{"generated_at":"2026-08-04T00:26:44.717Z","report":{"title":"OSuite Runtime Exposure Report","org_id":"","generated_at":"2026-08-04T00:26:44.717Z","product":"Runtime Exposure Management","exposure_score":0,"exposure_status":"not_started","executive_summary":"Connect an agent and run one governed action to build the first runtime exposure map.","inventory_metrics":[{"key":"agents","label":"Agents","value":"0"},{"key":"runtime_adapters","label":"Runtime adapters","value":"19"},{"key":"coverage_tier","label":"Coverage tier","value":"managed"},{"key":"active_sessions","label":"Active sessions","value":"4"},{"key":"systems_touched","label":"Systems touched","value":"0"},{"key":"governed_actions","label":"Governed actions","value":"0"},{"key":"high_impact_systems","label":"High-impact systems","value":"0"}],"top_exposures":[],"dependency_risk":{"status":"managed","score":15,"summary":"3 dependency lane(s) are visible across providers, runtimes, tools, systems, approvals, and evidence.","providers":["OpenAI / Codex","Anthropic / Claude","Microsoft / Azure","LangGraph","MCP tool servers"],"lanes":[{"id":"model_and_agent_providers","label":"Model and agent providers","count":5,"examples":["OpenAI / Codex","Anthropic / Claude","Microsoft / Azure","LangGraph","MCP tool servers"],"risk":"distributed","detail":"Provider and agent runtime dependencies inferred from agents and adapter lanes."},{"id":"runtime_adapters","label":"Runtime adapters","count":19,"examples":["Claude Connectors Directory","ChatGPT Apps Connector","Codex Remote Connector","Claude Desktop Extension","Claude Code Hooks","Codex Plugin"],"risk":"controlled","detail":"Execution lanes that can emit governed actions into OSuite."},{"id":"mcp_and_tool_servers","label":"MCP and tool servers","count":3,"examples":["Claude Connectors Directory","ChatGPT Apps Connector","Codex Remote Connector"],"risk":"review","detail":"Tool servers and MCP-style bridges that can expand agent reach."},{"id":"external_and_business_systems","label":"External and business systems","count":0,"examples":[],"risk":"not_started","detail":"Systems, SaaS surfaces, repositories, databases, and destinations touched by agent actions."},{"id":"approval_and_authority_lanes","label":"Approval and authority lanes","count":0,"examples":["PCAA","policy profile","Action Gate Lease"],"risk":"not_started","detail":"Human and policy routes that decide whether action execution may proceed."},{"id":"evidence_and_receipts","label":"Evidence and receipts","count":0,"examples":["CAVA receipt","PCAA proof bundle","decision record"],"risk":"not_started","detail":"Evidence stores used to reconstruct why actions were allowed, blocked, or escalated."}],"top_risks":[]},"approval_lease_posture":{"status":"not_started","summary":"No governed action has reached the runtime firewall yet.","lanes":[{"key":"allow","label":"Allow with proof","count":0,"tone":"success","detail":"Action may continue when CAVA meaning, policy profile, and proof closure agree."},{"key":"ask","label":"Ask for approval","count":0,"tone":"warning","detail":"Execution waits for a PCAA-recognized authority instead of trusting the agent runtime alone."},{"key":"block","label":"Block or fail closed","count":0,"tone":"danger","detail":"High-risk allow paths are treated as firewall defects until a bounded approval exists."},{"key":"observe","label":"Observe only","count":0,"tone":"neutral","detail":"OSuite can record evidence but cannot yet enforce before execution on this lane."},{"key":"expired","label":"Expired or unbound","count":0,"tone":"muted","detail":"Unsigned actions or proof gaps cannot be reused as durable approvals."}],"bounded_action_model":{"name":"Bounded Action Firewall / Action Gate Lease","binding_fields":["canonical_action_fingerprint","policy_version","approval_ttl","runtime_session_id","actor_identity","destination_scope","proof_receipt_digest"],"invariant":"A human approval is valid only for the canonical action, policy, session, actor, destination, and time window it was issued for."