See how the AI system, its authority, and its dependencies connect.
Maps models, agents, tools, data, identities, applications, infrastructure, suppliers, and human controls across the agreed boundary without claiming complete inventory or attack coverage.
What it contains
Models, agents, prompts and instructions, tools, data stores, retrieval paths, identities, permissions, APIs, applications, cloud services, networks, suppliers, and human approval points.
Trust, privilege, data, administration, and recovery paths; owners; source evidence; material unknowns; and next actions.
What leadership can act on
Identify which AI and infrastructure dependencies require design change, mitigation, validation, monitoring, or explicit attention.
Turn a security decision into a target design the team can implement and verify.
Records current and target architecture, material tradeoffs, testable requirements, implementation conditions, sequencing, exceptions, and validation gates.
What it contains
Current and target architecture, trust boundaries, identity, authorization, data flow, dependencies, failure, recovery, and operating constraints.
Material tradeoffs, testable security requirements, implementation conditions, sequencing, owners, exceptions, acceptance criteria, and validation gates.
What leadership can act on
Approve the design, approve it with conditions, redesign material elements, or defer until the required evidence exists.
Prioritize the attack, misuse, and failure paths that could cause real harm.
Connects credible AI-specific and conventional system scenarios to the actual architecture, actor capability, evidence maturity, business impact, current controls, response options, and owners.
What it contains
Prompt injection, data poisoning, model and tool misuse, excessive agency, identity abuse, tenant crossing, sensitive-data exposure, supply-chain compromise, denial and cost attacks, unsafe automation, and recovery failure.
Threat actors, preconditions, affected assets, paths, feasibility or maturity, evidence, controls, consequence, detection and mitigation needs, owners, and residual risk.
What leadership can act on
Decide which paths are material, which are theoretical, what evidence is missing, and what must change.
Turn security uncertainty into a sequenced plan with clear owners.
Connects material risk and alternatives to immediate containment, near-term mitigation, longer-term architecture and investment, owners, dependencies, timing, acceptance evidence, validation gates, exceptions, and residual-risk decisions.
What it contains
The decision, alternatives, evidence, uncertainty, material risks, immediate containment, near-term mitigation, and longer-term architecture and investment.
Expose the infrastructure paths that can compromise or disable critical services.
Traces identity, cloud, network, administration, delivery, secrets, suppliers, observability, and recovery paths across the agreed estate, distinguishing observed conditions from inference and unknowns.
What it contains
Cloud accounts and tenancy, identities and privileges, networks and exposed services, secrets and keys, delivery pipelines, software supply chain, logging and detection, administrative paths, recovery, and critical suppliers.
Material attack and failure paths, evidence, assumptions, unknowns, hardening and resilience actions, owners, verification steps, dependencies, and remaining exposure.
What leadership can act on
Direct design, mitigation, recovery, supplier, and validation work toward the paths that matter.
Sequence cryptographic remediation and PQC migration before dependencies become blockers.
Inventories cryptographic dependencies and data lifetimes, separates current weakness from quantum exposure, and plans crypto agility, supplier action, pilots, migration waves, interoperability, validation, rollback, and governance.
What it contains
Protocols, algorithms, certificates, keys, signing, hashing, KMS and HSM use, secret storage, rotation, recovery, revocation, artifact integrity, secure update, crypto agility, suppliers, and long-lived data exposure.
Current weaknesses, quantum exposure, data lifetimes, migration dependencies, pilots, waves, interoperability, performance, validation, rollback, owners, exceptions, and review triggers.
What leadership can act on
Prioritize immediate remediation, long-lived-data protection, supplier decisions, and standards-based migration without treating every system or deadline as equivalent.