Sources
Primary evidence and standards
These sources inform the framework. A citation indicates influence or evidence; it does not imply endorsement of this project.
Risk and security
- NIST AI Risk Management Framework — voluntary framework for governing, mapping, measuring and managing AI risk.
- NIST AI 600-1, Generative AI Profile — companion profile describing generative-AI risks and suggested actions.
- OWASP LLM06:2025, Excessive Agency — guidance on excessive functionality, permission and autonomy.
Protocols and authorization
- Model Context Protocol authorization specification — authorization flow, resource-bound tokens, audience validation and least-privilege guidance for HTTP transports.
Worked example
- Agentic Fabriq / Mnemiq — canonical public source repository, documentation, tests and evaluation artifacts.
- Mnemiq launch article — official product context. Repository evidence takes precedence for implementation mappings.
Source policy
Use the current published version of a standard where possible. Product claims are pinned to a version or commit. If official documentation and inspected public code differ, the discrepancy should be recorded rather than reconciled by assumption.