| ARS-01 | at least one declared tool authenticates by api_key or service_account or delegated_user or workload_identity_federation or oauth_client_credentials or oauth_authorization_code or unspecified | automatically verified, manually verified attestation alone cannot settle it | R not read by the harness | 4 change categories 1 of them conditional on the change | 90 days runtime observation |
| ARS-02 | at least one declared tool authenticates by api_key or service_account or delegated_user or workload_identity_federation or oauth_client_credentials or oauth_authorization_code or unspecified | automatically verified, manually verified attestation alone cannot settle it | 1 of 2 — capped | 5 change categories 1 of them conditional on the change | 180 days static reading |
| ARS-03 | every agent in the envelope — this control has no condition | automatically verified, manually verified attestation alone cannot settle it | 2 of 2 | 2 change categories | 180 days static reading |
| ARS-04 | at least one declared tool authenticates by api_key or service_account or delegated_user or workload_identity_federation or oauth_client_credentials or oauth_authorization_code or unspecified, or the declared trigger modes include scheduled or event_driven or agent_initiated | automatically verified, manually verified attestation alone cannot settle it | 1 of 2 — capped | 4 change categories 1 of them conditional on the change | 180 days static reading |
| ARS-05 | every agent in the envelope — this control has no condition | automatically verified, manually verified attestation alone cannot settle it | R not read by the harness | 2 change categories | 90 days runtime observation |
| ARS-06 | the contract declares at least 1 tool(s) | automatically verified, manually verified attestation alone cannot settle it | 1 of 2 — capped | 2 change categories | 180 days static reading |
| ARS-07 | the contract declares at least 1 tool(s) | automatically verified, manually verified attestation alone cannot settle it | 2 of 2 | 3 change categories | 180 days static reading |
| ARS-08 | at least one declared tool creates, modifies, deletes, sends or spends, or at least one declared skill has side effect write or send or spend or delete | automatically verified, manually verified attestation alone cannot settle it | 2 of 2 | 5 change categories 1 of them conditional on the change | 180 days static reading |
| ARS-09 | at least one destructive-action inventory entry is classified irreversible or reversible_with_effort, or at least one declared tool has side effect send or spend or delete | automatically verified, manually verified attestation alone cannot settle it | 1 of 2 — capped | 6 change categories 1 of them conditional on the change | 180 days static reading |
| ARS-10 | the contract declares at least one approval class, or at least one declared tool is gated at human_approval or human_approval_conditional | manually verified, attested attestation alone cannot settle it | G not read by the harness | 6 change categories 1 of them conditional on the change | 365 days governance review |
| ARS-11 | the contract declares at least 1 tool(s) | automatically verified, manually verified attestation alone cannot settle it | R not read by the harness | 5 change categories | 90 days runtime observation |
| ARS-12 | the contract declares at least 2 tool(s), and at least one declared tool can carry content out of the trust boundary, or at least one declared data sink is outside the platform, or at least one declared tool has side effect write or send or spend or delete | manually verified, attested attestation alone cannot settle it | G not read by the harness | 6 change categories | 365 days governance review |
| ARS-13 | every agent in the envelope — this control has no condition | automatically verified, manually verified attestation alone cannot settle it | R not read by the harness | 2 change categories | 90 days runtime observation |
| ARS-14 | every agent in the envelope — this control has no condition | automatically verified, manually verified attestation alone cannot settle it | 1 of 2 — capped | 4 change categories | 180 days static reading |
| ARS-15 | a declared sink or skill carries data classified internal or confidential or personal_data or special_category or financial or credential, or at least one declared prompt interpolates user or external content | manually verified, attested attestation alone cannot settle it | G not read by the harness | 5 change categories | 365 days governance review |
| ARS-16 | the declared lifecycle state is pilot or production, or the declared criticality is moderate or higher | automatically verified, manually verified attestation alone cannot settle it | R not read by the harness | 6 change categories | 90 days runtime observation |
