The stack, layer by layer

The stack, layer by layer An architecture diagram generated by Archify. Evidence store · OSCAL, queryable · Layer 05 Assurance & Continuous Compliance Evidence store OSCAL, queryable Framework mappings · generated from evidence · Layer 05 Assurance & Continuous Compliance Framework mappings generated from evidence Runtime guardrails · mediate tool calls · Layer 04 Runtime Controls & Observability Runtime guardrails mediate tool calls Agent identity · scope + kill switch · Layer 04 Runtime Controls & Observability Agent identity scope + kill switch Eval gate · fails the build · Layer 03 Evals & Red Teaming as Evidence Eval gate fails the build Eval suites · capability, adversarial · Layer 03 Evals & Red Teaming as Evidence Eval suites capability, adversarial Agent registry · owner, scope, status · Layer 02 Inventory & Transparency Agent registry owner, scope, status AIBOM · bill of materials · Layer 02 Inventory & Transparency AIBOM bill of materials Policy library · versioned rules · Layer 01 Govern-as-Code Policy library versioned rules Crosswalks · policy to framework · Layer 01 Govern-as-Code Crosswalks policy to framework evidence map policies per entry run in CI scope generated from Layer 05 Assurance & Continuous Compliance Layer 04 Runtime Controls & Observability Layer 03 Evals & Red Teaming as Evidence Layer 02 Inventory & Transparency Layer 01 Govern-as-Code Legend Database Security

A build order, not a chart

  • • Read it bottom to top: Policy, Inventory, Evals, Runtime, Assurance
  • • Each layer produces an artefact the layer above consumes
  • • This map is the artefacts, not the tools that make them

Evidence flows up

  • • A policy verdict, a registry entry, an eval result and a guardrail decision are structured records
  • • Layer 05 aggregates them into audit-ready evidence
  • • Every green cell traces to a running control and the evidence it emitted

How to read it

  • • Build in the order chapter 04 gives for a team of one
  • • Start at Layer 02: a registry a deploy writes to