-1",
      "publishedAt": "2024-07-26",
      "canonicalUrl": "https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-generative-artificial-intelligence",
      "artifactUrl": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf",
      "externalForce": "voluntary-guidance",
      "artifact": {
        "sha256": "6e73620ab6b64e90ef2c04bf0e0d6246185a2f4b1b13cab0df494496cff89b6a",
        "bytes": 1174643,
        "mediaType": "application/pdf"
      },
      "note": "A voluntary cross-sectoral AI RMF profile. The publication page was updated 2026-04-08; the exact PDF bytes retrieved here remain pinned."
    },
    {
      "id": "nist-aml-100-2e2025",
      "title": "Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations",
      "publisher": "National Institute of Standards and Technology",
      "version": "NIST AI 100-2 E2025",
      "publishedAt": "2025-03-24",
      "canonicalUrl": "https://csrc.nist.gov/pubs/ai/100/2/e2025/final",
      "artifactUrl": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-2e2025.pdf",
      "externalForce": "taxonomy-and-guidance",
      "artifact": {
        "sha256": "4811fb6ad73f9c9121843ab77e029b5adc6f2c86d33c2fc5b2099ef133847646",
        "bytes": 1964469,
        "mediaType": "application/pdf"
      },
      "note": "Pins the corrected PDF uploaded 2025-04-01. NIST's 2025-06-03 planning note reports an error on page x and prospective future correction, so task 18.3 must recheck errata."
    },
    {
      "id": "owasp-agentic-top10-2026",
      "title": "OWASP Top 10 for Agentic Applications for 2026",
      "publisher": "OWASP GenAI Security Project",
      "version": "2026",
      "publishedAt": "2025-12-09",
      "canonicalUrl": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
      "artifactUrl": "https://genai.owasp.org/wp-content/uploads/dlm_uploads/2025/12/OWASP-Top-10-for-Agentic-Applications-2026-12.6-1.pdf",
      "externalForce": "community-risk-guidance",
      "artifact": {
        "sha256": "a2db94cd00b08e0b3a5e5b619afe024bdbcd74503111085705e4f3dd886fcb5c",
        "bytes": 1274186,
        "mediaType": "application/pdf"
      },
      "note": "Peer-reviewed risk framework and mitigation guidance, not a binding protocol or certification claim."
    },
    {
      "id": "mcp-2025-11-25",
      "title": "Model Context Protocol Specification",
      "publisher": "Model Context Protocol",
      "version": "2025-11-25",
      "publishedAt": "2025-11-25",
      "canonicalUrl": "https://modelcontextprotocol.io/specification/2025-11-25",
      "repository": "https://github.com/modelcontextprotocol/modelcontextprotocol",
      "tag": "2025-11-25",
      "commit": "38c84e9f93ad191d9eb26d92b945d17bd0efcaf3",
      "commitAt": "2025-11-25T21:14:08Z",
      "externalForce": "normative-if-implementation-claims-version-and-capability",
      "artifacts": [
        {
          "path": "docs/specification/2025-11-25/basic/authorization.mdx",
          "sha256": "8182f6a204013b497369c2ad690ff313f8bd1d2ce9ebb68e8f5d0392aa348cb9",
          "bytes": 41415
        },
        {
          "path": "docs/specification/2025-11-25/basic/utilities/cancellation.mdx",
          "sha256": "d438bcff38437259bf72e5b38fb3bb86925846fac58b9b166fea9edd7cb2c842",
          "bytes": 2770
        },
        {
          "path": "docs/specification/2025-11-25/basic/utilities/progress.mdx",
          "sha256": "8de8c02945544dde615be30156638c2357125795640d5aef3041898032a0e431",
          "bytes": 3136
        },
        {
          "path": "docs/specification/2025-11-25/basic/utilities/tasks.mdx",
          "sha256": "6afbdf560a2f0740f6f168b40b3f36a9bee522c4d3c6037373fc48b54aa8e462",
          "bytes": 35792
        },
        {
          "path": "docs/specification/2025-11-25/server/tools.mdx",
          "sha256": "d4b51b2ee107f4b6b28f14479defb7904f373fff7b122aec55f1ef71f4244b73",
          "bytes": 13097
        },
        {
          "path": "schema/2025-11-25/schema.json",
          "sha256": "1ffe4c5577974012f5fa02af14ea88df4b7146679df1abaaad497c8d9230ca8a",
          "bytes": 174246
        }
      ],
      "note": "RFC 2119 terms are conditional on claiming this version and the relevant capability. Tasks are experimental and do not become an Eve requirement unless admitted."
    },
    {
      "id": "a2a-v1.0.0",
      "title": "Agent2Agent Protocol Specification",
      "publisher": "A2A Project",
      "version": "v1.0.0",
      "publishedAt": "2026-03-12",
      "canonicalUrl": "https://a2a-protocol.org/v1.0.0/specification/",
      "repository": "https://github.com/a2aproject/A2A",
      "tag": "v1.0.0",
      "commit": "173695755607e884aa9acf8ce4feed90e32727a1",
      "commitAt": "2026-03-12T16:34:00Z",
      "externalForce": "normative-if-implementation-claims-version-and-capability",
      "artifacts": [
        {
          "path": "docs/specification.md",
          "sha256": "087c6f6272ec08a7fcd90eb16843bf97e25e0dcd155afa5779033d23d5ac377d",
          "bytes": 152715
        },
        {
          "path": "specification/a2a.proto",
          "sha256": "4b74c0baa923ae0acb55474e548f1d6e5d3f83b80d757b65f8bf3e99a3c2257f",
          "bytes": 34461
        }
      ],
      "note": "A2A is a conditional interoperability choice for Eve. Local classes named A2A do not establish v1.0.0 wire conformance."
    },
    {
      "id": "ag-ui-2026-07-28",
      "title": "Agent User Interaction Protocol",
      "publisher": "AG-UI Protocol",
      "version": "release/2026-07-28",
      "publishedAt": "2026-07-28",
      "canonicalUrl": "https://docs.ag-ui.com/",
      "repository": "https://github.com/ag-ui-protocol/ag-ui",
      "tag": "release/2026-07-28",
      "commit": "ea3db4630d1e56d289093cbda0fe66929a44b6ed",
      "commitAt": "2026-07-28T15:13:20Z",
      "externalForce": "optional-compatibility-pattern",
      "artifacts": [
        {
          "path": "docs/introduction.mdx",
          "sha256": "f5e8babd6b5184cba5b7f644279bce3ed0a431628ddf0134e2fb9e1a106c9740",
          "bytes": 25916
        },
        {
          "path": "docs/concepts/events.mdx",
          "sha256": "a67dc47fd3875aa8fa3c1d553c7e7b0d78eeecbfa1efb8751c9b21bcc0a44852",
          "bytes": 35864
        },
        {
          "path": "docs/concepts/state.mdx",
          "sha256": "40e81e96a57ecffb4ca6e185b66e703d3fdeab4c45ee133d0b45117959b96a7a",
          "bytes": 8230
        },
        {
          "path": "docs/concepts/interrupts.mdx",
          "sha256": "240fc3e310fb87367f1f6b7dc3558c2a09233ab34612123601ce8cfe9c4d6acc",
          "bytes": 13606
        }
      ],
      "note": "Pinned as a comparison candidate. Task 16.1 owns an adopt/adapter/bespoke ADR; this record does not silently admit it."
    },
    {
      "id": "wcag-2.2-rec-2024-12-12",
      "title": "Web Content Accessibility Guidelines (WCAG) 2.2",
      "publisher": "World Wide Web Consortium",
      "version": "W3C Recommendation 2024-12-12",
      "publishedAt": "2024-12-12",
      "canonicalUrl": "https://www.w3.org/TR/2024/REC-WCAG22-20241212/",
      "artifactUrl": "https://www.w3.org/TR/2024/REC-WCAG22-20241212/",
      "externalForce": "normative-recommendation-when-conformance-claimed",
      "artifact": {
        "sha256": "6e3c5fe397257cae509a2fb4752b73062cf8cbeb92c2cec618989b17e4cf7057",
        "bytes": 512457,
        "mediaType": "text/html"
      },
      "note": "Main content is normative; introductions, appendices, examples, and notes are informative. Eve internally requires Level AA, but this audit makes neither a current conformance claim nor a legal conclusion."
