Method draft 0.1
Control library
Browse the working control set in Method draft 0.1. Each control explains the risk, evidence and limits of the proposed review.
24 controls
Named accountability
No one can accept residual risk or keep the agent within its approved use.
Intended use and exclusions
Users rely on the agent for tasks or populations it was never evaluated to handle.
Versioned system inventory
A result is attributed to components, prompts or tools that have since changed.
Mapped and minimised data flows
The agent collects or sends personal, health or financial data without a defined need.
Access and retention controls
Data remains available too broadly or for longer than the declared purpose requires.
Disclosure resistance
Sensitive context is revealed through responses, retrieval, logs or indirect prompt manipulation.
Untrusted input handling
A document, webpage, caller or tool result changes instructions and bypasses policy.
Least-privilege tools
A compromised or mistaken agent can read, change or send more than the task requires.
Secrets, dependencies and execution boundaries
Leaked credentials or unsafe dependencies turn agent execution into a path to wider systems.
Representative performance cases
A polished demo hides failure on real languages, users or operating conditions.
Unsupported output handling
The agent presents invented or weakly supported statements as reliable facts.
Regression control
A model, prompt or connector update silently breaks a previously acceptable behaviour.
Approval of consequential actions
The agent books, sends, deletes or advances a clinical or financial case without valid human authority.
Escalation to a competent person
Ambiguous or high-risk cases remain with automation when human judgement is needed.
Stop and containment
Operators cannot halt harmful actions or contain a compromised agent quickly.
Disclosure of AI interaction
People mistake an automated interaction for a human or do not understand how their input is used.
Understandable outcomes
A person cannot challenge or safely act on an agent-supported outcome.
Impact assessment and affected groups
Benefits and harms are assessed from the deployer’s view while affected people are overlooked.
Tamper-evident event trails
After an incident, the organization cannot reconstruct what the agent saw, decided and did.
Incident response for agent failures
Teams treat harmful output, data exposure or unauthorized action as an ordinary support ticket.
Change and quarterly review
A valid assessment becomes stale as models, prompts, data and operating conditions evolve.
Evidence provenance and integrity
Screenshots or exports cannot be tied to the tested system, time or responsible collector.
Reproducible verification
A result depends on an undocumented setup or a reviewer’s intuition.
Scope and residual-risk statement
Readers interpret a narrow result as a guarantee for the entire organization or future versions.
No matching results.