| ARS-17 | every agent in the envelope — this control has no condition | automatically verified, manually verified attestation alone cannot settle it | 2 of 2 | 2 change categories | 180 days static reading |
| ARS-18 | at least one declared tool creates, modifies, deletes, sends or spends, or the declared autonomy level is human_on_the_loop or higher, or the declared trigger modes include scheduled or event_driven or agent_initiated, or the declared maximum plausible blast radius reaches single_tenant or wider | automatically verified, manually verified attestation alone cannot settle it | R not read by the harness | 5 change categories 1 of them conditional on the change | 90 days runtime observation |
| ARS-19 | at least one declared tool creates, modifies, deletes, sends or spends, or at least one declared skill has side effect write or send or spend or delete | automatically verified, manually verified attestation alone cannot settle it | 1 of 2 — capped | 4 change categories 1 of them conditional on the change | 180 days static reading |
| ARS-20 | the contract declares at least 1 tool(s), or the declared autonomy level is human_on_the_loop or higher | automatically verified, manually verified attestation alone cannot settle it | 1 of 2 — capped | 5 change categories | 180 days static reading |
| ARS-21 | the declared lifecycle state is pilot or production, and the declared criticality is moderate or higher, or the declared maximum plausible blast radius reaches single_customer or wider, or at least one declared tool creates, modifies, deletes, sends or spends | manually verified, attested attestation alone cannot settle it | G not read by the harness | 6 change categories | 365 days governance review |
| ARS-22 | at least one declared tool creates, modifies, deletes, sends or spends, or at least one declared skill has side effect write or send or spend or delete, or at least one destructive-action inventory entry is classified reversible or reversible_with_effort or irreversible | automatically verified, manually verified, attested attestation alone cannot settle it | R not read by the harness | 7 change categories 1 of them conditional on the change | 90 days runtime observation |
| ARS-23 | every agent in the envelope — this control has no condition | automatically verified, manually verified, attested attestation alone cannot settle it | 1 of 2 — capped | 4 change categories | 180 days static reading |
| ARS-24 | at least one declared prompt is whose trust level is assembled_untrusted, or at least one declared prompt interpolates user or external content, or at least one declared data sink is outside the platform, whose direction is inbound or bidirectional | automatically verified, manually verified, attested attestation alone cannot settle it | 1 of 2 — capped | 5 change categories | 180 days static reading |
| ARS-25 | at least one declared prompt interpolates user or external content, or at least one declared data sink is outside the platform, and at least one declared tool creates, modifies, deletes, sends or spends, or at least one declared tool can carry content out of the trust boundary, or a required scope anywhere in the declaration is a wildcard or a breadth-named scope (*, admin, write_all and the like), or a declared sink or skill carries data classified confidential or personal_data or special_category or financial or credential | automatically verified, manually verified, attested attestation alone cannot settle it | R not read by the harness | 9 change categories | 90 days runtime observation |
| ARS-26 | at least one declared tool can carry content out of the trust boundary, or at least one declared data sink is outside the platform, or at least one declared skill has side effect send or write | automatically verified, manually verified, attested attestation alone cannot settle it | 1 of 2 — capped | 5 change categories 1 of them conditional on the change | 180 days static reading |
| ARS-27 | at least one declared data sink is outside the platform, or at least one declared tool can carry content out of the trust boundary, or a declared data sink permits * as a destination, or at least one declared skill has side effect send, and a declared sink or skill carries data classified internal or confidential or personal_data or special_category or financial or credential | manually verified, attested attestation alone cannot settle it | G not read by the harness | 7 change categories 1 of them conditional on the change | 365 days governance review |
| ARS-28 | every agent in the envelope — this control has no condition | automatically verified, manually verified attestation alone cannot settle it | 2 of 2 | 3 change categories | 180 days static reading |