    },
    {
      "id": "otel-semconv-1.44.0",
      "title": "OpenTelemetry Semantic Conventions",
      "publisher": "OpenTelemetry",
      "version": "v1.44.0",
      "publishedAt": "2026-08-04",
      "canonicalUrl": "https://opentelemetry.io/docs/specs/semconv/",
      "repository": "https://github.com/open-telemetry/semantic-conventions",
      "tag": "v1.44.0",
      "commit": "e10a930844c6951757a43b849d364f7d056ac32b",
      "commitAt": "2026-08-04T19:36:15Z",
      "externalForce": "normative-if-semantic-conventions-adopted",
      "artifacts": [
        {
          "path": "README.md",
          "sha256": "b256742d8553beb3aa9c2264a6eebe219392dad26cc4319caeb708d23c38dc30",
          "bytes": 3348
        }
      ],
      "note": "Core semantic-convention release. GenAI conventions have moved to a separate repository and are pinned separately below."
    },
    {
      "id": "otel-genai-dev-2026-09-01",
      "title": "OpenTelemetry GenAI Semantic Conventions",
      "publisher": "OpenTelemetry",
      "version": "development snapshot 2026-09-01",
      "publishedAt": "2026-09-01",
      "canonicalUrl": "https://github.com/open-telemetry/semantic-conventions-genai",
      "repository": "https://github.com/open-telemetry/semantic-conventions-genai",
      "tag": null,
      "commit": "ac46a5d7bfe0b0f47e8ce393e2db3a2c3042f236",
      "commitAt": "2026-09-01T14:21:32Z",
      "externalForce": "unversioned-development-conventions",
      "artifacts": [
        {
          "path": "docs/gen-ai/gen-ai-agent-spans.md",
          "sha256": "b6298d75a7dca8dd18511fb206ce3447845537b15bc4d96d2ba35fb491e10a44",
          "bytes": 99474
        },
        {
          "path": "docs/gen-ai/gen-ai-spans.md",
          "sha256": "a5e437839341470fa0110574903ab1198b0240ea144ece045e3f28e57659a287",
          "bytes": 120676
        },
        {
          "path": "docs/gen-ai/gen-ai-metrics.md",
          "sha256": "afe9d852b4122d9300d999aec3979a318b840dbd6410ba63004aa320033cda77",
          "bytes": 98206
        },
        {
          "path": "docs/gen-ai/mcp.md",
          "sha256": "d5eb3b023f553c56052a07aecf3384ac5f64f894825c72eacf8c0eeda3c49a26",
          "bytes": 114878
        },
        {
          "path": "model/gen-ai/spans.yaml",
          "sha256": "7bc1a3025319821cf8fc3e730e827149a9640ef2e4227bdb5abb02eed7faef69",
          "bytes": 38428
        },
        {
          "path": "model/gen-ai/metrics.yaml",
          "sha256": "e490bcfc2d36696dc563fc642a609ead1bb603cc8a9285a34674f8b48c08395d",
          "bytes": 11160
        },
        {
          "path": "model/gen-ai/registry.yaml",
          "sha256": "8381a0cd47111869d2fbcf847da357504ba7a554ad2ed6c3d4b416d346f9f4fa",
          "bytes": 43067
        }
      ],
      "note": "No release tag was present at retrieval. This same-day commit is evidence of a moving development target, not a stable compatibility claim."
    }
  ],
  "controls": [
    {
      "id": "initiative-governance",
      "label": "Cross-phase admission gates and preregistered outcome owners",
      "status": "implemented-partial",
      "evidence": [
        {
          "path": "EVE_SOTA_GAP_CLOSURE_TODOS_2026-09-01.md",
          "proves": "Security, evaluation, reliability, privacy, and human-decision gates have named downstream task owners.",
          "doesNotProve": "The unchecked downstream controls or external-framework conformance are complete."
        },
        {
          "path": "docs/audits/eve-sota-outcome-scorecard/2026-09-01.json",
          "proves": "Targets, floors, samples, decision owners, and breach actions are preregistered.",
          "doesNotProve": "Those outcomes have yet met their floors."
        }
      ]
    },
    {
      "id": "bounded-mcp-tool-surface",
      "label": "Bounded stdio MCP workbench tool allowlist",
      "status": "implemented-partial",
      "evidence": [
        {
          "path": "tools/workbench-mcp/server.mjs",
          "proves": "The stdio server exposes six named workbench tools with bounded Zod inputs, a 120-second API timeout, and surfaced tool errors.",
          "doesNotProve": "MCP 2025-11-25 lifecycle, protected HTTP authorization, progress, cancellation, tasks, or independent conformance."
        },
        {
          "path": "tools/eve-codex-agent.mjs",
          "proves": "The live smoke initializes, lists six tools, checks two schema bounds, and calls the queue.",
          "doesNotProve": "Current-version conformance; the smoke requests protocol version 2024-11-05."
        }
      ]
    },
    {
      "id": "workbench-agent-auth",
      "label": "Fail-closed workbench authentication and attributable agent identity",
      "status": "implemented-partial",
      "evidence": [
        {
          "path": "apps/oshun/bff/src/workbench/agent-auth.ts",
          "proves": "Missing or malformed configuration fails closed; per-agent mode binds a timing-safe bearer token to a validated agent id.",
          "doesNotProve": "OAuth 2.1, resource/audience-bound MCP tokens, tenant authorization, or external-agent identity."
        },
        {
          "path": "apps/oshun/bff/src/workbench/agent-auth.spec.ts",
          "proves": "Wrong-token, impersonation, inherited-property, malformed-map, and shared-fallback attacks are negative-tested.",
          "doesNotProve": "Network protocol interoperability, token audience, tenant isolation, or delegated external identity."
        }
      ]
    },
    {
      "id": "governed-write-confirmation",
      "label": "One-shot, bound, fresh human confirmation for assistant writes",
      "status": "implemented-partial",
      "evidence": [
        {
          "path": "apps/oshun/bff/src/assistant/action-confirm.ts",
          "proves": "Confirmation is one-shot, TTL-bound, session/user-bound, and decline does not execute.",
          "doesNotProve": "Every high-impact tool across every plane is covered or undoable."
        },
        {
          "path": "apps/oshun/bff/src/assistant/workbench-kit-write.ts",
          "proves": "Prepared cards capture revision/preconditions and are consumed once before a freshness-checked write.",
          "doesNotProve": "External MCP/A2A callers follow the same path."
        },
        {
          "path": "apps/oshun/bff/src/workbench/workbench-agent-tools.integration.spec.ts",
          "proves": "Real-PostgreSQL tests cover parking, provenance, one-shot confirm, decline, missing capability, and failure surfacing.",
          "doesNotProve": "Universal coverage for destructive actions."
        }
      ]
    },
    {
      "id": "attributable-work-ledger",
      "label": "Append-only work lifecycle with leases and machine verification",
      "status": "implemented-partial",
      "evidence": [
        {
          "path": "apps/oshun/bff/src/workbench/intent-machines.ts",
          "proves": "The event-sourced lifecycle constrains transitions and reserves verified status for a machine verifier.",
          "doesNotProve": "MCP Tasks or A2A task-state conformance."
        },
        {
          "path": "apps/oshun/bff/src/workbench/intent-store.ts",
          "proves": "Row locking, lease CAS, attributable actors, bounded reports, expiry handling, and append-only events are implemented.",
          "doesNotProve": "Cross-agent tenant isolation or distributed cascade containment."
        },
        {
          "path": "apps/oshun/bff/src/workbench/work-queue.integration.spec.ts",
          "proves": "Real-PostgreSQL races, lease recovery, holder-only reporting, bounds, and verifier outcomes are tested.",
          "doesNotProve": "Protocol-level task interoperability, cross-tenant isolation, or distributed recovery."
        }
      ]
    },
    {
      "id": "untrusted-page-bounds",
      "label": "Size-bounded untrusted page context",
      "status": "implemented-partial",
      "evidence": [
        {
          "path": "apps/oshun/bff/src/assistant/page-context.ts",
          "proves": "Untrusted page fields are shape-checked, normalized, capped, and empty payloads are dropped.",
          "doesNotProve": "Instruction/data taint, provenance labels, or semantic prompt-injection resistance."
        }
      ]
    },
    {
      "id": "injection-regression-deck",
      "label": "Observable prompt-injection and trust-boundary regression cases",
      "status": "implemented-partial",
      "evidence": [
        {
          "path": "apps/oshun/bff/src/assistant/evals/deck-adversarial-cases.ts",
          "proves": "Eight injection cases cover page headings, selection, tool demand, work-item title, docs content, page title, role override, and forged tool output with observable canaries/tool expectations.",
          "doesNotProve": "A dedicated injection family, broad attack coverage, a production floor, or source taint propagation."
