Reference toolchain by stack layer

Reference toolchain by stack layer An architecture diagram generated by Archify. Evidence store · OSCAL evidence · 05 Assurance & Continuous Compliance Evidence store OSCAL evidence AI-governance suites · aggregate & present · 05 Assurance & Continuous Compliance AI-governance suites aggregate & present Guardrail frameworks · tool-call mediation · 04 Runtime Controls & Observability Guardrail frameworks tool-call mediation Agent workload identity · identity + kill switch · 04 Runtime Controls & Observability Agent workload identity identity + kill switch Observability · trace agent runs · 04 Runtime Controls & Observability Observability trace agent runs Evaluation frameworks · eval gate in CI · 03 Evals & Red Teaming as Evidence Evaluation frameworks eval gate in CI Adversarial probes · red-team & vuln probes · 03 Evals & Red Teaming as Evidence Adversarial probes red-team & vuln probes Agent registry · runtime-aware inventory · 02 Inventory & Transparency Agent registry runtime-aware inventory Agent-discovery tools · reconcile & flag drift · 02 Inventory & Transparency Agent-discovery tools reconcile & flag drift AIBOM formats · bill of materials · 02 Inventory & Transparency AIBOM formats bill of materials Policy engines · allow/deny logic · 01 Govern-as-Code Policy engines allow/deny logic Policy Cards · proposed policy artefact · 01 Govern-as-Code Policy Cards proposed policy artefact gate deploy on registration names object under test carries thresholds to runtime streams decisions & traces aggregated as OSCAL evidence rule as data reconciles, flags drift AIBOM per entry red-team evals identity & scope verdicts traced 05 Assurance & Continuous Compliance 04 Runtime Controls & Observability 03 Evals & Red Teaming as Evidence 02 Inventory & Transparency 01 Govern-as-Code Legend Backend Database Security External

Read it as one spine

  • • Policy → Inventory → Evals → Runtime → Assurance
  • • Each layer produces an artefact the next consumes
  • • Evidence is produced at the bottom and proven at the top

Minimum viable stack (team of one)

  • • Layer 02 first: a registry a deploy writes to
  • • One policy with teeth, one eval gate, identity + kill switch
  • • Evidence as a by-product, into one store

Categories, not brands

  • • Every tool is an example of a category, interchangeable
  • • The AIBOM tells the eval layer what to test
  • • Runtime signals compared against the eval baseline