},"lease_verifier":{"evaluated_actions":0,"lease_ready_actions":0,"replay_checks":0,"rejected_replay_checks":0,"rejection_rate":0,"missing_binding_fields":[],"sample_results":[]}},"external_verifier_coverage":{"status":"not_started","summary":"No external verifier checkpoint has been attached to recent runtime actions yet.","coverage_pct":0,"covered_actions":0,"total_actions_window":0,"verified_refs":0,"independent_mediator_refs":0,"valid_but_unmapped_refs":0,"failed_refs":0,"diverged_execution_bindings":0,"expected_source_class":"independent_mediator","providers":[],"latest_refs":[]},"governance_capital":{"product_name":"AI Deployment Survival","category":"governance capital","score":16,"status":"exposed","headline":"Governance capital starts accumulating after the first connected runtime and governed action.","summary":"What survives if AI budgets, providers, or internal sponsors change: the controlled runtime inventory, action authority, approval leases, exposure history, and evidence record.","dimensions":[{"key":"runtime_control_assets","label":"Runtime control assets","score":21,"status":"exposed","value":"0 agent(s), 19 adapter lane(s), 4 recent session(s)","detail":"The governed runtime inventory that remains useful even if a specific model vendor or agent framework changes.","why_it_matters":"If the organization cannot see the runtime estate, AI budget cuts or provider swaps turn into another discovery project."},{"key":"bounded_authority","label":"Bounded authority","score":0,"status":"not_started","value":"0 approval-bound / 0 high-impact action(s)","detail":"PCAA and BAF keep authority tied to the exact governed action instead of a reusable human yes.","why_it_matters":"Trust is easier to preserve after an incident when approvals are scoped, time-bound, and replay-resistant."},{"key":"evidence_durability","label":"Evidence durability","score":0,"status":"not_started","value":"0/0 verification-ready action(s)","detail":"Proof bundles, receipts, and outcome closure that survive procurement review, incident response, and leadership turnover.","why_it_matters":"A pilot becomes defensible only when the team can prove what happened without reconstructing it manually."},{"key":"runtime_portability","label":"Runtime portability","score":92,"status":"strong","value":"1 bound adapter lane(s)","detail":"The control story can move across hooks, SDKs, MCP, managed agents, and workflow tools.","why_it_matters":"Portability keeps OSuite from depending on a single agent vendor cycle."},{"key":"exposure_resilience","label":"Exposure resilience","score":0,"status":"not_started","value":"0/100 current exposure","detail":"Lower runtime exposure creates room to keep useful automation alive when the market becomes more risk-averse.","why_it_matters":"When AI hype corrects, teams keep the systems that can show controlled blast radius and remediation progress."},{"key":"policy_to_runtime_binding","label":"Policy-to-runtime binding","score":0,"status":"not_started","value":"0/100 runtime security readiness","detail":"Policy profile, CAVA meaning, Decision Score, lease verification, and proof closure point to the same action object.","why_it_matters":"Policy language becomes capital only when it changes runtime behavior and leaves evidence."}],"survival_frontier":[{"label":"Budget correction","posture":"needs proof","explanation":"Reduce proof gaps and observe-only lanes before using OSuite as a budget-defense artifact."},{"label":"Provider churn","posture":"portable","explanation":"The governance object can survive a runtime or model-provider change."},{"label":"Incident review","posture":"fragile","explanation":"Close evidence durability and approval binding before relying on post-incident reconstruction."},{"label":"Procurement diligence","posture":"needs hardening","explanation":"Map policy profile, runtime decisions, and proof closure into one exportable packet."}],"recommended_actions":[{"dimension":"bounded_authority","label":"Bounded authority","score":0,"action":"Route high-impact actions through bounded approval and reject mutated replay variants."},{"dimension":"evidence_durability","label":"Evidence durability","score":0,"action":"Close proof bundles for governed actions before treating them as buyer-ready evidence."},{"dimension":"exposure_resilience","label":"Exposure resilience","score":0,"action":"Resolve the highest-priority exposure backlog item and save a new exposure snapshot."}]},"framework_mappings":[{"id":"ctem","label":"CTEM","fit":"scope, discover, prioritize, validate, and mobilize agent action exposures continuously."},{"id":"ai_spm","label":"AI-SPM","fit":"discover agents, runtime adapters, MCP/tool surfaces, reachable systems, and policy gaps."},{"id":"runtime_protection","label":"AI runtime protection","fit":"turn prompt/tool/runtime events into pre-execution allow, ask, block, or observe lanes."},{"id":"nist_ai_rmf","label":"NIST AI RMF","fit":"map runtime evidence into Govern, Map, Measure, and Manage outputs."},{"id":"owasp_agentic","label":"OWASP Agentic AI","fit":"surface tool, authorization, identity, data, and autonomy risks as action-level controls."},{"id":"mitre_atlas","label":"MITRE ATLAS","fit":"preserve incident evidence for AI-specific attack paths and control validation."