        }
      ]
    },
    {
      "id": "operator-memory-boundary",
      "label": "Subject-bound durable operator memory with refusal and deletion controls",
      "status": "implemented-partial",
      "evidence": [
        {
          "path": "apps/oshun/bff/src/assistant/operator-memory.ts",
          "proves": "Memory is database-bound by default, subject-scoped, capped, serially written, deletable, kill-switchable, and rejects member-id/email-shaped values.",
          "doesNotProve": "Source provenance, taint, supersession, expiry policy, semantic poisoning defense, or measured useful recall."
        }
      ]
    },
    {
      "id": "assistant-safety-and-checkers",
      "label": "Safety supersede and post-generation honesty checks",
      "status": "implemented-partial",
      "evidence": [
        {
          "path": "apps/oshun/bff/src/routes/assistant.ts",
          "proves": "Safety can supersede a turn; unsafe streaming is held; false lookup, audit, dispatch, and explicit-tool claims are held until evidence exists.",
          "doesNotProve": "Complete OWASP agentic mitigation coverage, independent policy authority, or an adversarial release floor."
        }
      ]
    },
    {
      "id": "turn-abort-and-sse",
      "label": "Client-disconnect abort and ordered bespoke assistant events",
      "status": "implemented-partial",
      "evidence": [
        {
          "path": "apps/oshun/bff/src/routes/assistant.ts",
          "proves": "The BFF emits named SSE frames and aborts before the next provider call when the client socket closes.",
          "doesNotProve": "Immediate in-flight cancellation, no post-cancel effects, resumability, MCP cancellation/progress, A2A streaming, or AG-UI compatibility."
        },
        {
          "path": "apps/oshun/web/src/lib/assistant/turn-stream.ts",
          "proves": "The web client parses the bespoke frames, validates UI intents, and returns client-tool results.",
          "doesNotProve": "Protocol negotiation or standard event/state semantics."
        }
      ]
    },
    {
      "id": "bespoke-ui-intents",
      "label": "Validated assistant UI intents and explicit confirmation interrupts",
      "status": "implemented-partial",
      "evidence": [
        {
          "path": "apps/oshun/web/src/lib/assistant/turn-stream.ts",
          "proves": "Highlight, tour, and client-tool frames are parsed through local validation and callbacks.",
          "doesNotProve": "AG-UI event, shared-state, lifecycle, or interrupt conformance."
        },
        {
          "path": "apps/oshun/web/src/components/assistant/AssistantPanel.tsx",
          "proves": "The shipped assistant panel renders the local streaming and action-confirm interaction model.",
          "doesNotProve": "Typed generative UI safety across arbitrary components or all accessibility journeys."
        }
      ]
    },
    {
      "id": "custom-a2a-precursors",
      "label": "In-house agent cards, task lifecycle, routing, streaming, and push primitives",
      "status": "unwired-precursor",
      "evidence": [
        {
          "path": "libs/oshun/ai-platform/src/agents.ts",
          "proves": "Custom AgentCard, task lifecycle, stream, authenticated gateway, discovery, routing, and rate-limit primitives exist.",
          "doesNotProve": "A2A v1.0.0 data model, transport binding, version negotiation, security, or tenant isolation."
        },
        {
          "path": "libs/oshun/ai-platform/src/integrations.ts",
          "proves": "The custom push notifier requires HTTPS, sends HMAC authentication, retries, and can format SSE.",
          "doesNotProve": "A2A push payloads, receiver validation, delivery semantics, or official conformance."
        }
      ]
    },
    {
      "id": "iris-signed-agent-precursor",
      "label": "Iris signed-card and agent-task prototype",
      "status": "unwired-precursor",
      "evidence": [
        {
          "path": "libs/iris/a2a/src/agent-card.ts",
          "proves": "Iris contains custom Ed25519 agent-card signing and verification logic.",
          "doesNotProve": "That the generated starting-point library is wired to Eve or conforms to A2A v1.0.0 JCS, trust, and wire requirements."
        },
        {
          "path": "libs/iris/a2a/src/task-negotiation.ts",
          "proves": "Iris contains custom task negotiation and cancellation logic.",
          "doesNotProve": "A2A v1.0.0 lifecycle, transport, authorization, isolation, or interoperability."
        },
        {
          "path": "libs/iris/a2a/README.md",
          "proves": "The library documents itself as a generated starting point awaiting owner-supplied usage and API notes.",
          "doesNotProve": "Production wiring, protocol admission, external interoperability, or runtime trust policy."
        }
      ]
    },
    {
      "id": "axe-accessibility-gates",
      "label": "Rendered-route axe scans for WCAG A/AA tags",
      "status": "implemented-with-carve-outs",
      "evidence": [
        {
          "path": "apps/oshun/admin/e2e/accessibility-key-workspaces.spec.ts",
          "proves": "Rendered admin workspaces receive serious/critical axe scans with WCAG 2.1/2.2 A/AA tags.",
          "doesNotProve": "Full WCAG conformance; color contrast and scrollable-region focusability are disabled, lesser impacts and manual criteria are not gated."
        },
        {
          "path": "apps/oshun/admin/e2e/wcag-aa-signoff-v1-p2-3512.spec.ts",
          "proves": "Seven named admin surfaces receive the same rendered-page automation.",
          "doesNotProve": "The Eve drawer, tours, selection, confirmation, generated UI, live announcements, focus journeys, mobile, or assistive-technology operation."
        },
        {
          "path": "apps/oshun/admin/e2e/support/accessibility.ts",
          "proves": "The helper selects WCAG 2.0/2.1/2.2 A/AA axe tags.",
          "doesNotProve": "Criteria that automated DOM analysis cannot determine."
        }
      ]
    },
    {
      "id": "wcag22-technique-inventory",
      "label": "Evidence-shape analysis for the six WCAG 2.2 A/AA additions",
      "status": "analysis-with-open-gaps",
      "evidence": [
        {
          "path": "libs/oshun/workbench-kit/src/wcag22-coverage.ts",
          "proves": "The six new A/AA criteria are mapped to automated, browser-journey, and manual evidence shapes and identifies missing product-layer inputs/instruments.",
          "doesNotProve": "That the missing product-layer journeys or reviews passed."
        },
        {
          "path": "libs/oshun/workbench-kit/src/primitive-accessibility.ts",
          "proves": "The repo maintains the complete WCAG 2.2 A/AA criterion inventory used by the coverage analysis.",
          "doesNotProve": "Conformance of any page or complete process."
        }
      ]
    },
    {
      "id": "structural-turn-traces",
      "label": "Opt-in content-minimized assistant turn traces",
      "status": "implemented-partial",
      "evidence": [
        {
          "path": "apps/oshun/bff/src/assistant/turn-trace.ts",
          "proves": "Opt-in JSONL traces record ids, sizes, shapes, tool names, outcomes, tokens, cost, and checker slugs without prompt or member text fields.",
          "doesNotProve": "W3C Trace Context propagation, span hierarchy across services, durable delivery, OpenTelemetry export, or semantic-convention alignment."
        }
      ]
    },
    {
      "id": "assistant-metrics",
      "label": "Durable aggregate assistant outcome, cost, token, latency, and refusal metrics",
      "status": "implemented-partial",
      "evidence": [
        {
          "path": "apps/oshun/bff/src/assistant/turn-metrics.ts",
          "proves": "The BFF aggregates provider/model outcomes, tokens, cost, latency, tool errors, routing, checker, and refusal data with durable snapshots.",
          "doesNotProve": "OpenTelemetry metric names/units, histogram boundaries, cross-service correlation, or SLO coverage."
        }
      ]
    },
    {
      "id": "in-memory-trace-model",
      "label": "In-house AI span and monitor model",
      "status": "unwired-or-partial",
      "evidence": [
        {
          "path": "libs/oshun/ai-platform/src/observability.ts",
          "proves": "An in-memory trace/span hierarchy and model/cost/guardrail monitor API exist.",
          "doesNotProve": "Production wiring, sensitive-payload defaults, W3C context, exporter durability, or OpenTelemetry semantic conformance."
        }
      ]
    },
    {
      "id": "trace-manifest",
      "label": "Declared trace/correlation field manifest",
      "status": "implemented-partial",
      "evidence": [
        {
          "path": "libs/oshun/analytics/src/tracing-manifest.ts",
          "proves": "A source-aware inventory declares correlation and trace field expectations for existing event families.",
          "doesNotProve": "One end-to-end runtime trace context across Eve, MCP, A2A, tools, models, and external runtimes."