| ARS-29 | the declared maximum plausible blast radius reaches single_tenant or wider, or at least one declared tool acts as shared_service_account or service_identity or unspecified, or a required scope anywhere in the declaration is a wildcard or a breadth-named scope (*, admin, write_all and the like) | automatically verified, manually verified, attested attestation alone cannot settle it | R not read by the harness | 5 change categories 1 of them conditional on the change | 90 days runtime observation |
| ARS-30 | the declared lifecycle state is pilot or production, or the declared autonomy level is human_on_the_loop or higher, or the declared trigger modes include scheduled or event_driven or agent_initiated | automatically verified, manually verified, attested attestation alone cannot settle it | 1 of 2 — capped | 5 change categories | 180 days static reading |
| ARS-31 | the declared lifecycle state is pilot or production, and the declared criticality is moderate or higher, or the declared trigger modes include scheduled or event_driven or agent_initiated, or the declared autonomy level is human_on_the_loop or higher | automatically verified, manually verified, attested attestation alone cannot settle it | G not read by the harness | 5 change categories | 365 days governance review |
| ARS-32 | the contract declares at least 1 tool(s), and the declared autonomy level is human_on_the_loop or higher, or the declared trigger modes include scheduled or event_driven or agent_initiated, or no value is declared for the containment field loop_ceiling, or no value is declared for the containment field retry_ceiling | automatically verified, manually verified, attested attestation alone cannot settle it | 1 of 2 — capped | 7 change categories | 180 days static reading |
| ARS-33 | the declared lifecycle state is pilot or production | automatically verified, manually verified attestation alone cannot settle it | 2 of 2 | 6 change categories | 180 days static reading |
| ARS-34 | at least one destructive-action inventory entry is classified reversible or reversible_with_effort or irreversible | automatically verified, manually verified attestation alone cannot settle it | 2 of 2 | 6 change categories 1 of them conditional on the change | 180 days static reading |
| ARS-35 | the declared lifecycle state is production | automatically verified, manually verified, attested attestation alone cannot settle it | R not read by the harness | 7 change categories | 90 days runtime observation |
| ARS-36 | the declared lifecycle state is pilot or production, and the declared trigger modes include human_initiated, or at least one declared data sink is outside the platform, or at least one declared tool can carry content out of the trust boundary, or at least one declared skill has side effect send | manually verified, attested attestation alone cannot settle it | G not read by the harness | 4 change categories | 365 days governance review |
| ARS-37 | the declared lifecycle state is pilot or production, and at least one declared tool creates, modifies, deletes, sends or spends, or at least one declared data sink is outside the platform, or the declared maximum plausible blast radius reaches single_customer or wider, or a declared sink or skill carries data classified confidential or personal_data or special_category or financial or credential | manually verified, attested | G not read by the harness | 7 change categories | 365 days attestable |
| ARS-38 | at least one declared tool has side effect read, or at least one declared skill has side effect read, and a declared sink or skill carries data classified internal or confidential or personal_data or special_category or financial or credential | automatically verified, manually verified, attested attestation alone cannot settle it | R not read by the harness | 5 change categories 1 of them conditional on the change | 90 days runtime observation |
| ARS-39 | the contract declares at least one prompt, and a declared sink or skill carries data classified confidential or personal_data or special_category or financial or credential | automatically verified, manually verified, attested attestation alone cannot settle it | 1 of 2 — capped | 6 change categories | 180 days static reading |
| ARS-40 | the declared lifecycle state is pilot or production, and a declared sink or skill carries data classified confidential or personal_data or special_category or financial or credential | automatically verified, manually verified, attested attestation alone cannot settle it | G not read by the harness | 4 change categories | 365 days governance review |
| ARS-41 | the declared lifecycle state is production, or the declared criticality is high or higher, or the declared maximum plausible blast radius reaches single_tenant or wider, or a declared sink or skill carries data classified personal_data or special_category or financial or credential | manually verified, attested attestation alone cannot settle it | G not read by the harness | 6 change categories | 365 days governance review |