}],"remediation":[],"sections":[{"id":"runtime_inventory","title":"AI Runtime Inventory","summary":"No AI runtime exposure surface has been discovered yet.","metrics":[{"key":"agents","label":"Agents","value":"0"},{"key":"runtime_adapters","label":"Runtime adapters","value":"19"},{"key":"coverage_tier","label":"Coverage tier","value":"managed"},{"key":"active_sessions","label":"Active sessions","value":"4"},{"key":"systems_touched","label":"Systems touched","value":"0"},{"key":"governed_actions","label":"Governed actions","value":"0"},{"key":"high_impact_systems","label":"High-impact systems","value":"0"}],"agents":[],"adapters":[{"id":"claude_remote_connector","label":"Claude Connectors Directory","family":"remote_mcp","status":"ready","active_sessions":0,"session_count":0,"href":"/runtimes/claude_remote_connector"},{"id":"chatgpt_apps_connector","label":"ChatGPT Apps Connector","family":"remote_mcp","status":"ready","active_sessions":0,"session_count":0,"href":"/runtimes/chatgpt_apps_connector"},{"id":"codex_remote_connector","label":"Codex Remote Connector","family":"remote_mcp","status":"ready","active_sessions":0,"session_count":0,"href":"/runtimes/codex_remote_connector"},{"id":"claude_desktop_extension","label":"Claude Desktop Extension","family":"framework_sdk","status":"ready","active_sessions":0,"session_count":0,"href":"/runtimes/claude_desktop_extension"},{"id":"claude_code_hooks","label":"Claude Code Hooks","family":"tool_hook_runtime","status":"ready","active_sessions":4,"session_count":4,"href":"/runtimes/claude_code_hooks"},{"id":"codex_plugin","label":"Codex Plugin","family":"tool_hook_runtime","status":"ready","active_sessions":0,"session_count":0,"href":"/runtimes/codex_plugin"},{"id":"codex_hooks","label":"Codex Hooks","family":"tool_hook_runtime","status":"ready","active_sessions":0,"session_count":0,"href":"/runtimes/codex_hooks"},{"id":"azure_foundry","label":"Azure Foundry","family":"managed_agent_platform","status":"ready","active_sessions":0,"session_count":0,"href":"/runtimes/azure_foundry"},{"id":"gemini_enterprise_agent_platform","label":"Gemini Enterprise Agent Platform","family":"managed_agent_platform","status":"planned","active_sessions":0,"session_count":0,"href":"/runtimes/gemini_enterprise_agent_platform"},{"id":"bedrock_agentcore","label":"Bedrock AgentCore","family":"managed_agent_platform","status":"planned","active_sessions":0,"session_count":0,"href":"/runtimes/bedrock_agentcore"},{"id":"openai_agents_sdk","label":"OpenAI Agents SDK","family":"framework_sdk","status":"planned","active_sessions":0,"session_count":0,"href":"/runtimes/openai_agents_sdk"},{"id":"openai_api","label":"OpenAI API","family":"framework_sdk","status":"planned","active_sessions":0,"session_count":0,"href":"/runtimes/openai_api"},{"id":"openai_frontier","label":"OpenAI Frontier","family":"managed_agent_platform","status":"planned","active_sessions":0,"session_count":0,"href":"/runtimes/openai_frontier"},{"id":"xai_api","label":"xAI API","family":"framework_sdk","status":"planned","active_sessions":0,"session_count":0,"href":"/runtimes/xai_api"},{"id":"grok_business","label":"Grok Business","family":"managed_agent_platform","status":"planned","active_sessions":0,"session_count":0,"href":"/runtimes/grok_business"},{"id":"grok_enterprise","label":"Grok Enterprise","family":"managed_agent_platform","status":"planned","active_sessions":0,"session_count":0,"href":"/runtimes/grok_enterprise"},{"id":"servicenow_ai_agent_fabric","label":"ServiceNow AI Agent Fabric","family":"managed_agent_platform","status":"planned","active_sessions":0,"session_count":0,"href":"/runtimes/servicenow_ai_agent_fabric"},{"id":"salesforce_agentforce","label":"Salesforce Agentforce","family":"managed_agent_platform","status":"planned","active_sessions":0,"session_count":0,"href":"/runtimes/salesforce_agentforce"},{"id":"langgraph_platform","label":"LangGraph Platform","family":"framework_sdk","status":"planned","active_sessions":0,"session_count":0,"href":"/runtimes/langgraph_platform"}],"sessions":[{"id":"00a631a5-ae38-47f0-8849-0b96f24ac8eb","label":"claude_code_hooks","status":"active","agent_id":"codex-cli-prod-smoke","agent_label":"codex-cli-prod-smoke","runtime_adapter_id":"claude_code_hooks","runtime_adapter_label":"Claude Code Hooks","runtime_family":"tool_hook_runtime","governance_posture":"enforce","signature_mode":"workspace_key_optional","client_version":null,"started_at":"2026-05-15T19:51:21.822Z","updated_at":"2026-05-15T19:51:21.822Z","href":"/api/runtime-sessions/00a631a5-ae38-47f0-8849-0b96f24ac8eb"},{"id":"d54e5524-7d98-4bf2-b483-7e01f020b629","label":"claude_code_hooks","status":"active","agent_id":"codex-cli-prod-smoke","agent_label":"codex-cli-prod-smoke","runtime_adapter_id":"claude_code_hooks","runtime_adapter_label":"Claude