Framework Alignment
When agents touch a multi-party shared record, security and compliance will ask whether access is bounded, logged, and reviewable. This page is the forwardable answer.
It is evidence mapping for Legate as Stratum’s agent connection surface. It is not a certification, conformity assessment, or a claim that Legate alone is “SOC 2 certified,” “ISO certified,” or “EU AI Act compliant.”
Send with Access model and Disclosure Boundary. Deeper diligence packages are available through BlockSkunk on request.
Who this page is for
| You are… | Use this page to… |
|---|---|
| CISO / Head of Risk | Defend agent access posture to the board or an executive sponsor |
| GRC / Compliance Manager | Brief an assessor or vendor-risk reviewer without rebuilding the story |
| Internal Audit | Confirm what is in scope for Legate vs what stays with the deployer and the LLM host |
| Security / legal reviewer | Get a stable contract of what is published vs what stays private |
Technical connection steps stay in For integrators. This page stays in buyer and reviewer language.
What you can tell reviewers
| Question reviewers ask | What Legate on Stratum gives you |
|---|---|
| Who may act? | Operators entitle access. Agents hold short-lived credentials and capability packs, not long-lived write keys |
| Can an agent write freely? | No. Writes need an explicit consent claim. Final signature stays with a human or dedicated signer |
| Can we prove what was called? | Tool-call digests record actor, tool, argument digest, and status. Secrets stay out of logs |
| Is access least-privilege? | Packs bound read vs write. Calls outside the granted pack are denied |
| Where does AI judgment live? | In the client (the model host). Legate is the connection surface to the shared record, not the LLM |
Outcome for GRC: fewer screenshot packs for “who could the agent touch,” and a clearer boundary between agent tooling and human write finality. Pair with Arbiter when you need assessor-ready evidence packages on top of the shared record.
Frameworks in scope
Reviewers commonly map agent-access and information-security questions to these families. Legate’s published interface supports evidence conversations against them. It does not replace your organization’s control owners, AIMS, or audit opinions.
- Information security and trust services: NIST CSF, ISO/IEC 27001, SOC 2 (Security / Confidentiality themes)
- AI management and agent tooling: ISO/IEC 42001, MCP authorization guidance, OWASP MCP risk themes
- AI Act operational crosswalks (tooling component, not a full high-risk system package): AIUC-1 × EU AI Act
Ask for a diligence package when you need control-ID level mapping for a specific engagement. That detail is not dumped on this public page by design. See Disclosure Boundary.
Honest boundaries
What this page does not claim:
- FedRAMP, full NIST SP 800-53 SSP, or CE marking for Legate alone
- That Legate is your OAuth identity provider or your AI management system
- That deployer duties (impact assessments, “interacting with AI” notices, model training obligations) move into Legate
- Guard scoring, policy source files, or internal admission rules. Those stay private
What to do next:
- Confirm maturity on Integration Surfaces
- Forward Disclosure Boundary with this page
- Book an infrastructure review if agents will touch a multi-party shared record