Standards Crosswalk

ACR Runtime Control Plane Standard v1.0.1

The normative specification defining required control outcomes, decision semantics, evidence properties, and conformance criteria. Implementation-independent, testable, and auditable.

Conformance Levels

Three cumulative conformance levels.

Level 1Observability
  • Action logging
  • Decision logging
  • Correlation identifiers
  • Agent identity and purpose records
  • Policy decision records
  • Audit export capability
  • Minimum retention enforcement

Does not require mandatory pre-execution blocking for all protected actions. The conformance claim must identify every execution path outside enforcement scope.

Level 2Enforcement
  • Mandatory pre-execution control
  • Deny-by-default behavior
  • Identity and purpose binding
  • Policy enforcement at Execution Boundary
  • Approval gating for escalated actions
  • Executor-side verification
  • Containment with kill path

A protected action without valid control-plane authorization must fail. The executor must reject replayed, tampered, and unauthorized execution requests.

Level 3Full Runtime Control Plane Compliance
  • All Level 2 capabilities
  • Enforcement at all three Boundaries
  • Full four-state decision model (ALLOW/DENY/MODIFY/ESCALATE)
  • Drift detection with thresholded response
  • Graduated containment
  • Quarterly containment testing
  • Tamper-evident high-risk logging
  • Full STRIKE mapping
  • Formal escalation authority matrix
  • Safe-state definitions
  • Audit-ready evidence bundles

Verification requires controlled tests demonstrating all four decision outcomes, reconstructable incident records, drift conditions triggering documented response tiers, and on-schedule kill-switch test records.

Control Crosswalk

ACR controls mapped to five governance frameworks.

ACR IDControlPillarISO 42001NIST AI RMFNIST CSF 2.0ISO 27001NIST ZT
ACR-1-01Agent IdentityP1A.6.2.2MAP 1.1ID.AM-01A.5.163.1, 3.2
ACR-1-02Purpose BindingP1A.6.2.3MAP 1.5ID.AM-02A.5.183.3
ACR-1-03Agent ManifestP1A.6.2.4GOV 1.3ID.AM-03A.5.93.1
ACR-2-01Input BoundaryP2A.8.2MAN 2.1PR.DS-01A.8.34.1
ACR-2-02Execution BoundaryP2A.8.4MAN 2.2PR.DS-02A.8.54.2
ACR-2-03Output BoundaryP2A.8.5MAN 2.4PR.DS-10A.8.104.3
ACR-2-04Deny-by-DefaultP2A.6.1.2MAN 3.1PR.AA-01A.5.153.4
ACR-2-05Policy VersioningP2A.6.1.4GOV 1.4GV.PO-01A.5.1---
ACR-3-01Behavioral BaselineP3A.9.3MEA 2.1DE.AE-02A.8.165.1
ACR-3-02Drift ScoringP3A.9.4MEA 2.3DE.AE-03A.8.165.2
ACR-3-03Response TiersP3A.9.5MEA 2.6RS.MI-01A.5.265.3
ACR-4-01Decision LoggingP4A.9.2MEA 1.1DE.CM-01A.8.156.1
ACR-4-02Correlation IdentifiersP4A.9.2MEA 1.2DE.CM-06A.8.156.2
ACR-4-03Tamper-Evident LoggingP4A.9.8MEA 1.3PR.DS-06A.8.156.3
ACR-4-04Retention EnforcementP4A.9.9MEA 1.4PR.DS-11A.5.33---
ACR-4-05Audit ExportP4A.9.10MEA 1.5ID.IM-04A.5.35---
ACR-5-01Kill CapabilityP5A.10.1MAN 4.1RS.MI-02A.5.267.1
ACR-5-02Graduated ContainmentP5A.10.2MAN 4.2RS.MI-01A.5.267.2
ACR-5-03Safe-State DefinitionsP5A.10.3MAN 4.3RC.RP-01A.5.297.3
ACR-5-04Quarterly TestingP5A.10.4MAN 4.4RS.AN-07A.5.30---
ACR-6-01Action TieringP6A.7.3GOV 2.1GV.RM-01A.5.128.1
ACR-6-02Escalation MatrixP6A.7.4GOV 2.2GV.RR-01A.5.258.2
ACR-6-03Approval RecordsP6A.7.5GOV 2.3GV.SC-01A.5.258.3

Informative crosswalk mappings are provided for orientation. Conformance to the ACR Standard is evaluated solely against the requirements defined therein.