Universal Entity Lifecycle Governance Framework (UELGF)
Universal Entity Lifecycle Governance Framework (UELGF): canonical entity taxonomy and Confidentiality, Integrity, and Availability (CIA) classification system for determining governance intensity
- A stable UELGF taxonomy should classify entities by dominant executed function rather than by owning team or implementation medium, because operational taxonomies remain durable only when runtime consequence, service role, and domain boundary are separated explicitlyAmazon (n.d.)Opengroup (n.d.)CSDM (n.d.)
- AI agents need four mutually exclusive autonomy classes with observable falsifiers, because human oversight, trigger mode, and task persistence cleanly separate attended assistants from tool-using, event-triggered, and fully autonomous actors at intakeNIST (n.d.)Business (n.d.)AI (n.d.)
- The CIA model should keep Confidentiality, Integrity, and Availability separate and set overall tier to the highest triggered axis, because regulated guidance treats those harms as distinct and a single catastrophic action surface must not be averaged awayAPRA (n.d.)APRA (n.d.)NIST (n.d.)NIST (n.d.)
- Confidentiality thresholds should be driven by data class and subject scale, Integrity thresholds by reversibility and action-consequence blast radius, and Availability thresholds by dependency criticality and outage tolerance, because those are the observable factors the reviewed standards and adjacent agentic-governance work require teams to documentAPRA (n.d.)NIST (n.d.)NIST (n.d.)Access (n.d.)
- Mandatory floors must be attached to entity type and consequence-bearing surfaces rather than to builder opinion, because payment-card scope, prudential information-security accountability, software-assurance levels, and agentic blast-radius evidence all show that some classes are too consequential for discretionary downgradingPCI (n.d.)APRA (n.d.)Federal (8110)Access (n.d.)
- High and Critical assignments should be independently validated and downward appeals should require specific contrary evidence instead of compensating-control narratives, because the enterprise bears the downside of under-classification while the builder experiences only the local cost of stronger governanceAPRA (n.d.)NIST (n.d.)Business (n.d.)
- Scaffold generation should stamp immutable invariants for entity type, autonomy class, data class, write capability, privilege level, external exposure, dependency criticality, and human-checkpoint pattern, because any change to those attributes materially changes risk and enforcement topologyAPRA (n.d.)NIST (n.d.)AI (n.d.)Policy (n.d.)
- The governance profile should be implemented as tier baselines plus entity modifiers rather than as a flat bespoke matrix, because that structure is exhaustive, composable, and directly consumable by the adjacent policy-layer and PAP-topology itemsGithub (n.d.)Policy (n.d.)AI (n.d.)
Research Question
What canonical entity taxonomy and Confidentiality, Integrity, and Availability (CIA) classification system should the UELGF use to determine governance intensity, ensuring that every entity type, from a fully autonomous Artificial Intelligence (AI) agent to a procurement decision, receives a governance profile that is proportionate to its actual risk and that the classification process cannot be gamed by builder self-assessment at high CIA tiers?
Findings
Executive Summary
-
The UELGF should classify every governed object into one canonical entity type and one CIA tier using highest-triggered-axis scoring plus mandatory floors, because APRA separates availability impact from confidentiality or integrity impact, NIST requires documented context and impact analysis, and PCI shows that some control surfaces are high consequence by rule rather than by self-description.
-
The canonical taxonomy should distinguish passive policy or content artefacts, passive data products, interactive frontend applications, integration components, software services, SaaS products, decision workflows, and four mutually exclusive AI agent autonomy classes, with classification assigned to the highest-action surface exposed at rail entry.
-
Builder self-assessment should stop at evidence submission, because the accessible high-assurance analogues all place minimum consequence class assignment outside developer discretion, and machine-speed blast radius means autonomy, privileged access, and regulated-data adjacency must impose automatic floors before builder optimism can reduce them.
-
Governance intensity should then be applied compositionally: tier baselines determine which policy layers, gates, manual checkpoints, observability controls, and review cadences apply, while entity-type modifiers add specific controls for agents, decision workflows, data products, and privileged execution surfaces.
Key Findings
- A stable UELGF taxonomy should classify entities by dominant executed function rather than by owning team or implementation medium, because operational taxonomies remain durable only when runtime consequence, service role, and domain boundary are separated explicitly.