        }
      ]
    }
  ],
  "crosswalk": [
    {
      "id": "nist-rmf-govern",
      "sourceId": "nist-ai-rmf-1.0",
      "requirementIds": ["GOVERN 1", "GOVERN 2", "GOVERN 3", "GOVERN 4", "GOVERN 5", "GOVERN 6"],
      "externalNormativity": "GUIDANCE",
      "initiativeDisposition": "adopted-risk-guidance",
      "requirementOrRisk": "Cultivate accountable AI risk governance across policies, roles, workforce, monitoring, engagement, and third-party risk.",
      "existingControlIds": ["initiative-governance", "attributable-work-ledger"],
      "gap": "The initiative has admission gates and owners but lacks the completed control/evidence manifest, full external registry, independent signoff chain, and recurring governance review.",
      "downstreamTasks": ["0.5", "0.6", "14.6", "16.5", "18.1", "18.3"],
      "decisionOwner": "Agentic AI PM"
    },
    {
      "id": "nist-rmf-map",
      "sourceId": "nist-ai-rmf-1.0",
      "requirementIds": ["MAP 1", "MAP 2", "MAP 3", "MAP 4", "MAP 5"],
      "externalNormativity": "GUIDANCE",
      "initiativeDisposition": "adopted-risk-guidance",
      "requirementOrRisk": "Establish context, categorize the AI system, map benefits/harms, and identify affected actors and lifecycle dependencies.",
      "existingControlIds": ["initiative-governance"],
      "gap": "The gap ledger is broad, but the end-to-end threat model, data-flow inventory, modality capability map, and external dependency registry remain unchecked.",
      "downstreamTasks": ["4.1", "14.1", "16.5", "17.1"],
      "decisionOwner": "Security Lead"
    },
    {
      "id": "nist-rmf-measure",
      "sourceId": "nist-ai-rmf-1.0",
      "requirementIds": ["MEASURE 1", "MEASURE 2", "MEASURE 3", "MEASURE 4"],
      "externalNormativity": "GUIDANCE",
      "initiativeDisposition": "adopted-risk-guidance",
      "requirementOrRisk": "Use appropriate methods, metrics, independent assessment, feedback, and documented uncertainty to analyze and track trustworthy-AI risks.",
      "existingControlIds": [
        "initiative-governance",
        "injection-regression-deck",
        "assistant-metrics"
      ],
      "gap": "The scorecard is preregistered but the complete family taxonomy, independent graders, long-horizon evaluation, online feedback, and release-gate floors remain incomplete.",
      "downstreamTasks": ["12.1", "12.2", "12.3", "12.4", "12.6", "12.7"],
      "decisionOwner": "Evaluation Lead"
    },
    {
      "id": "nist-rmf-manage",
      "sourceId": "nist-ai-rmf-1.0",
      "requirementIds": ["MANAGE 1", "MANAGE 2", "MANAGE 3", "MANAGE 4"],
      "externalNormativity": "GUIDANCE",
      "initiativeDisposition": "adopted-risk-guidance",
      "requirementOrRisk": "Prioritize, treat, monitor, communicate, and respond to mapped AI risks, including go/no-go and decommission decisions.",
      "existingControlIds": [
        "initiative-governance",
        "governed-write-confirmation",
        "attributable-work-ledger"
      ],
      "gap": "High-impact action policy, kill/undo coverage, SLO/error budgets, chaos and restore evidence, dashboards, game day, and final closure audit are still open.",
      "downstreamTasks": ["4.7", "13.1", "13.5", "13.6", "13.7", "18.5"],
      "decisionOwner": "Operations Lead"
    },
    {
      "id": "nist-genai-information-integrity",
      "sourceId": "nist-genai-profile-600-1",
      "requirementIds": ["Confabulation", "Information Integrity"],
      "externalNormativity": "GUIDANCE",
      "initiativeDisposition": "adopted-risk-guidance",
      "requirementOrRisk": "Generated content may be confidently false, lose provenance, or distort the information ecosystem.",
      "existingControlIds": ["assistant-safety-and-checkers", "initiative-governance"],
      "gap": "Grounded-answer families, claim/citation provenance, conflict handling, calibrated abstention, and long-context provenance-retention floors are incomplete.",
      "downstreamTasks": ["3.5", "12.1", "12.4", "15.3"],
      "decisionOwner": "Sophia PM"
    },
    {
      "id": "nist-genai-security-privacy",
      "sourceId": "nist-genai-profile-600-1",
      "requirementIds": ["Data Privacy", "Information Security"],
      "externalNormativity": "GUIDANCE",
      "initiativeDisposition": "adopted-risk-guidance",
      "requirementOrRisk": "GAI inputs, outputs, models, tools, and retained context may expose private data or enable security compromise.",
      "existingControlIds": [
        "workbench-agent-auth",
        "structural-turn-traces",
        "operator-memory-boundary"
      ],
      "gap": "The full data-flow map, provider review, multimodal secret/exfiltration tests, retention/access rules, and deletion propagation across every store remain open.",
      "downstreamTasks": ["4.1", "14.1", "14.2", "14.3", "14.4", "14.5"],
      "decisionOwner": "Privacy Lead"
    },
    {
      "id": "nist-genai-human-harm",
      "sourceId": "nist-genai-profile-600-1",
      "requirementIds": [
        "Dangerous, Violent, or Hateful Content",
        "Harmful Bias or Homogenization",
        "Human-AI Configuration",
        "Obscene, Degrading, and/or Abusive Content"
      ],
      "externalNormativity": "GUIDANCE",
      "initiativeDisposition": "adopted-risk-guidance",
      "requirementOrRisk": "Human-AI interaction can produce harmful content, over-reliance, anthropomorphic trust, bias, or unsafe configuration and escalation behavior.",
      "existingControlIds": [
        "assistant-safety-and-checkers",
        "governed-write-confirmation",
        "initiative-governance"
      ],
      "gap": "Human-trust exploitation, calibrated oversight, blinded human labels, affected-group evaluation, and operator acceptance evidence are not complete.",
      "downstreamTasks": ["4.1", "4.8", "12.3", "14.6"],
      "decisionOwner": "Trust & Safety Lead"
    },
    {
      "id": "nist-genai-value-chain",
      "sourceId": "nist-genai-profile-600-1",
      "requirementIds": ["Value Chain and Component Integration"],
      "externalNormativity": "GUIDANCE",
      "initiativeDisposition": "adopted-risk-guidance",
      "requirementOrRisk": "Opaque or changing upstream models, datasets, tools, components, and providers create systemic and supply-chain risk.",
      "existingControlIds": ["bounded-mcp-tool-surface", "initiative-governance"],
      "gap": "External integrations lack a single provenance/version/permission/health registry; every model leg still needs capability, data-posture, canary, drift, and rollback contracts.",
      "downstreamTasks": ["4.6", "15.1", "15.2", "15.5", "16.5"],
      "decisionOwner": "Platform Lead"
    },
    {
      "id": "nist-genai-ip-media",
      "sourceId": "nist-genai-profile-600-1",
      "requirementIds": ["Intellectual Property"],
      "externalNormativity": "GUIDANCE",
      "initiativeDisposition": "adopted-risk-guidance",
      "requirementOrRisk": "Training sources, prompts, retrieved content, and generated outputs may create intellectual-property and provenance risks.",
      "existingControlIds": ["initiative-governance"],
      "gap": "Eval-data licensing and creative/media source, attribution, consent, generated-media disclosure, redistribution, and training restrictions are not yet proven.",
      "downstreamTasks": ["12.5", "14.7", "17.4"],
      "decisionOwner": "Governance Lead"
    },
    {
      "id": "nist-genai-specialized-and-environmental",
      "sourceId": "nist-genai-profile-600-1",
      "requirementIds": ["CBRN Information or Capabilities", "Environmental Impacts"],
      "externalNormativity": "GUIDANCE",
      "initiativeDisposition": "adopted-risk-guidance",
      "requirementOrRisk": "Specialized dangerous capability and material resource/energy costs require context-specific admission, measurement, and refusal.",
      "existingControlIds": ["initiative-governance", "assistant-metrics"],
      "gap": "Capability-specific high-risk admission and verified-outcome resource/cost measurement across all model and media legs remain incomplete.",
      "downstreamTasks": ["12.1", "15.4", "17.1", "17.5"],
      "decisionOwner": "Agentic AI PM"
    },
    {
      "id": "nist-aml-evasion",
      "sourceId": "nist-aml-100-2e2025",
      "requirementIds": ["NISTAML.022", "NISTAML.025"],
      "externalNormativity": "GUIDANCE",
      "initiativeDisposition": "adopted-risk-guidance",
      "requirementOrRisk": "Evasion and black-box evasion manipulate inference-time inputs so the system makes an attacker-chosen error.",
