Chapter 37. Glossary
Agent Card. Primary record holding an agent’s identity, authorized tools, action boundaries, escalation thresholds, and kill-switch conditions.
AI Architecture. The domain concerned with how AI capability is sourced, hosted, grounded, orchestrated, observed, and constrained. Governs existence, connection, and authority boundary; not internal construction.
AI Governance Body. Standing body authorizing deployment and material change for Tier 3–4 systems. Absorbs the independent-challenge function of a model risk committee.
AI System Card. Derived view compiling governance status from primary records. Never independently authored.
Approved state. The configuration recorded in a Decision or ADR, against which actual state is compared.
Architecture Input Package. The structured information architecture supplies to portfolio governance, which portfolio must consume but need not defer to.
Control Deficit. Axis of the tiering matrix; average of D2 and D3, rounded up.
Control Plane. The seven-function loop comparing deployed state against approved state: observe, compare, evaluate, alert, recommend, enforce, learn.
Core Model. The eight entities without which the framework’s traceability claims do not function: Intent, Capability, AI System, Decision, Risk, Control, Outcome, Assurance.
D1–D5. The five composite risk dimensions: Decision Consequence Severity, Autonomy, Reversibility Deficit, Exposure and Scale, Data Sensitivity and Model Uncertainty.
Derived view. A record compiled by reference from primary records, never independently maintained.
Drift. Divergence between deployed state and approved state, or between approved state and an external requirement that changed.
Effective autonomy. The autonomy a system carries in practice, which may exceed its recorded D2 score where human review is nominal.
Evidence-as-code. Automatic capture of gate evidence as a byproduct of normal operation.
G1–G5. The five governance gates: Qualification and Provisional Risk, Architecture and Data Readiness, Deployment Authorization, Material Change, Retirement.
Impact. Axis of the tiering matrix; average of D1, D4, and D5, rounded up.
Kill-switch condition. An objectively evaluable, pre-approved condition permitting automated shutdown. The sole exception to the prohibition on automated corrective action at Tier 3–4.
Machine-readable boundary. An agent’s authority expressed so that a policy engine can compare it against live permissions.
Minimum Viable Framework. The subset of IRGF judged to deliver most of its value, centered on independent risk-tier verification.
Policy-as-code. Machine-executable expression of a policy rule, enabling preventive control.
Primary record. An artifact with exactly one authoritative owner and one location.
Reference pattern. A pre-approved architecture that, used unmodified, enables the automated G2 path at Tier 1–2.
Regulatory Overlay Reference. Record mapping applicable regulatory regimes to affected systems.
S0–S10. The eleven AI build lifecycle stages, from Opportunity to Retirement.
Safety-override floor. Rule flooring a system at Tier 3 where D1 = 4, or where D2 = 4 and D3 = 4.
T0–T7. The eight transformation lifecycle stages, from Purpose to Capability Re-Baseline.
TG0. The initiative qualification checkpoint at T2, with a known enforcement gap addressed by retroactive detection.
Tier 1–4. Risk classification determining governance intensity, decision authority, evidence depth, and automation eligibility.