- AI agents need four mutually exclusive autonomy classes with observable falsifiers, because human oversight, trigger mode, and task persistence cleanly separate attended assistants from tool-using, event-triggered, and fully autonomous actors at intake.
- The CIA model should keep Confidentiality, Integrity, and Availability separate and set overall tier to the highest triggered axis, because regulated guidance treats those harms as distinct and a single catastrophic action surface must not be averaged away.
- Confidentiality thresholds should be driven by data class and subject scale, Integrity thresholds by reversibility and action-consequence blast radius, and Availability thresholds by dependency criticality and outage tolerance, because those are the observable factors the reviewed standards and adjacent agentic-governance work require teams to document.
- Mandatory floors must be attached to entity type and consequence-bearing surfaces rather than to builder opinion, because payment-card scope, prudential information-security accountability, software-assurance levels, and agentic blast-radius evidence all show that some classes are too consequential for discretionary downgrading.
- High and Critical assignments should be independently validated and downward appeals should require specific contrary evidence instead of compensating-control narratives, because the enterprise bears the downside of under-classification while the builder experiences only the local cost of stronger governance.
- Scaffold generation should stamp immutable invariants for entity type, autonomy class, data class, write capability, privilege level, external exposure, dependency criticality, and human-checkpoint pattern, because any change to those attributes materially changes risk and enforcement topology.
- The governance profile should be implemented as tier baselines plus entity modifiers rather than as a flat bespoke matrix, because that structure is exhaustive, composable, and directly consumable by the adjacent policy-layer and PAP-topology items.
Assumptions
- Subject-count bands can be used as an intake proxy for Confidentiality where exact live counts are unavailable. Justification: pre-deployment classification still requires measurable thresholds before runtime history exists.
- The accessible AWS and ArchiMate sources plus the completed ServiceNow CSDM item are sufficient to anchor the entity-family split despite the seeded ServiceNow hierarchy page being inaccessible in this runtime. Justification: all three sources support the same active-versus-passive and strategic-versus-runtime distinctions.
Analysis
- Proposed canonical entity taxonomy and default floors:
| Entity type | Distinguishing property | Observable entry evidence | Mandatory builder inputs | Scaffold invariants | Default floor |
|---|---|---|---|---|---|
| Policy or content artefact | Declares, constrains, or communicates but does not execute | file type, publication target, no runtime identity | audience, regulated use, downstream enforcement use | regulated use, publication channel | Low |
| Data product | Primary value is maintained data for consumption by others | dataset schema, access path, producer, consumers | data classes, subject-count band, refresh cadence | data classes, subject-count band, external sharing | Low, or High if regulated data |
| Frontend application | Interactive user surface without independent orchestration | user interface, session model, channel exposure | auth model, data classes, write surfaces | auth mode, write surfaces, external exposure | Low |
| Integration component | Moves, transforms, or synchronizes data or commands across systems | connector list, endpoints, triggers | source and target systems, directionality, write surfaces | endpoint scope, trigger mode, write surfaces | Medium |
| Software service | Hosts business or technical capability behind an interface | service endpoint, deployment identity, dependent systems | dependency class, write surfaces, recovery tolerance | dependency criticality, privilege level | Medium |
| SaaS product | Externally provided application surface with tenant-level governance | vendor platform, tenant boundaries, admin surface | vendor role, system-of-record status, data classes | vendor role, system-of-record status | Medium |
| Decision workflow | Produces binding approval or rejection state | workflow engine, approval outcome, downstream actuation | decision consequence, reversal path, human checkpoint | decision consequence, checkpoint pattern | High |
| AI agent | Uses model-led reasoning to answer, decide, or act | model component, tool surface, trigger mode | autonomy class, tool set, checkpoint pattern | autonomy class, tool set, checkpoint pattern | Class-dependent |
- AI agent autonomy sub-taxonomy:
| Class | Definition | Entry test | Falsification trigger | Floor |
|---|---|---|---|---|
| Agent-1 Declarative or scoped assistant | Generates content or analysis inside a user-invoked interaction and has no side-effecting tool execution | no external write, no independent trigger | any side-effecting tool call | Low |
| Agent-2 User-invoked action agent | Runs only inside an explicit user request but can call tools or APIs to read or write during that session | user initiation required per run | scheduled or event-triggered execution | Medium |
| Agent-3 Event-triggered bounded autonomous agent | Executes on schedule or event without per-run initiation, but goal is predefined and bounded | autonomous trigger, fixed scope | persistent task creation or reprioritization | High |