      "existingControlIds": ["injection-regression-deck", "assistant-safety-and-checkers"],
      "gap": "The current eight injection cases are not a dedicated statistically gated family and do not cover encoded, multimodal, adaptive, long-horizon, or cross-tool evasion.",
      "downstreamTasks": ["4.3", "4.8", "12.1", "12.2"],
      "decisionOwner": "Security Lead"
    },
    {
      "id": "nist-aml-poisoning",
      "sourceId": "nist-aml-100-2e2025",
      "requirementIds": [
        "NISTAML.011",
        "NISTAML.012",
        "NISTAML.013",
        "NISTAML.023",
        "NISTAML.024",
        "NISTAML.026",
        "NISTAML.051"
      ],
      "externalNormativity": "GUIDANCE",
      "initiativeDisposition": "adopted-risk-guidance",
      "requirementOrRisk": "Data, model, targeted, backdoor, clean-label, and availability poisoning can corrupt learned or retrieved behavior.",
      "existingControlIds": ["operator-memory-boundary", "untrusted-page-bounds"],
      "gap": "Memory, retrieval corpora, embeddings, model supply, tool descriptions, external registries, and eval data lack one end-to-end taint/provenance and poisoning test regime.",
      "downstreamTasks": ["3.6", "4.2", "4.6", "9.5", "12.5", "15.5", "16.5"],
      "decisionOwner": "Security Lead"
    },
    {
      "id": "nist-aml-privacy",
      "sourceId": "nist-aml-100-2e2025",
      "requirementIds": ["NISTAML.03"],
      "externalNormativity": "GUIDANCE",
      "initiativeDisposition": "adopted-risk-guidance",
      "requirementOrRisk": "Privacy attacks can infer membership, reconstruct sensitive data, extract training information, or exploit model outputs.",
      "existingControlIds": ["structural-turn-traces", "operator-memory-boundary"],
      "gap": "Membership/reconstruction/extraction attacks and privacy-budget or provider-retention behavior are not covered by the current evaluation and data-rights suites.",
      "downstreamTasks": ["4.8", "12.1", "14.2", "14.3", "14.4"],
      "decisionOwner": "Privacy Lead"
    },
    {
      "id": "nist-aml-generative-prompt-attacks",
      "sourceId": "nist-aml-100-2e2025",
      "requirementIds": [
        "Generative AI Taxonomy §3.3 Direct Prompting",
        "Generative AI Taxonomy §3.3 Indirect Prompt Injection"
      ],
      "externalNormativity": "GUIDANCE",
      "initiativeDisposition": "adopted-risk-guidance",
      "requirementOrRisk": "Direct and indirect instructions can redirect a generative system through user, retrieved, tool, document, or environmental channels.",
      "existingControlIds": [
        "untrusted-page-bounds",
        "injection-regression-deck",
        "assistant-safety-and-checkers"
      ],
      "gap": "Content is bounded but not labeled as untrusted data; authority is not centrally enforced across all prompt/tool/memory/media channels, and broad red-team evidence is absent.",
      "downstreamTasks": ["4.2", "4.3", "4.4", "4.8", "17.2"],
      "decisionOwner": "Security Lead"
    },
    {
      "id": "owasp-asi01",
      "sourceId": "owasp-agentic-top10-2026",
      "requirementIds": ["ASI01 Agent Goal Hijack"],
      "externalNormativity": "GUIDANCE",
      "initiativeDisposition": "adopted-risk-guidance",
      "requirementOrRisk": "Manipulated inputs or context redirect an agent's goals and multi-step plan.",
      "existingControlIds": [
        "untrusted-page-bounds",
        "injection-regression-deck",
        "assistant-safety-and-checkers"
      ],
      "gap": "No end-to-end authority/taint system proves that hostile retrieved, memory, tool, media, and inter-agent content cannot become goals.",
      "downstreamTasks": ["4.1", "4.2", "4.3", "4.4", "4.8"],
      "decisionOwner": "Security Lead"
    },
    {
      "id": "owasp-asi02",
      "sourceId": "owasp-agentic-top10-2026",
      "requirementIds": ["ASI02 Tool Misuse and Exploitation"],
      "externalNormativity": "GUIDANCE",
      "initiativeDisposition": "adopted-risk-guidance",
      "requirementOrRisk": "Legitimate tools are invoked with unsafe intent, arguments, sequencing, authority, or side effects.",
      "existingControlIds": [
        "bounded-mcp-tool-surface",
        "governed-write-confirmation",
        "workbench-agent-auth"
      ],
      "gap": "A single central policy does not yet cover every tool plane, dry-run/undo/kill/idempotency is incomplete, and external tool descriptions are not continuously attested.",
      "downstreamTasks": ["4.4", "4.6", "4.7", "16.5", "16.6"],
      "decisionOwner": "Security Lead"
    },
    {
      "id": "owasp-asi03",
      "sourceId": "owasp-agentic-top10-2026",
      "requirementIds": ["ASI03 Identity and Privilege Abuse"],
      "externalNormativity": "GUIDANCE",
      "initiativeDisposition": "adopted-risk-guidance",
      "requirementOrRisk": "Agent credentials, delegated identity, scopes, or privilege transitions are stolen, confused, shared, or escalated.",
      "existingControlIds": ["workbench-agent-auth", "attributable-work-ledger"],
      "gap": "Shared-token mode remains self-attributed; caller/tenant/task binding, step-up, credential rotation/revocation, and confused-deputy negatives are incomplete across protocols.",
      "downstreamTasks": ["4.1", "4.4", "4.5", "16.3", "16.4", "16.6"],
      "decisionOwner": "Security Lead"
    },
    {
      "id": "owasp-asi04",
      "sourceId": "owasp-agentic-top10-2026",
      "requirementIds": ["ASI04 Agentic Supply Chain Vulnerabilities"],
      "externalNormativity": "GUIDANCE",
      "initiativeDisposition": "adopted-risk-guidance",
      "requirementOrRisk": "Models, tools, skills, registries, prompts, packages, agents, or their metadata can change or be compromised upstream.",
      "existingControlIds": ["bounded-mcp-tool-surface", "initiative-governance"],
      "gap": "There is no complete external component registry with source/version/hash/permissions/destinations, schema-description drift detection, quarantine, and re-evaluation.",
      "downstreamTasks": ["4.1", "4.6", "15.1", "15.5", "16.5"],
      "decisionOwner": "Platform Lead"
    },
    {
      "id": "owasp-asi05",
      "sourceId": "owasp-agentic-top10-2026",
      "requirementIds": ["ASI05 Unexpected Code Execution (RCE)"],
      "externalNormativity": "GUIDANCE",
      "initiativeDisposition": "adopted-risk-guidance",
      "requirementOrRisk": "Agent-controlled inputs reach interpreters, shells, code loaders, templates, plugins, or unsafe execution environments.",
      "existingControlIds": ["bounded-mcp-tool-surface", "governed-write-confirmation"],
      "gap": "The six-tool allowlist is narrow evidence only; subprocess, coding, browser, DCC, plugin, archive, and external-agent paths still need isolation and adversarial RCE proof.",
      "downstreamTasks": ["4.1", "4.5", "4.6", "4.8", "11.3"],
      "decisionOwner": "Security Lead"
    },
    {
      "id": "owasp-asi06",
      "sourceId": "owasp-agentic-top10-2026",
      "requirementIds": ["ASI06 Memory & Context Poisoning"],
      "externalNormativity": "GUIDANCE",
      "initiativeDisposition": "adopted-risk-guidance",
      "requirementOrRisk": "Persistent or transient context is corrupted so future agent decisions inherit malicious or stale state.",
      "existingControlIds": ["operator-memory-boundary", "untrusted-page-bounds"],
      "gap": "Memory lacks source confidence, taint, supersession, expiry, conflict semantics, quarantine, poisoning evaluation, and measured harmful-recall locks.",
      "downstreamTasks": ["4.2", "4.8", "9.2", "9.3", "9.4", "9.5", "9.6", "9.7"],
      "decisionOwner": "Iris PM"
    },
    {
      "id": "owasp-asi07",
      "sourceId": "owasp-agentic-top10-2026",
      "requirementIds": ["ASI07 Insecure Inter-Agent Communication"],
      "externalNormativity": "GUIDANCE",
      "initiativeDisposition": "adopted-risk-guidance",
      "requirementOrRisk": "Agents exchange unauthenticated, untrusted, replayed, over-privileged, or cross-tenant messages, tasks, artifacts, and credentials.",
      "existingControlIds": [
        "workbench-agent-auth",
        "custom-a2a-precursors",
        "iris-signed-agent-precursor"
      ],
      "gap": "Local precursor types are not admitted wire protocols; trusted cards, mutual identity, tenant/task isolation, replay/downgrade defenses, credential binding, and independent interoperability tests are missing.",
      "downstreamTasks": ["4.1", "4.4", "4.5", "16.4", "16.5", "16.6"],
      "decisionOwner": "Security Lead"
    },
