Use-Case Intake & Risk Tiering

Use-Case Intake & Risk Tiering A workflow diagram generated by Archify. 01 / Product team 02 / Layer 01 Govern-as-Code 03 / Layer 02 Inventory & Transparency EX / Blocked Request Record, screen, tier Gates + registry Use-case request · built or bought · Product team › Request Use-case request built or bought Use-case record · purpose, users, data · Layer 01 Govern-as-Code › Record, screen, tier Use-case record purpose, users, data Prohibited-use screen · then the AI Act ladder · Layer 01 Govern-as-Code › Record, screen, tier Prohibited-use screen then the AI Act ladder Tier rule · profile fields to tier · Layer 01 Govern-as-Code › Record, screen, tier · versioned Tier rule profile fields to tier versioned Gates switched on · evals, DPIA, FRIA · Layer 01 Govern-as-Code › Gates + registry Gates switched on evals, DPIA, FRIA Registry entry · no stub, no deploy · Layer 02 Inventory & Transparency › Gates + registry Registry entry no stub, no deploy Blocked at intake · prohibited practice · Blocked › Record, screen, tier Blocked at intake prohibited practice write entry screen submit prohibited classify tier Legend Agent logic Policy Context / trace External system

One path in

  • • Every use case, built or bought, enters through the same form-plus-code intake
  • • The use-case record states purpose, out-of-scope uses, affected persons and data
  • • Prohibited practices are screened first and never tiered

A tier computed, not negotiated

  • • A versioned rule reads autonomy, decision impact, exposure, reversibility and data class
  • • The tier selects assessments, eval categories, approvers and review cadence
  • • A disputed tier changes a factor, with evidence, in a reviewed change

The record is the entry

  • • No intake record, no deployment: the inventory is complete by construction
  • • A new purpose, population or data source reopens intake