| Agent-4 Fully autonomous agent | Can create, chain, or reprioritize work across time and operate under its own bounded machine identity | persistent work graph or independent re-entry | not applicable, this is top class | High, or Critical with privileged or consequential write access |
- CIA threshold model:
| Axis | Low | Medium | High | Critical |
|---|---|---|---|---|
| Confidentiality | public or internal operational data, no regulated personal or secret material | internal confidential business data or limited personal data | customer personal, financial, authentication, or security-sensitive data, or broad subject-scale exposure | payment credentials, encryption keys, privileged secrets, or data whose exposure materially threatens customers or enterprise control |
| Integrity | read-only or fully reversible internal changes | bounded writes with routine correction path | consequential writes to production, regulated records, customer communications, or approval states | legally, financially, or operationally irreversible machine-speed action, including privileged policy or payment execution |
| Availability | outage tolerable for more than five business days with simple workaround | outage tolerable for one to five business days with costly workaround | outage materially disrupts critical operations or customers within one business day | outage threatens critical operation, regulatory obligation, or customer access within hours |
- Automatic floors and assignment process:
| Trigger | Minimum result | Why it floors |
|---|---|---|
| Cardholder or sensitive authentication data, or system can impact that environment | Confidentiality High and overall High minimum | PCI treats those surfaces as in scope by rule |
| Privileged credentials, policy mutation, payment execution, or production deployment authority | Integrity Critical | Reversal is too slow or incomplete once action is exercised |
| Decision workflow affecting customer, credit, procurement, or regulatory commitment | Integrity High minimum | The primary risk is wrong or premature binding state change |
| Agent-3 autonomy | overall High minimum | Non-attended execution removes per-run human initiation |
| Agent-4 plus privileged or consequential write access | overall Critical minimum | Machine-speed multi-step action creates enterprise-scale blast radius |
| System of record for critical operation | Availability High minimum | Operational dependency dominates governance intensity |
| Step | Actor | Rule |
|---|---|---|
| Evidence submission | builder | declares type, surfaces, data, dependencies, autonomy, and checkpoints |
| Provisional scoring | platform or PAP | computes axis scores and floors automatically |
| Medium validation | architecture plus security owner | confirms declared evidence and floors |
| High validation | architecture, security, and risk owner | required before rail approval |
| Critical validation | architecture, security, risk, and accountable executive | required before build or deployment progresses |
| Downward appeal | independent review body | allowed only if triggering attribute is factually absent |
- Governance profile matrix, built as tier baselines plus entity modifiers:
| Tier baseline | Applicable policy layers | Mandatory hard gates | Manual checkpoints | Observability | Maximum re-evaluation interval |
|---|---|---|---|---|---|
| Low | Layers 5, 7, 8 | scaffold lint and policy conformance only | none by default | inventory plus basic audit log | 12 months |
| Medium | Layers 5, 6, 7, 8 | intake validation, identity check, delivery gate | owner approval | inventory, decision log, change log, dependency map | 6 months |
| High | Layers 1, 5, 6, 7, 8 | intake gate, identity gate, delivery gate, pre-production readiness gate | architecture, security, and risk checkpoint | full decision logs, access logs, policy-denial logs, anomaly alerts | 90 days |
| Critical | Layers 1, 2, 3, 5, 6, 7, 8 | hard intake gate, hard identity gate, hard delivery gate, production enablement gate | accountable executive plus independent risk sign-off | real-time telemetry, immutable audit trail, rollback and kill-switch validation, continuous anomaly monitoring | 30 days |
| Entity modifier | Extra controls added to baseline |
|---|---|
| Policy or content artefact | add review for regulated publication and version integrity when downstream enforcement depends on content |
| Data product | add schema drift, access-pattern, and downstream-consumer monitoring |
| Frontend application | add user-session telemetry and channel-specific abuse monitoring |
| Integration component | add connector allow-list, source-target lineage, and rate anomaly monitoring |
| Software service | add dependency health, privileged-operation logging, and release provenance |
| SaaS product | add vendor-admin review, tenant-boundary review, and compensating-control check |
| Decision workflow | add mandatory human override route, outcome attribution, and decision-sampling review |
| AI agent | add autonomy-specific tool-call logs, prompt or policy version binding, and checkpoint-failure escalation |
Risks, Gaps, and Uncertainties
- The official Federal Register path for current FDA Computer Software Assurance guidance was anti-bot gated in this runtime, so pharmaceutical-manufacturing evidence was not used to support the final floor model.