Code Hooks","runtime_family":"tool_hook_runtime","governance_posture":"enforce","signature_mode":"workspace_key_optional","client_version":null,"started_at":"2026-05-15T19:28:56.130Z","updated_at":"2026-05-15T19:28:56.130Z","href":"/api/runtime-sessions/d54e5524-7d98-4bf2-b483-7e01f020b629"},{"id":"671ab267-4845-47f9-b017-7d17e442c81a","label":"claude_code_hooks","status":"active","agent_id":"codex-cli-prod-smoke","agent_label":"codex-cli-prod-smoke","runtime_adapter_id":"claude_code_hooks","runtime_adapter_label":"Claude Code Hooks","runtime_family":"tool_hook_runtime","governance_posture":"enforce","signature_mode":"workspace_key_optional","client_version":null,"started_at":"2026-05-15T19:10:43.605Z","updated_at":"2026-05-15T19:10:43.605Z","href":"/api/runtime-sessions/671ab267-4845-47f9-b017-7d17e442c81a"},{"id":"f7a64600-7032-42ce-bcaa-c1e8a2978a4c","label":"claude_code_hooks","status":"active","agent_id":"claude-hooks-demo","agent_label":"claude-hooks-demo","runtime_adapter_id":"claude_code_hooks","runtime_adapter_label":"Claude Code Hooks","runtime_family":"tool_hook_runtime","governance_posture":"enforce","signature_mode":"workspace_key_optional","client_version":null,"started_at":"2026-05-15T19:08:33.097Z","updated_at":"2026-05-15T19:08:33.097Z","href":"/api/runtime-sessions/f7a64600-7032-42ce-bcaa-c1e8a2978a4c"}]},{"id":"runtime_coverage","title":"Runtime Coverage","summary":"Runtime Coverage separates Reference adapters, Managed OSuite adapters, and Enterprise custom adapters so customers can see which action lanes are understood, supported, and production-governed. Current top active tier: Managed OSuite adapters.","status":"active","selected_tier":"managed","tiers":[{"id":"reference","label":"Reference adapters","description":"Open CAVA schemas, parser-pack contracts, reference examples, and local experiments. This is where developers learn the action language.","user_path":"Install osuite-cava-core, define or reuse parser packs, run local canonicalization and receipt checks.","cli_example":"cava scan ./repo --adapter github-actions --adapter package-json","studio_behavior":"Shown as reference coverage only; high-impact production lanes should not be marked fully governed from this tier alone.","count":0},{"id":"managed","label":"Managed OSuite adapters","description":"OSuite-maintained adapters for Codex, Claude, ChatGPT Apps, MCP, SDK, hooks, and common workflow runtimes.","user_path":"Use the one-line installer or connector flow; OSuite maintains parser updates and evidence quality.","cli_example":"osuite adapters status && osuite adapters coverage","studio_behavior":"Appears as Runtime Coverage with parser posture, evidence gaps, unsupported actions, and remediation paths.","count":8},{"id":"enterprise_custom","label":"Enterprise custom adapters","description":"Customer-specific mapping for ERP, CRM, ticketing, payments, manufacturing, data warehouses, and private workflow systems.","user_path":"Map sample events into CAVA fields, validate coverage, version the adapter, and deploy through OSuite.","cli_example":"osuite adapter init acme-erp && osuite adapter test .osuite/adapters/acme-erp.json","studio_behavior":"Appears as customer runtime coverage with field mapping, versioning, approval routing, and proof export.","count":11}],"metrics":[{"key":"reference_lanes","label":"Reference lanes","value":"0"},{"key":"managed_lanes","label":"Managed lanes","value":"8"},{"key":"enterprise_custom_lanes","label":"Enterprise custom lanes","value":"11"},{"key":"connected_coverage","label":"Connected coverage","value":"1/19"},{"key":"runtime_sessions","label":"Runtime sessions","value":"4"},{"key":"covered_agents","label":"Covered agents","value":"0"}],"adapter_lanes":[{"id":"claude_remote_connector","label":"Claude Connectors Directory","family":"remote_mcp","adapter_mode":"remote","tier":"managed","tier_label":"Managed OSuite adapters","parser_posture":"managed","support_model":"osuite_managed","status":"ready","connected":false,"active_sessions":0,"session_count":0,"linked_agents":0,"next_action":"Keep the OSuite adapter current and watch incomplete-evidence or unsupported-action counts in Runtime Security.","disclosure":"Managed pack: OSuite maintains parser updates, coverage diagnostics, proof export, and policy routing."},{"id":"chatgpt_apps_connector","label":"ChatGPT Apps Connector","family":"remote_mcp","adapter_mode":"remote","tier":"managed","tier_label":"Managed OSuite adapters","parser_posture":"managed","support_model":"osuite_managed","status":"ready","connected":false,"active_sessions":0,"session_count":0,"linked_agents":0,"next_action":"Keep the OSuite adapter current and watch incomplete-evidence or unsupported-action counts in Runtime Security.","disclosure":"Managed pack: OSuite maintains parser updates, coverage diagnostics, proof export, and policy routing."