    {
      "id": "owasp-asi08",
      "sourceId": "owasp-agentic-top10-2026",
      "requirementIds": ["ASI08 Cascading Failures"],
      "externalNormativity": "GUIDANCE",
      "initiativeDisposition": "adopted-risk-guidance",
      "requirementOrRisk": "One faulty model, tool, message, memory, or agent propagates and amplifies across multi-step or multi-agent workflows.",
      "existingControlIds": ["attributable-work-ledger", "turn-abort-and-sse", "assistant-metrics"],
      "gap": "Per-operation deadlines, backpressure, circuit breakers, bounded concurrency, fault containment, chaos/soak evidence, and multi-agent cascade tests remain incomplete.",
      "downstreamTasks": ["4.1", "4.5", "13.3", "13.4", "13.5", "15.6"],
      "decisionOwner": "SRE Lead"
    },
    {
      "id": "owasp-asi09",
      "sourceId": "owasp-agentic-top10-2026",
      "requirementIds": ["ASI09 Human-Agent Trust Exploitation"],
      "externalNormativity": "GUIDANCE",
      "initiativeDisposition": "adopted-risk-guidance",
      "requirementOrRisk": "People are manipulated into over-trust, unsafe confirmation, credential disclosure, or reliance on fabricated status and authority.",
      "existingControlIds": [
        "governed-write-confirmation",
        "assistant-safety-and-checkers",
        "initiative-governance"
      ],
      "gap": "Confirmation quality, trust calibration, social-engineering/credential prompts, deceptive status, fatigue, and human acceptance/correction are not yet a complete red-team family and measured gate.",
      "downstreamTasks": ["4.1", "4.7", "4.8", "12.2", "12.3"],
      "decisionOwner": "Trust & Safety Lead"
    },
    {
      "id": "owasp-asi10",
      "sourceId": "owasp-agentic-top10-2026",
      "requirementIds": ["ASI10 Rogue Agents"],
      "externalNormativity": "GUIDANCE",
      "initiativeDisposition": "adopted-risk-guidance",
      "requirementOrRisk": "An agent persistently deviates from intended behavior, acts outside authority, resists control, conceals activity, or continues after revocation.",
      "existingControlIds": [
        "workbench-agent-auth",
        "attributable-work-ledger",
        "turn-abort-and-sse"
      ],
      "gap": "Central authority, durable kill/revoke across all planes, behavioral drift detection, containment, no-post-cancel effects, and rogue/colluding-agent evaluations remain open.",
      "downstreamTasks": ["4.1", "4.4", "4.5", "4.7", "4.8", "13.3"],
      "decisionOwner": "Security Lead"
    },
    {
      "id": "mcp-version-capabilities",
      "sourceId": "mcp-2025-11-25",
      "requirementIds": [
        "Lifecycle initialize/version negotiation",
        "Capability negotiation",
        "Protocol-version mismatch"
      ],
      "externalNormativity": "MUST_IF_ADOPTED",
      "initiativeDisposition": "conditional-protocol-requirement",
      "requirementOrRisk": "A claimed MCP 2025-11-25 peer must negotiate the supported protocol version and applicable capabilities and reject or handle mismatches according to the specification.",
      "existingControlIds": ["bounded-mcp-tool-surface"],
      "gap": "The only live smoke requests 2024-11-05 and checks six tool names; there is no per-client/server 2025-11-25 conformance or downgrade matrix.",
      "downstreamTasks": ["16.2", "16.6"],
      "decisionOwner": "Protocol Lead"
    },
    {
      "id": "mcp-protected-http-auth",
      "sourceId": "mcp-2025-11-25",
      "requirementIds": [
        "Authorization §Protocol Requirements",
        "OAuth 2.0 Protected Resource Metadata",
        "RFC 8707 resource indicator",
        "Access token audience and no token passthrough"
      ],
      "externalNormativity": "MUST_IF_ADOPTED",
      "initiativeDisposition": "conditional-protocol-requirement",
      "requirementOrRisk": "Authorization is optional overall; when protected HTTP MCP authorization is implemented, applicable discovery, resource binding, token transport, validation, audience, and no-passthrough requirements become normative. Stdio should use its environment boundary instead.",
      "existingControlIds": ["workbench-agent-auth", "bounded-mcp-tool-surface"],
      "gap": "The current MCP server is stdio and forwards an environment bearer to the BFF; protected-resource discovery, OAuth, resource indicators, audience validation, rotation/revocation, tenant/task binding, and confused-deputy negatives do not exist for HTTP MCP.",
      "downstreamTasks": ["16.2", "16.3", "16.6"],
      "decisionOwner": "Security Lead"
    },
    {
      "id": "mcp-tool-contract-safety",
      "sourceId": "mcp-2025-11-25",
      "requirementIds": [
        "Tools capability declaration",
        "Input/output schema validity",
        "Tool result/error contract",
        "Human-in-the-loop safety guidance"
      ],
      "externalNormativity": "MUST_IF_ADOPTED",
      "initiativeDisposition": "conditional-protocol-requirement",
      "requirementOrRisk": "Tool-capable servers must declare the capability and honor schema/result requirements; clients should treat annotations as untrusted and support visible, confirmable tool operation.",
      "existingControlIds": ["bounded-mcp-tool-surface", "governed-write-confirmation"],
      "gap": "Only two input bounds and a live queue call are smoked; output-schema validation, annotations, list-change, malformed calls/results, logging policy, and independent client/server compatibility are not comprehensively tested.",
      "downstreamTasks": ["4.6", "4.7", "16.2", "16.5", "16.6"],
      "decisionOwner": "Protocol Lead"
    },
    {
      "id": "mcp-progress",
      "sourceId": "mcp-2025-11-25",
      "requirementIds": [
        "Progress token type and uniqueness",
        "Monotonic progress",
        "Task-lifetime progress token",
        "Stop after terminal status",
        "Rate-limit guidance"
      ],
      "externalNormativity": "MUST_IF_ADOPTED",
      "initiativeDisposition": "conditional-protocol-requirement",
      "requirementOrRisk": "When progress is used, tokens must be valid and unique, progress must increase, task progress must retain the original token, and notifications must stop at terminal completion.",
      "existingControlIds": ["turn-abort-and-sse", "attributable-work-ledger"],
      "gap": "Bespoke SSE and workbench state expose activity but do not implement MCP progress tokens, monotonicity, terminal suppression, flood limits, or progress conformance tests.",
      "downstreamTasks": ["13.1", "13.3", "16.2", "16.6"],
      "decisionOwner": "Protocol Lead"
    },
    {
      "id": "mcp-cancellation",
      "sourceId": "mcp-2025-11-25",
      "requirementIds": [
        "notifications/cancelled request restrictions",
        "Initialize must not be cancelled",
        "Task cancellation uses tasks/cancel",
        "Cancellation race handling"
      ],
      "externalNormativity": "MUST_IF_ADOPTED",
      "initiativeDisposition": "conditional-protocol-requirement",
      "requirementOrRisk": "Peers must apply the correct cancellation mechanism, handle races, and distinguish ordinary request cancellation from task cancellation.",
      "existingControlIds": ["turn-abort-and-sse"],
      "gap": "Socket close only prevents the next provider call and is not an MCP notification or task cancel; immediate quiescence, post-cancel side-effect locks, user-visible cancel/resume, and protocol negatives are unproved.",
      "downstreamTasks": ["8.5", "13.3", "16.2", "16.6"],
      "decisionOwner": "SRE Lead"
    },
    {
      "id": "mcp-experimental-tasks",
      "sourceId": "mcp-2025-11-25",
      "requirementIds": [
        "Experimental tasks capability",
        "Task lifecycle and terminality",
        "tasks/get/list/result/cancel",
        "Related-task metadata",
        "Authorization-context binding",
        "Enumeration and rate-limit security"
      ],
      "externalNormativity": "MUST_IF_ADOPTED",
      "initiativeDisposition": "conditional-protocol-requirement",
      "requirementOrRisk": "If experimental MCP Tasks are admitted, capability declaration, state transitions, results, cancellation, metadata, pagination, context isolation, and enumeration defenses are normative for that capability.",
      "existingControlIds": ["attributable-work-ledger", "workbench-agent-auth"],
      "gap": "The workbench has real domain tasks but exposes none of the MCP Tasks methods or metadata; task state similarity does not prove protocol semantics, authorization-context isolation, or interoperability.",
