Governance capital
Public readiness note for OSuite's AI Deployment Survival score and the runtime controls that make agent governance durable.
Public position
Governance capital is the durable control value created when agent actions become visible, bounded, portable, and provable.
OSuite uses this phrase carefully. It does not mean AI spend is always good. It means a buyer should be able to tell which AI deployments remain defensible if budgets tighten, providers change, or the organization has to explain an incident.
What is included
The in-product AI Deployment Survival score is calculated from six dimensions:
- runtime control assets
- bounded authority
- evidence durability
- runtime portability
- exposure resilience
- policy-to-runtime binding
Those dimensions are derived from existing OSuite objects: runtime adapters, actions, sessions, CAVA canonical action fields, policy profile output, Decision Score, PCAA authority, BAF leases, AREG exposure paths, and Runtime Exposure backlog state.
Buyer-readable test
A buyer can ask OSuite to export the Runtime Exposure report and check whether it answers:
- which agents and runtime lanes are active
- which actions are high impact
- which approvals are bounded to a specific action, actor, destination, policy, runtime session, and time window
- which proof bundles are complete enough for review
- which provider or runtime dependencies matter
- which exposure backlog items should be fixed next
If those answers are visible, the deployment has governance capital. If they are missing, the deployment is still mostly a pilot artifact.
Current implementation status
Status: implemented in Studio
Implemented surfaces:
- Runtime Exposure Management page
- Runtime Exposure Markdown, JSON, and print/PDF reports
- Control Center summary
- governance documentation
- readiness documentation
Current limitations:
- The score depends on observed runtime metadata and governed actions.
- Observe-only runtime lanes are disclosed as weaker than pre-execution enforcement.
- OSuite does not replace identity, DLP, SIEM, endpoint, or cloud-security controls.
- Customers still need to configure policy profiles and runtime adapters for their own environment.
Recommended pilot acceptance criteria
- At least one runtime lane is connected.
- At least one governed action is visible in Studio.
- The Runtime Exposure report includes Governance Capital.
- High-impact actions are approval-bound or clearly disclosed as observe-only.
- Proof and verification gaps are visible as remediation work.
- The buyer can explain what would survive a provider change.