Universal Entity Lifecycle Governance Framework (UELGF)

Universal Entity Lifecycle Governance Framework (UELGF): canonical entity taxonomy and Confidentiality, Integrity, and Availability (CIA) classification system for determining governance intensity

2026-04-27 · agentic-ai governance-policy security-risk tools-infrastructure · medium · source → · wiki →
key claims
  1. A stable UELGF taxonomy should classify entities by dominant executed function rather than by owning team or implementation medium, because operational taxonomies remain durable only when runtime consequence, service role, and domain boundary are separated explicitlyAmazon (n.d.)Opengroup (n.d.)CSDM (n.d.)
  2. AI agents need four mutually exclusive autonomy classes with observable falsifiers, because human oversight, trigger mode, and task persistence cleanly separate attended assistants from tool-using, event-triggered, and fully autonomous actors at intakeNIST (n.d.)Business (n.d.)AI (n.d.)
  3. The CIA model should keep Confidentiality, Integrity, and Availability separate and set overall tier to the highest triggered axis, because regulated guidance treats those harms as distinct and a single catastrophic action surface must not be averaged awayAPRA (n.d.)APRA (n.d.)NIST (n.d.)NIST (n.d.)
  4. Confidentiality thresholds should be driven by data class and subject scale, Integrity thresholds by reversibility and action-consequence blast radius, and Availability thresholds by dependency criticality and outage tolerance, because those are the observable factors the reviewed standards and adjacent agentic-governance work require teams to documentAPRA (n.d.)NIST (n.d.)NIST (n.d.)Access (n.d.)
  5. Mandatory floors must be attached to entity type and consequence-bearing surfaces rather than to builder opinion, because payment-card scope, prudential information-security accountability, software-assurance levels, and agentic blast-radius evidence all show that some classes are too consequential for discretionary downgradingPCI (n.d.)APRA (n.d.)Federal (8110)Access (n.d.)
  6. High and Critical assignments should be independently validated and downward appeals should require specific contrary evidence instead of compensating-control narratives, because the enterprise bears the downside of under-classification while the builder experiences only the local cost of stronger governanceAPRA (n.d.)NIST (n.d.)Business (n.d.)
  7. Scaffold generation should stamp immutable invariants for entity type, autonomy class, data class, write capability, privilege level, external exposure, dependency criticality, and human-checkpoint pattern, because any change to those attributes materially changes risk and enforcement topologyAPRA (n.d.)NIST (n.d.)AI (n.d.)Policy (n.d.)
  8. The governance profile should be implemented as tier baselines plus entity modifiers rather than as a flat bespoke matrix, because that structure is exhaustive, composable, and directly consumable by the adjacent policy-layer and PAP-topology itemsGithub (n.d.)Policy (n.d.)AI (n.d.)

Research Question

What canonical entity taxonomy and Confidentiality, Integrity, and Availability (CIA) classification system should the UELGF use to determine governance intensity, ensuring that every entity type, from a fully autonomous Artificial Intelligence (AI) agent to a procurement decision, receives a governance profile that is proportionate to its actual risk and that the classification process cannot be gamed by builder self-assessment at high CIA tiers?

Findings

Executive Summary

Key Findings

  1. A stable UELGF taxonomy should classify entities by dominant executed function rather than by owning team or implementation medium, because operational taxonomies remain durable only when runtime consequence, service role, and domain boundary are separated explicitly.
  2. AI agents need four mutually exclusive autonomy classes with observable falsifiers, because human oversight, trigger mode, and task persistence cleanly separate attended assistants from tool-using, event-triggered, and fully autonomous actors at intake.
  3. The CIA model should keep Confidentiality, Integrity, and Availability separate and set overall tier to the highest triggered axis, because regulated guidance treats those harms as distinct and a single catastrophic action surface must not be averaged away.
  4. Confidentiality thresholds should be driven by data class and subject scale, Integrity thresholds by reversibility and action-consequence blast radius, and Availability thresholds by dependency criticality and outage tolerance, because those are the observable factors the reviewed standards and adjacent agentic-governance work require teams to document.
  5. Mandatory floors must be attached to entity type and consequence-bearing surfaces rather than to builder opinion, because payment-card scope, prudential information-security accountability, software-assurance levels, and agentic blast-radius evidence all show that some classes are too consequential for discretionary downgrading.
  6. High and Critical assignments should be independently validated and downward appeals should require specific contrary evidence instead of compensating-control narratives, because the enterprise bears the downside of under-classification while the builder experiences only the local cost of stronger governance.
  7. Scaffold generation should stamp immutable invariants for entity type, autonomy class, data class, write capability, privilege level, external exposure, dependency criticality, and human-checkpoint pattern, because any change to those attributes materially changes risk and enforcement topology.
  8. The governance profile should be implemented as tier baselines plus entity modifiers rather than as a flat bespoke matrix, because that structure is exhaustive, composable, and directly consumable by the adjacent policy-layer and PAP-topology items.

