01Secure + Agentic
Incident response
- Required result
- Investigate the event, identify the cause, take an approved recovery action, and prepare the incident record.
- Actors
- Approved responder or AI agent, incident lead, recovery approver, and protected-system owner.
- Selected capability
- Selected telemetry, evidence, diagnostic tools, models, compute, and approved protected-system actions.
- Authority to avoid
- Broad production reach, reusable credentials, copied evidence, unrestricted diagnostic endpoints, and open-ended recovery authority.
- Crossings
- Telemetry and artifact input, diagnostic execution, review, protected-system actions, publication, and recovery closeout.
- Evidence
- Request, selected resources, policy decision, analysis operations, protected-system actions, crossings, result, and closure.
02Agentic
Protected-data analysis
- Required result
- Answer a bounded financial, healthcare, scientific, legal, engineering, or business question and prepare a reviewable result.
- Actors
- Approved analyst or AI agent, data owner, reviewer, and output approver.
- Selected capability
- Defined data view, approved models and tools, bounded compute, private work state, and allowed result path.
- Authority to avoid
- Broad storage access, reusable credentials, uncontrolled copies, unrestricted tools or network reach, and automatic publication.
- Crossings
- Selected data input, model and tool operations, review, artifact publication, approved destination, and closure.
- Evidence
- Requester, data and execution selection, material operations, review, publication decision, artifact reference, and closure.
03Secure
Third-party maintenance
- Required result
- Complete approved maintenance during a defined window and return the named system to the required state.
- Actors
- Approved third-party technician, customer approver, and responsible protected-system owner.
- Selected capability
- Named service application and target, approved interaction controls, explicit transfer paths, and bounded duration.
- Authority to avoid
- Standing VPN access, reusable general-purpose accounts, broad network reach, and open-ended file movement.
- Crossings
- Identity route, clipboard, upload, download, credential use, target changes, and session closeout.
- Evidence
- Request, approver, route, target, granted capabilities, material actions, crossings, session bounds, and outcome.