      "downstreamTasks": ["13.3", "16.2", "16.3", "16.6"],
      "decisionOwner": "Protocol Lead"
    },
    {
      "id": "a2a-version-binding-model",
      "sourceId": "a2a-v1.0.0",
      "requirementIds": [
        "§3.6 Versioning",
        "§4 Protocol Data Model",
        "§5 Protocol Binding Requirements and Interoperability"
      ],
      "externalNormativity": "MUST_IF_ADOPTED",
      "initiativeDisposition": "conditional-protocol-requirement",
      "requirementOrRisk": "A2A v1.0 clients and agents must negotiate Major.Minor, expose functionally equivalent canonical data structures, declare interfaces, and preserve errors and field semantics across bindings.",
      "existingControlIds": ["custom-a2a-precursors", "iris-signed-agent-precursor"],
      "gap": "The two local precursor models use custom fields/states and have no admitted HTTP/gRPC/JSON-RPC binding, A2A-Version negotiation, official ProtoJSON validation, or independent implementation test.",
      "downstreamTasks": ["16.4", "16.6"],
      "decisionOwner": "Protocol Lead"
    },
    {
      "id": "a2a-agent-card-trust",
      "sourceId": "a2a-v1.0.0",
      "requirementIds": [
        "§8 Agent Card availability",
        "§8.3 interface declarations",
        "§8.4 JCS canonicalization and signatures",
        "§8.4.3 signature verification"
      ],
      "externalNormativity": "MUST_IF_ADOPTED",
      "initiativeDisposition": "conditional-protocol-requirement",
      "requirementOrRisk": "Admitted A2A servers must publish accurate cards; signed-card verification must canonicalize correctly, validate protected headers/keys, and reject invalid or revoked trust material.",
      "existingControlIds": ["custom-a2a-precursors", "iris-signed-agent-precursor"],
      "gap": "Iris signing is an unwired custom prototype and the ai-platform card is unsigned; no trusted issuer policy, JCS proof, revocation, cache/change detection, or external card admission exists.",
      "downstreamTasks": ["16.4", "16.5", "16.6"],
      "decisionOwner": "Security Lead"
    },
    {
      "id": "a2a-auth-isolation",
      "sourceId": "a2a-v1.0.0",
      "requirementIds": [
        "§7 TLS",
        "§7.4 authenticate every request",
        "§7.5 authorization",
        "§7.6 auth-required task state",
        "Caller/tenant/task isolation profile"
      ],
      "externalNormativity": "MUST_IF_ADOPTED",
      "initiativeDisposition": "conditional-protocol-requirement",
      "requirementOrRisk": "Production A2A requires encrypted transport, declared authentication, per-request authentication/authorization, safe credential acquisition, and an explicit isolation profile.",
      "existingControlIds": ["workbench-agent-auth", "custom-a2a-precursors"],
      "gap": "A nonempty auth string and a local rate limit are not credential validation or tenant/task isolation; auth-required/HITL, delegated-credential binding, replay, and cross-tenant negatives are absent.",
      "downstreamTasks": ["4.4", "4.5", "16.4", "16.6"],
      "decisionOwner": "Security Lead"
    },
    {
      "id": "a2a-task-stream-artifact-cancel",
      "sourceId": "a2a-v1.0.0",
      "requirementIds": [
        "§3.4 Task and context semantics",
        "§3.5 ordered updates",
        "§3.7 Messages and Artifacts",
        "CancelTask",
        "SubscribeToTask"
      ],
      "externalNormativity": "MUST_IF_ADOPTED",
      "initiativeDisposition": "conditional-protocol-requirement",
      "requirementOrRisk": "Tasks require unique ids, context consistency, valid lifecycle, ordered multi-stream delivery, reliable artifact retrieval, cancellation, and reconnect behavior.",
      "existingControlIds": [
        "custom-a2a-precursors",
        "iris-signed-agent-precursor",
        "attributable-work-ledger"
      ],
      "gap": "Custom in-memory streams and workbench leases do not prove A2A ordering across streams, context mismatch rejection, artifact semantics, durable reconnect, cancellation quiescence, or official error mappings.",
      "downstreamTasks": ["13.3", "16.4", "16.6"],
      "decisionOwner": "Protocol Lead"
    },
    {
      "id": "a2a-push-security",
      "sourceId": "a2a-v1.0.0",
      "requirementIds": [
        "§4.3 Push Notification Objects",
        "Push receiver task-id validation",
        "Idempotent duplicate processing",
        "Authenticated delivery and source verification"
      ],
      "externalNormativity": "MUST_IF_ADOPTED",
      "initiativeDisposition": "conditional-protocol-requirement",
      "requirementOrRisk": "Push delivery must authenticate as configured, bind notifications to expected tasks, tolerate duplicates, use bounded delivery behavior, and let receivers verify sources.",
      "existingControlIds": ["custom-a2a-precursors"],
      "gap": "The HMAC/HTTPS notifier is a sender-only precursor; canonical payloads, receiver validation, replay/idempotency, task isolation, rotation, timeout policy, and delivery evidence are missing.",
      "downstreamTasks": ["13.3", "16.4", "16.6"],
      "decisionOwner": "Security Lead"
    },
    {
      "id": "agui-events",
      "sourceId": "ag-ui-2026-07-28",
      "requirementIds": [
        "Core event lifecycle",
        "Text message events",
        "Tool-call events",
        "Error and lifecycle events"
      ],
      "externalNormativity": "OPTIONAL_PATTERN",
      "initiativeDisposition": "optional-compatibility-decision",
      "requirementOrRisk": "A standard agent-to-UI event vocabulary can reduce adapter cost and make text, tools, lifecycle, and errors interoperable.",
      "existingControlIds": ["turn-abort-and-sse", "bespoke-ui-intents"],
      "gap": "Eve emits turn.meta/delta/tool_call/tool_result/ui/complete/error and client-tool frames with local shapes; no mapping proves AG-UI lifecycle, ordering, ids, versioning, or error compatibility.",
      "downstreamTasks": ["16.1"],
      "decisionOwner": "Frontend Platform Lead"
    },
    {
      "id": "agui-state",
      "sourceId": "ag-ui-2026-07-28",
      "requirementIds": [
        "State snapshots",
        "State deltas",
        "Predictive state",
        "Shared-state synchronization"
      ],
      "externalNormativity": "OPTIONAL_PATTERN",
      "initiativeDisposition": "optional-compatibility-decision",
      "requirementOrRisk": "Explicit snapshots and deltas can synchronize agent and UI state without inferring truth from text or bespoke side channels.",
      "existingControlIds": ["bespoke-ui-intents", "turn-abort-and-sse"],
      "gap": "The buffered mobile reply and local UI-intent callbacks do not implement a versioned shared-state snapshot/delta contract, conflict semantics, rollback, or resume.",
      "downstreamTasks": ["8.4", "8.6", "16.1"],
      "decisionOwner": "Frontend Platform Lead"
    },
    {
      "id": "agui-interrupts-control",
      "sourceId": "ag-ui-2026-07-28",
      "requirementIds": [
        "Interrupt patterns",
        "Human approval",
        "Tool-based interrupts",
        "Cancel and resume lifecycle comparison"
      ],
      "externalNormativity": "OPTIONAL_PATTERN",
      "initiativeDisposition": "optional-compatibility-decision",
      "requirementOrRisk": "Typed interrupts can pause execution for human input or approval and make stop/resume behavior visible to a user interface.",
      "existingControlIds": [
        "governed-write-confirmation",
        "bespoke-ui-intents",
        "turn-abort-and-sse"
      ],
      "gap": "One-shot confirmations are real but use a bespoke contract; generalized pause/input/resume/cancel state, crash recovery, mobile parity, and an adopt/adapter/bespoke ADR remain open.",
      "downstreamTasks": ["8.4", "8.5", "8.6", "16.1"],
      "decisionOwner": "Frontend Platform Lead"
    },
    {
      "id": "wcag-perceivable-aa",
      "sourceId": "wcag-2.2-rec-2024-12-12",
      "requirementIds": [
        "1.1.1",
        "1.2.1",
        "1.2.2",
        "1.2.3",
        "1.2.4",
        "1.2.5",
        "1.3.1",
        "1.3.2",
        "1.3.3",
        "1.3.4",
        "1.3.5",
        "1.4.1",
        "1.4.2",
        "1.4.3",
        "1.4.4",
        "1.4.5",
        "1.4.10",
        "1.4.11",
        "1.4.12",
        "1.4.13"
      ],
      "externalNormativity": "NORMATIVE_RECOMMENDATION",
      "initiativeDisposition": "required-wcag-aa",
      "requirementOrRisk": "Level A and AA perceivable content needs text alternatives, time-based-media alternatives, adaptable structure, and distinguishable visual/audio presentation.",