Assumptions

Analysis

Entity type Distinguishing property Observable entry evidence Mandatory builder inputs Scaffold invariants Default floor
Policy or content artefact Declares, constrains, or communicates but does not execute file type, publication target, no runtime identity audience, regulated use, downstream enforcement use regulated use, publication channel Low
Data product Primary value is maintained data for consumption by others dataset schema, access path, producer, consumers data classes, subject-count band, refresh cadence data classes, subject-count band, external sharing Low, or High if regulated data
Frontend application Interactive user surface without independent orchestration user interface, session model, channel exposure auth model, data classes, write surfaces auth mode, write surfaces, external exposure Low
Integration component Moves, transforms, or synchronizes data or commands across systems connector list, endpoints, triggers source and target systems, directionality, write surfaces endpoint scope, trigger mode, write surfaces Medium
Software service Hosts business or technical capability behind an interface service endpoint, deployment identity, dependent systems dependency class, write surfaces, recovery tolerance dependency criticality, privilege level Medium
SaaS product Externally provided application surface with tenant-level governance vendor platform, tenant boundaries, admin surface vendor role, system-of-record status, data classes vendor role, system-of-record status Medium
Decision workflow Produces binding approval or rejection state workflow engine, approval outcome, downstream actuation decision consequence, reversal path, human checkpoint decision consequence, checkpoint pattern High
AI agent Uses model-led reasoning to answer, decide, or act model component, tool surface, trigger mode autonomy class, tool set, checkpoint pattern autonomy class, tool set, checkpoint pattern Class-dependent
Class Definition Entry test Falsification trigger Floor
Agent-1 Declarative or scoped assistant Generates content or analysis inside a user-invoked interaction and has no side-effecting tool execution no external write, no independent trigger any side-effecting tool call Low
Agent-2 User-invoked action agent Runs only inside an explicit user request but can call tools or APIs to read or write during that session user initiation required per run scheduled or event-triggered execution Medium
Agent-3 Event-triggered bounded autonomous agent Executes on schedule or event without per-run initiation, but goal is predefined and bounded autonomous trigger, fixed scope persistent task creation or reprioritization High
Agent-4 Fully autonomous agent Can create, chain, or reprioritize work across time and operate under its own bounded machine identity persistent work graph or independent re-entry not applicable, this is top class High, or Critical with privileged or consequential write access
Axis Low Medium High Critical
Confidentiality public or internal operational data, no regulated personal or secret material internal confidential business data or limited personal data customer personal, financial, authentication, or security-sensitive data, or broad subject-scale exposure payment credentials, encryption keys, privileged secrets, or data whose exposure materially threatens customers or enterprise control
Integrity read-only or fully reversible internal changes bounded writes with routine correction path consequential writes to production, regulated records, customer communications, or approval states legally, financially, or operationally irreversible machine-speed action, including privileged policy or payment execution
Availability outage tolerable for more than five business days with simple workaround outage tolerable for one to five business days with costly workaround outage materially disrupts critical operations or customers within one business day outage threatens critical operation, regulatory obligation, or customer access within hours
Trigger Minimum result Why it floors
Cardholder or sensitive authentication data, or system can impact that environment Confidentiality High and overall High minimum PCI treats those surfaces as in scope by rule
Privileged credentials, policy mutation, payment execution, or production deployment authority Integrity Critical Reversal is too slow or incomplete once action is exercised
Decision workflow affecting customer, credit, procurement, or regulatory commitment Integrity High minimum The primary risk is wrong or premature binding state change
Agent-3 autonomy overall High minimum Non-attended execution removes per-run human initiation
Agent-4 plus privileged or consequential write access overall Critical minimum Machine-speed multi-step action creates enterprise-scale blast radius
System of record for critical operation Availability High minimum Operational dependency dominates governance intensity
Step Actor Rule
Evidence submission builder declares type, surfaces, data, dependencies, autonomy, and checkpoints
Provisional scoring platform or PAP computes axis scores and floors automatically
Medium validation architecture plus security owner confirms declared evidence and floors
High validation architecture, security, and risk owner required before rail approval
Critical validation architecture, security, risk, and accountable executive required before build or deployment progresses
Downward appeal independent review body allowed only if triggering attribute is factually absent
Tier baseline Applicable policy layers Mandatory hard gates Manual checkpoints Observability Maximum re-evaluation interval
Low Layers 5, 7, 8 scaffold lint and policy conformance only none by default inventory plus basic audit log 12 months
Medium Layers 5, 6, 7, 8 intake validation, identity check, delivery gate owner approval inventory, decision log, change log, dependency map 6 months
High Layers 1, 5, 6, 7, 8 intake gate, identity gate, delivery gate, pre-production readiness gate architecture, security, and risk checkpoint full decision logs, access logs, policy-denial logs, anomaly alerts 90 days
Critical Layers 1, 2, 3, 5, 6, 7, 8 hard intake gate, hard identity gate, hard delivery gate, production enablement gate accountable executive plus independent risk sign-off real-time telemetry, immutable audit trail, rollback and kill-switch validation, continuous anomaly monitoring 30 days
Entity modifier Extra controls added to baseline
Policy or content artefact add review for regulated publication and version integrity when downstream enforcement depends on content
Data product add schema drift, access-pattern, and downstream-consumer monitoring
Frontend application add user-session telemetry and channel-specific abuse monitoring
Integration component add connector allow-list, source-target lineage, and rate anomaly monitoring
Software service add dependency health, privileged-operation logging, and release provenance
SaaS product add vendor-admin review, tenant-boundary review, and compensating-control check
Decision workflow add mandatory human override route, outcome attribution, and decision-sampling review
AI agent add autonomy-specific tool-call logs, prompt or policy version binding, and checkpoint-failure escalation

Risks, Gaps, and Uncertainties

Open Questions


sources

Connected items

Loading…

View full knowledge graph →