},{"id":"codex_remote_connector","label":"Codex Remote Connector","family":"remote_mcp","adapter_mode":"remote","tier":"managed","tier_label":"Managed OSuite adapters","parser_posture":"managed","support_model":"osuite_managed","status":"ready","connected":false,"active_sessions":0,"session_count":0,"linked_agents":0,"next_action":"Keep the OSuite adapter current and watch incomplete-evidence or unsupported-action counts in Runtime Security.","disclosure":"Managed pack: OSuite maintains parser updates, coverage diagnostics, proof export, and policy routing."},{"id":"claude_desktop_extension","label":"Claude Desktop Extension","family":"framework_sdk","adapter_mode":"gateway","tier":"managed","tier_label":"Managed OSuite adapters","parser_posture":"managed","support_model":"osuite_managed","status":"ready","connected":false,"active_sessions":0,"session_count":0,"linked_agents":0,"next_action":"Keep the OSuite adapter current and watch incomplete-evidence or unsupported-action counts in Runtime Security.","disclosure":"Managed pack: OSuite maintains parser updates, coverage diagnostics, proof export, and policy routing."},{"id":"claude_code_hooks","label":"Claude Code Hooks","family":"tool_hook_runtime","adapter_mode":"hook","tier":"managed","tier_label":"Managed OSuite adapters","parser_posture":"managed","support_model":"osuite_managed","status":"connected","connected":true,"active_sessions":4,"session_count":4,"linked_agents":2,"next_action":"Keep the OSuite adapter current and watch incomplete-evidence or unsupported-action counts in Runtime Security.","disclosure":"Managed pack: OSuite maintains parser updates, coverage diagnostics, proof export, and policy routing."},{"id":"codex_plugin","label":"Codex Plugin","family":"tool_hook_runtime","adapter_mode":"hook","tier":"managed","tier_label":"Managed OSuite adapters","parser_posture":"managed","support_model":"osuite_managed","status":"ready","connected":false,"active_sessions":0,"session_count":0,"linked_agents":0,"next_action":"Keep the OSuite adapter current and watch incomplete-evidence or unsupported-action counts in Runtime Security.","disclosure":"Managed pack: OSuite maintains parser updates, coverage diagnostics, proof export, and policy routing."},{"id":"codex_hooks","label":"Codex Hooks","family":"tool_hook_runtime","adapter_mode":"hook","tier":"managed","tier_label":"Managed OSuite adapters","parser_posture":"managed","support_model":"osuite_managed","status":"ready","connected":false,"active_sessions":0,"session_count":0,"linked_agents":0,"next_action":"Keep the OSuite adapter current and watch incomplete-evidence or unsupported-action counts in Runtime Security.","disclosure":"Managed pack: OSuite maintains parser updates, coverage diagnostics, proof export, and policy routing."},{"id":"azure_foundry","label":"Azure Foundry","family":"managed_agent_platform","adapter_mode":"bridge","tier":"enterprise_custom","tier_label":"Enterprise custom adapters","parser_posture":"enterprise_custom","support_model":"customer_specific","status":"ready","connected":false,"active_sessions":0,"session_count":0,"linked_agents":0,"next_action":"Map customer-specific fields into CAVA through a managed adapter or enterprise schema workshop.","disclosure":"Enterprise custom pack: OSuite maps private runtime fields, customer schemas, and sensitive business systems."},{"id":"gemini_enterprise_agent_platform","label":"Gemini Enterprise Agent Platform","family":"managed_agent_platform","adapter_mode":"bridge","tier":"enterprise_custom","tier_label":"Enterprise custom adapters","parser_posture":"enterprise_custom","support_model":"customer_specific","status":"planned","connected":false,"active_sessions":0,"session_count":0,"linked_agents":0,"next_action":"Map customer-specific fields into CAVA through a managed adapter or enterprise schema workshop.","disclosure":"Enterprise custom pack: OSuite maps private runtime fields, customer schemas, and sensitive business systems."},{"id":"bedrock_agentcore","label":"Bedrock AgentCore","family":"managed_agent_platform","adapter_mode":"bridge","tier":"enterprise_custom","tier_label":"Enterprise custom adapters","parser_posture":"enterprise_custom","support_model":"customer_specific","status":"planned","connected":false,"active_sessions":0,"session_count":0,"linked_agents":0,"next_action":"Map customer-specific fields into CAVA through a managed adapter or enterprise schema workshop.","disclosure":"Enterprise custom pack: OSuite maps private runtime fields, customer schemas, and sensitive business systems."