- APRA gives methodology direction rather than numeric thresholds, so the exact subject-count and outage-tolerance bands in the proposed model are a synthesis layer rather than regulator-prescribed numbers.
- FAA material in this runtime was more usable for the governance pattern of assigned consequence classes than for a detailed extraction of all software-level definitions, so aviation is used here as an assignment analogue rather than as a one-to-one numeric template.
Open Questions
- Should the PAP expose floors as human-readable policy rules or only as computed outputs from a topology-derivation function?
- Should Agent-4 entities be split again by whether they can modify their own tool graph or only their task graph?
- What empirical subject-count and outage-tolerance thresholds best fit the target banking context without creating unnecessary High classifications for low-consequence internal data sets?
sources
- [x] APRA CPS 234 Information Security — - primary definitions for confidentiality, integrity, availability, criticality, sensitivity, and board accountability
- [x] APRA CPG 234 Information Security — - primary guidance on classification methodology, lifecycle controls, and annual or material-change review
- [x] APRA information security landing page — - official APRA source pointing to the current CPS 234 and CPG 234 artefacts
- [x] APRA CPG 234 PDF — - primary text used for direct extraction of classification-methodology clauses
- [x] NIST SP 800-30 Rev. 1 — - primary risk-assessment guidance for likelihood and impact framing
- [x] NIST likelihood glossary entry — - direct NIST definition linked back to SP 800-30
- [x] NIST AI RMF 1.0 publication page — - primary description of the AI RMF's purpose and scope
- [x] NIST AI RMF Core — - primary source for intended purpose, human oversight, impact likelihood and magnitude, and go or no-go logic
- [x] NIST AI RMF Playbook Map page — - official companion page for Map-function implementation guidance
- [x] PCI DSS standard page — - official scoping statement for cardholder data, sensitive authentication data, and systems that could impact the cardholder data environment
- [x] PCI SSC document library — - official document-library entry point for PCI DSS v4.0.1 artefacts
- [x] Amazon Web Services (AWS) ARN and namespace reference — - primary evidence that operational asset taxonomies distinguish resources by service namespace and resource type
- [x] The Open Group ArchiMate 4 Specification overview — - official reference that enterprise architecture uses explicit domain distinctions rather than one undifferentiated asset class
- [x] Federal Aviation Administration (FAA) Order 8110.49A — - official software-approval guidance showing software levels are assigned by system safety assessment rather than developer preference
- [x] Federal Aviation Administration (FAA) AC 20-115C — - official advisory circular that ties compliance activities to the assigned software level
- [x] AI agent control plane architecture for enterprise — - prior completed item on autonomy levels and control-plane implications
- [x] AI agent identity and access management for enterprise — - prior completed item on machine identity, delegation, and least privilege by actor type
- [x] AI and low-code risk tier classification and controls — - prior completed item on highest-triggered-tier logic and proportional control depth
- [x] Business-led low-code agent governance — - prior completed item on bounded complexity, central governance, and maker incentives
- [x] Policy Administration Point (PAP) dynamic policy profiling and proportionality — - prior completed item on CIA-driven proportional enforcement topology
- [x] ServiceNow Common Service Data Model (CSDM): Practical Data Modelling Across ITSM, APM, SPM, IRM, and FSO — - prior completed item on business application, service instance, and technical-service distinctions
- [x] AI concept classification taxonomy — - prior completed item on mutually exclusive taxonomy construction
- [x] Access control amplification under agentic operations — - prior completed item on machine-speed blast radius and least-privilege amplification