Agent authority and evidence records.
Northgate Wealth Partners · Client onboarding
Executive decision
The estate meets nine of ten readiness criteria and still carries three critical findings. The score counts how much governance exists; the risk level answers what is wrong right now, so a single critical finding holds the level at high. Nothing here requires a model change — every open item is an owner, an approval control, or a mapping.
- Governance readiness
- 90
- Criteria met
- 9/10
- Critical findings
- 3
- Receipts verified
- 4/4
Fictional estate, generated by the assessment tooling rather than written by hand, and deliberately imperfect so the findings are visible. These are not measured ThePlus Tech customer outcomes.Pack hash 9ccf4d47d44f1e25d5b5c2b6a398cdd3dabf8f06135d91fba4105b72574b0ad6
Agent inventory
Authority map
Control gaps
At least one agent has no accountable human owner.
Assign a human owner to every agent.
Agent has no accountable owner (Suitability Drafting Agent).
Name the human accountable for this agent's behaviour.
High-risk tool requires approval control (Sanctions Screening Provider, confidential).
Require approval on this tool, or lower its data access level.
Authority boundary incomplete (Suitability Drafting Agent).
State what this agent may not do, not only what it may.
Governance rule lacks evidence mapping (Model version must be recorded).
Map this rule to a Control Plane pillar or a framework reference.
Evidence receipts
Every governed action leaves one, including the refused attempt. A record holding only successes cannot show a control working. The payloads never leave the tenant; only their digests appear here.
email.send · Denied
Adviser Notification Agent · approval not required43a77bd2fae0357bbafda86ff0a76435bc1cfe9012e9620ed699d7a79660eaf3
suitability.draft · Approval required
Suitability Drafting Agent · approval pending494e921da8f2b324aac24f560d7f8ef6da0cf80890d5307293872603bae21cc4
registry.lookup · Allowed
KYC Extraction Agent · approval not requiredb5b2be11789237900d2942e9e18876e1a93ab64230e89e71ef2f767c17c14381
kyc.extract · Approval required
KYC Extraction Agent · approval approved07026be614a5af463b7ee3591812a2181604ab6ff0c3c9e249ed9f6e63ca6b68
Framework mappings
Each control is bound to an external reference a reviewer can follow. These are pointers, not a compliance opinion, and nothing here certifies conformity. Unmapped pillar: revenue — an empty pillar is a finding, not a blank.
Named human owner per agent
Identity · ISO/IEC 42001 A.3
Each agent is owned by a named role accountable for its behaviour.
Authority boundaries per agent
Policy · OWASP LLM Top 10 LLM08
Excessive agency controlled by an explicit agent-to-tool authority map.
Human oversight of high-risk output
Policy · EU AI Act Art.14
Suitability summaries require adviser sign-off before filing.
Record-keeping of AI decisions
Audit · EU AI Act Art.12
Every governed action leaves a hashed evidence receipt.
Sensitive information disclosure
Evidence · OWASP LLM Top 10 LLM06
Receipts carry digests; client content never leaves the tenant boundary.
Risk measurement and tracking
Observability · NIST AI RMF MEASURE-2.5
Governance readiness scored and re-scored as the estate changes.