},{"id":"openai_agents_sdk","label":"OpenAI Agents SDK","family":"framework_sdk","adapter_mode":"inline_sdk","tier":"managed","tier_label":"Managed OSuite adapters","parser_posture":"managed","support_model":"osuite_managed","status":"planned","connected":false,"active_sessions":0,"session_count":0,"linked_agents":0,"next_action":"Keep the OSuite adapter current and watch incomplete-evidence or unsupported-action counts in Runtime Security.","disclosure":"Managed pack: OSuite maintains parser updates, coverage diagnostics, proof export, and policy routing."},{"id":"openai_api","label":"OpenAI API","family":"framework_sdk","adapter_mode":"inline_sdk","tier":"enterprise_custom","tier_label":"Enterprise custom adapters","parser_posture":"enterprise_custom","support_model":"customer_specific","status":"planned","connected":false,"active_sessions":0,"session_count":0,"linked_agents":0,"next_action":"Map customer-specific fields into CAVA through a managed adapter or enterprise schema workshop.","disclosure":"Enterprise custom pack: OSuite maps private runtime fields, customer schemas, and sensitive business systems."},{"id":"openai_frontier","label":"OpenAI Frontier","family":"managed_agent_platform","adapter_mode":"workspace","tier":"enterprise_custom","tier_label":"Enterprise custom adapters","parser_posture":"enterprise_custom","support_model":"customer_specific","status":"planned","connected":false,"active_sessions":0,"session_count":0,"linked_agents":0,"next_action":"Map customer-specific fields into CAVA through a managed adapter or enterprise schema workshop.","disclosure":"Enterprise custom pack: OSuite maps private runtime fields, customer schemas, and sensitive business systems."},{"id":"xai_api","label":"xAI API","family":"framework_sdk","adapter_mode":"inline_sdk","tier":"enterprise_custom","tier_label":"Enterprise custom adapters","parser_posture":"enterprise_custom","support_model":"customer_specific","status":"planned","connected":false,"active_sessions":0,"session_count":0,"linked_agents":0,"next_action":"Map customer-specific fields into CAVA through a managed adapter or enterprise schema workshop.","disclosure":"Enterprise custom pack: OSuite maps private runtime fields, customer schemas, and sensitive business systems."},{"id":"grok_business","label":"Grok Business","family":"managed_agent_platform","adapter_mode":"workspace","tier":"enterprise_custom","tier_label":"Enterprise custom adapters","parser_posture":"enterprise_custom","support_model":"customer_specific","status":"planned","connected":false,"active_sessions":0,"session_count":0,"linked_agents":0,"next_action":"Map customer-specific fields into CAVA through a managed adapter or enterprise schema workshop.","disclosure":"Enterprise custom pack: OSuite maps private runtime fields, customer schemas, and sensitive business systems."},{"id":"grok_enterprise","label":"Grok Enterprise","family":"managed_agent_platform","adapter_mode":"workspace","tier":"enterprise_custom","tier_label":"Enterprise custom adapters","parser_posture":"enterprise_custom","support_model":"customer_specific","status":"planned","connected":false,"active_sessions":0,"session_count":0,"linked_agents":0,"next_action":"Map customer-specific fields into CAVA through a managed adapter or enterprise schema workshop.","disclosure":"Enterprise custom pack: OSuite maps private runtime fields, customer schemas, and sensitive business systems."},{"id":"servicenow_ai_agent_fabric","label":"ServiceNow AI Agent Fabric","family":"managed_agent_platform","adapter_mode":"workspace","tier":"enterprise_custom","tier_label":"Enterprise custom adapters","parser_posture":"enterprise_custom","support_model":"customer_specific","status":"planned","connected":false,"active_sessions":0,"session_count":0,"linked_agents":0,"next_action":"Map customer-specific fields into CAVA through a managed adapter or enterprise schema workshop.","disclosure":"Enterprise custom pack: OSuite maps private runtime fields, customer schemas, and sensitive business systems."},{"id":"salesforce_agentforce","label":"Salesforce Agentforce","family":"managed_agent_platform","adapter_mode":"workspace","tier":"enterprise_custom","tier_label":"Enterprise custom adapters","parser_posture":"enterprise_custom","support_model":"customer_specific","status":"planned","connected":false,"active_sessions":0,"session_count":0,"linked_agents":0,"next_action":"Map customer-specific fields into CAVA through a managed adapter or enterprise schema workshop.","disclosure":"Enterprise custom pack: OSuite maps private runtime fields, customer schemas, and sensitive business systems."