      "existingControlIds": ["axe-accessibility-gates", "wcag22-technique-inventory"],
      "gap": "Automated route scans exclude color contrast and cannot prove alt-text quality, media captions/descriptions, zoom/reflow across generated UI, or the affected assistant and mobile surfaces.",
      "downstreamTasks": ["8.7", "8.8", "8.9", "17.3"],
      "decisionOwner": "Accessibility Lead"
    },
    {
      "id": "wcag-operable-aa",
      "sourceId": "wcag-2.2-rec-2024-12-12",
      "requirementIds": [
        "2.1.1",
        "2.1.2",
        "2.1.4",
        "2.2.1",
        "2.2.2",
        "2.3.1",
        "2.4.1",
        "2.4.2",
        "2.4.3",
        "2.4.4",
        "2.4.5",
        "2.4.6",
        "2.4.7",
        "2.4.11",
        "2.5.1",
        "2.5.2",
        "2.5.3",
        "2.5.4",
        "2.5.7",
        "2.5.8"
      ],
      "externalNormativity": "NORMATIVE_RECOMMENDATION",
      "initiativeDisposition": "required-wcag-aa",
      "requirementOrRisk": "Level A and AA operation must work by keyboard and pointer alternatives, avoid traps and unsafe timing/motion, preserve navigation/focus, and meet focus-obscuring, dragging, and target-size rules.",
      "existingControlIds": [
        "axe-accessibility-gates",
        "wcag22-technique-inventory",
        "bespoke-ui-intents"
      ],
      "gap": "The repo analysis explicitly finds product-layer gaps for 2.4.11, 2.5.7, and 2.5.8; assistant drawer/tour/selection/confirmation/stop-resume focus and pointer journeys need deep Playwright and manual residue review.",
      "downstreamTasks": ["8.5", "8.8", "8.9"],
      "decisionOwner": "Accessibility Lead"
    },
    {
      "id": "wcag-understandable-aa",
      "sourceId": "wcag-2.2-rec-2024-12-12",
      "requirementIds": [
        "3.1.1",
        "3.1.2",
        "3.2.1",
        "3.2.2",
        "3.2.3",
        "3.2.4",
        "3.2.6",
        "3.3.1",
        "3.3.2",
        "3.3.3",
        "3.3.4",
        "3.3.7",
        "3.3.8"
      ],
      "externalNormativity": "NORMATIVE_RECOMMENDATION",
      "initiativeDisposition": "required-wcag-aa",
      "requirementOrRisk": "Level A and AA interfaces must be readable, predictable, consistently supported, and provide input assistance, error prevention, redundant-entry relief, and accessible authentication.",
      "existingControlIds": [
        "axe-accessibility-gates",
        "wcag22-technique-inventory",
        "governed-write-confirmation"
      ],
      "gap": "The coverage analysis finds no product register/instrument for consistent help, multi-step redundant entry, or authentication-process review; generated instructions, errors, confirmations, and mobile journeys remain unproved.",
      "downstreamTasks": ["8.6", "8.8", "8.9"],
      "decisionOwner": "Accessibility Lead"
    },
    {
      "id": "wcag-robust-aa",
      "sourceId": "wcag-2.2-rec-2024-12-12",
      "requirementIds": ["4.1.2", "4.1.3"],
      "externalNormativity": "NORMATIVE_RECOMMENDATION",
      "initiativeDisposition": "required-wcag-aa",
      "requirementOrRisk": "Controls need programmatically determinable name/role/value and status messages must be exposed without taking focus.",
      "existingControlIds": ["axe-accessibility-gates", "bespoke-ui-intents"],
      "gap": "Static automation does not prove live streaming deltas, tool status, confirmations, errors, tours, generated UI, and interruption announcements with supported screen readers across web and mobile.",
      "downstreamTasks": ["8.4", "8.6", "8.8", "8.9"],
      "decisionOwner": "Accessibility Lead"
    },
    {
      "id": "wcag-conformance-aa",
      "sourceId": "wcag-2.2-rec-2024-12-12",
      "requirementIds": [
        "5.2.1 Conformance Level",
        "5.2.2 Full pages",
        "5.2.3 Complete processes",
        "5.2.4 Accessibility-supported use",
        "5.2.5 Non-interference"
      ],
      "externalNormativity": "NORMATIVE_RECOMMENDATION",
      "initiativeDisposition": "required-wcag-aa",
      "requirementOrRisk": "A Level AA claim requires every A and AA criterion across full pages and complete processes using accessibility-supported techniques, while nonconforming alternatives do not interfere.",
      "existingControlIds": ["axe-accessibility-gates", "wcag22-technique-inventory"],
      "gap": "Current scans cover selected pages, suppress two known rules, gate only serious/critical findings, and lack the assistive-technology/manual/complete-process matrix; no WCAG 2.2 AA conformance claim is justified yet.",
      "downstreamTasks": ["8.8", "8.9", "18.6"],
      "decisionOwner": "Accessibility Lead"
    },
    {
      "id": "otel-trace-context",
      "sourceId": "otel-semconv-1.44.0",
      "requirementIds": [
        "Semantic Conventions v1.44.0 general trace/span model",
        "W3C trace-context-compatible propagation decision"
      ],
      "externalNormativity": "MUST_IF_ADOPTED",
      "initiativeDisposition": "optional-observability-alignment",
      "requirementOrRisk": "If OpenTelemetry conventions are adopted, common resource/span identity and context propagation should support interoperable end-to-end traces.",
      "existingControlIds": ["structural-turn-traces", "in-memory-trace-model", "trace-manifest"],
      "gap": "Existing trace ids are local and unwired; one context does not propagate across invocation, model, tools, MCP/A2A, confirmation, ledger, queue, agents, watchers, channels, and verification.",
      "downstreamTasks": ["13.2"],
      "decisionOwner": "SRE Lead"
    },
    {
      "id": "otel-genai-agent-spans",
      "sourceId": "otel-genai-dev-2026-09-01",
      "requirementIds": [
        "GenAI agent spans development conventions",
        "GenAI model/inference spans development conventions"
      ],
      "externalNormativity": "DEVELOPMENT_CONVENTION",
      "initiativeDisposition": "optional-observability-alignment",
      "requirementOrRisk": "Common GenAI operation, agent, model, token, response, error, and duration attributes can make traces comparable without bespoke interpretation.",
      "existingControlIds": [
        "structural-turn-traces",
        "assistant-metrics",
        "in-memory-trace-model"
      ],
      "gap": "The GenAI source has no stable release tag, current event names are bespoke, and task 13.2 must choose a commit/version and minimal safe attribute profile before any compatibility claim.",
      "downstreamTasks": ["13.1", "13.2", "15.4"],
      "decisionOwner": "SRE Lead"
    },
    {
      "id": "otel-genai-metrics",
      "sourceId": "otel-genai-dev-2026-09-01",
      "requirementIds": [
        "GenAI metrics development conventions",
        "Token usage",
        "Operation duration",
        "Time to first token"
      ],
      "externalNormativity": "DEVELOPMENT_CONVENTION",
      "initiativeDisposition": "optional-observability-alignment",
      "requirementOrRisk": "Stable names, units, attributes, and histogram boundaries can support comparable latency, token, cost, and error SLOs.",
      "existingControlIds": ["assistant-metrics", "initiative-governance"],
      "gap": "Current aggregates do not prove convention names/units, TTFT, consistent histograms, exemplars, fleet/tool/task coverage, or privacy-safe cardinality; the convention itself is still a development snapshot.",
      "downstreamTasks": ["13.1", "13.2", "13.4", "15.4"],
      "decisionOwner": "SRE Lead"
    },
    {
      "id": "otel-mcp-and-sensitive-data",
      "sourceId": "otel-genai-dev-2026-09-01",
      "requirementIds": [
        "MCP semantic conventions development snapshot",
        "Sensitive input/output opt-in guidance",
        "Tool and protocol correlation"
      ],
      "externalNormativity": "DEVELOPMENT_CONVENTION",
      "initiativeDisposition": "optional-observability-alignment",
      "requirementOrRisk": "MCP and GenAI telemetry should correlate operations while avoiding unsafe default capture of prompts, arguments, results, secrets, and user data.",
      "existingControlIds": [
        "structural-turn-traces",
        "bounded-mcp-tool-surface",
        "trace-manifest"
      ],
      "gap": "Structural assistant traces minimize content but do not cover MCP/A2A/external spans or durable export; explicit field-level classification, redaction tests, retention/deletion, and a pinned semantic profile remain open.",
      "downstreamTasks": ["13.2", "14.1", "14.3", "14.4"],
      "decisionOwner": "Privacy Lead"
    }
  ]
}