},{"id":"langgraph_platform","label":"LangGraph Platform","family":"framework_sdk","adapter_mode":"bridge","tier":"enterprise_custom","tier_label":"Enterprise custom adapters","parser_posture":"enterprise_custom","support_model":"customer_specific","status":"planned","connected":false,"active_sessions":0,"session_count":0,"linked_agents":0,"next_action":"Map customer-specific fields into CAVA through a managed adapter or enterprise schema workshop.","disclosure":"Enterprise custom pack: OSuite maps private runtime fields, customer schemas, and sensitive business systems."}],"operating_rule":"CAVA core remains stable; adapter coverage is versioned around the runtime so parser packs can evolve without changing the proof object."},{"id":"governance_capital","title":"Governance Capital","summary":"What survives if AI budgets, providers, or internal sponsors change: the controlled runtime inventory, action authority, approval leases, exposure history, and evidence record.","product_name":"AI Deployment Survival","score":16,"status":"exposed","dimensions":[{"key":"runtime_control_assets","label":"Runtime control assets","score":21,"status":"exposed","value":"0 agent(s), 19 adapter lane(s), 4 recent session(s)","detail":"The governed runtime inventory that remains useful even if a specific model vendor or agent framework changes.","why_it_matters":"If the organization cannot see the runtime estate, AI budget cuts or provider swaps turn into another discovery project."},{"key":"bounded_authority","label":"Bounded authority","score":0,"status":"not_started","value":"0 approval-bound / 0 high-impact action(s)","detail":"PCAA and BAF keep authority tied to the exact governed action instead of a reusable human yes.","why_it_matters":"Trust is easier to preserve after an incident when approvals are scoped, time-bound, and replay-resistant."},{"key":"evidence_durability","label":"Evidence durability","score":0,"status":"not_started","value":"0/0 verification-ready action(s)","detail":"Proof bundles, receipts, and outcome closure that survive procurement review, incident response, and leadership turnover.","why_it_matters":"A pilot becomes defensible only when the team can prove what happened without reconstructing it manually."},{"key":"runtime_portability","label":"Runtime portability","score":92,"status":"strong","value":"1 bound adapter lane(s)","detail":"The control story can move across hooks, SDKs, MCP, managed agents, and workflow tools.","why_it_matters":"Portability keeps OSuite from depending on a single agent vendor cycle."},{"key":"exposure_resilience","label":"Exposure resilience","score":0,"status":"not_started","value":"0/100 current exposure","detail":"Lower runtime exposure creates room to keep useful automation alive when the market becomes more risk-averse.","why_it_matters":"When AI hype corrects, teams keep the systems that can show controlled blast radius and remediation progress."},{"key":"policy_to_runtime_binding","label":"Policy-to-runtime binding","score":0,"status":"not_started","value":"0/100 runtime security readiness","detail":"Policy profile, CAVA meaning, Decision Score, lease verification, and proof closure point to the same action object.","why_it_matters":"Policy language becomes capital only when it changes runtime behavior and leaves evidence."}],"survival_frontier":[{"label":"Budget correction","posture":"needs proof","explanation":"Reduce proof gaps and observe-only lanes before using OSuite as a budget-defense artifact."},{"label":"Provider churn","posture":"portable","explanation":"The governance object can survive a runtime or model-provider change."},{"label":"Incident review","posture":"fragile","explanation":"Close evidence durability and approval binding before relying on post-incident reconstruction."},{"label":"Procurement diligence","posture":"needs hardening","explanation":"Map policy profile, runtime decisions, and proof closure into one exportable packet."}],"recommended_actions":[{"dimension":"bounded_authority","label":"Bounded authority","score":0,"action":"Route high-impact actions through bounded approval and reject mutated replay variants."},{"dimension":"evidence_durability","label":"Evidence durability","score":0,"action":"Close proof bundles for governed actions before treating them as buyer-ready evidence."},{"dimension":"exposure_resilience","label":"Exposure resilience","score":0,"action":"Resolve the highest-priority exposure backlog item and save a new exposure snapshot."}]},{"id":"top_exposures","title":"Top Runtime Exposures","summary":"No exposure backlog item is currently active.","items":[]},{"id":"dependency_risk","title":"Vendor and Runtime Dependency Risk","summary":"3 dependency lane(s) are visible across providers, runtimes, tools, systems, approvals, and evidence.","lanes":[{"id":"model_and_agent_providers","label":"Model and agent providers","count":5,"examples":["OpenAI / Codex","Anthropic / Claude","Microsoft / Azure","LangGraph","MCP tool servers"],"risk":"distributed","detail":"Provider and agent runtime dependencies inferred from agents and adapter lanes."},{"id":"runtime_adapters","label":"Runtime adapters","count":19,"examples":["Claude Connectors Directory","ChatGPT Apps Connector","Codex Remote Connector","Claude Desktop Extension","Claude Code Hooks","Codex Plugin"],"risk":"controlled","detail":"Execution lanes that can emit governed actions into OSuite."},{"id":"mcp_and_tool_servers","label":"MCP and tool servers","count":3,"examples":["Claude Connectors Directory","ChatGPT Apps Connector","Codex Remote Connector"],"risk":"review","detail":"Tool servers and MCP-style bridges that can expand agent reach."},{"id":"external_and_business_systems","label":"External and business systems","count":0,"examples":[],"risk":"not_started","detail":"Systems, SaaS surfaces, repositories, databases, and destinations touched by agent actions."},{"id":"approval_and_authority_lanes","label":"Approval and authority lanes","count":0,"examples":["PCAA","policy profile","Action Gate Lease"],"risk":"not_started","detail":"Human and policy routes that decide whether action execution may proceed."},{"id":"evidence_and_receipts","label":"Evidence and receipts","count":0,"examples":["CAVA receipt","PCAA proof bundle","decision record"],"risk":"not_started","detail":"Evidence stores used to reconstruct why actions were allowed, blocked, or escalated."}],"top_risks":[]},{"id":"approval_lease_posture","title":"Approval Lease Posture","summary":"No governed action has reached the runtime firewall yet.","lanes":[{"key":"allow","label":"Allow with proof","count":0,"tone":"success","detail":"Action may continue when CAVA meaning, policy profile, and proof closure agree."},{"key":"ask","label":"Ask for approval","count":0,"tone":"warning","detail":"Execution waits for a PCAA-recognized authority instead of trusting the agent runtime alone."},{"key":"block","label":"Block or fail closed","count":0,"tone":"danger","detail":"High-risk allow paths are treated as firewall defects until a bounded approval exists."},{"key":"observe","label":"Observe only","count":0,"tone":"neutral","detail":"OSuite can record evidence but cannot yet enforce before execution on this lane."},{"key":"expired","label":"Expired or unbound","count":0,"tone":"muted","detail":"Unsigned actions or proof gaps cannot be reused as durable approvals."}],"verifier":{"evaluated_actions":0,"lease_ready_actions":0,"replay_checks":0,"rejected_replay_checks":0,"rejection_rate":0,"missing_binding_fields":[],"sample_results":[]}},{"id":"external_verifier_coverage","title":"External Verifier Coverage","summary":"No external verifier checkpoint has been attached to recent runtime actions yet.","coverage":{"status":"not_started","summary":"No external verifier checkpoint has been attached to recent runtime actions yet.","coverage_pct":0,"covered_actions":0,"total_actions_window":0,"verified_refs":0,"independent_mediator_refs":0,"valid_but_unmapped_refs":0,"failed_refs":0,"diverged_execution_bindings":0,"expected_source_class":"independent_mediator","providers":[],"latest_refs":[]},"latest_refs":[]},{"id":"framework_mapping","title":"Framework Mapping","summary":"Runtime exposure evidence can be mapped into security and governance operating models.","frameworks":[{"id":"ctem","label":"CTEM","fit":"scope, discover, prioritize, validate, and mobilize agent action exposures continuously."},{"id":"ai_spm","label":"AI-SPM","fit":"discover agents, runtime adapters, MCP/tool surfaces, reachable systems, and policy gaps."},{"id":"runtime_protection","label":"AI runtime protection","fit":"turn prompt/tool/runtime events into pre-execution allow, ask, block, or observe lanes."},{"id":"nist_ai_rmf","label":"NIST AI RMF","fit":"map runtime evidence into Govern, Map, Measure, and Manage outputs."},{"id":"owasp_agentic","label":"OWASP Agentic AI","fit":"surface tool, authorization, identity, data, and autonomy risks as action-level controls."},{"id":"mitre_atlas","label":"MITRE ATLAS","fit":"preserve incident evidence for AI-specific attack paths and control validation."}]},{"id":"recommended_remediation","title":"Recommended Remediation","summary":"Run at least one governed action before remediation can be recommended.","items":[]}]}}