CONTENTS
01 What This Is
The Attestation Coverage Matrix is a diagnostic for a specific, common mistake: treating "we scoped this agent correctly" as if it meant "this agent is safe." It answers one question:
What does this agent's governance actually attest to, and where does that attestation stop?
Most organizations run an access review, pass it, and let the passing grade quietly stand in for a much bigger claim than the review ever made. The Matrix checks five things a scoping program can genuinely cover, and names one thing, plainly, that it structurally cannot, so nobody mistakes the five for the whole picture.
It is usable on its own. You do not need to read the full issue to run it.
02 Core Concept: Attestation Has a Boundary
A passed access review makes one claim: this agent's granted permissions match a documented, approved scope. That claim is real and worth having. It is not a claim about whether the agent's work was correct, and it was never designed to be one.
The Matrix treats that boundary as the organizing fact. It scores five dimensions a governance program can actually deliver, and it refuses, by design, to let a clean scorecard on those five read as "safe." One dimension, Completion Judgment, is included specifically so it cannot be silently dropped from the picture: it stays visible on every scorecard, marked as currently unassessable, because pretending otherwise is the exact substitution this issue is about.
03 The Six Dimensions
| # | Dimension | Core question | What a failure looks like |
|---|---|---|---|
| 1 | Grant Fit | Does granted access match currently justified use? | Standing permissions nobody has exercised, kept "just in case" |
| 2 | Runtime Binding | Is the permission re-checked at the moment of the specific action, or only once at deployment? | A session-length approval treated as covering every action inside it equally |
| 3 | Category Coverage | Is the risk being governed actually an access risk? | Access tooling credited for catching a completion, retrieval, or response failure it never touched |
| 4 | Lifecycle Currency | Does the grant still match today's owner, purpose, and connected tools? | A review from six months ago describing an agent that has since changed shape |
| 5 | Attestation Scope | Does anyone citing this agent's governance know what it actually certifies? | A signed audit treated internally, or externally, as proof of safety rather than proof of scope |
| 6 | Completion Judgment | Was this specific action, taken inside authorized scope, actually the correct one? | Not scored by this Matrix. This issue's research did not establish a reliable, general-purpose method for automatically certifying this dimension. See below. |
Dimension 6 is never scored Pass. It is not a placeholder for a future version of this artifact to fill in casually; it is included to keep the honest limit of the other five permanently visible.
04 The Five Embedded Modules
The Matrix does not invent new instruments for dimensions 1 through 5. It integrates the tools from this issue's Vector Special Reports and Table, each of which operationalizes one dimension directly.
| Module | From | Primarily evaluates |
|---|---|---|
| Grant-vs-Use Gap Audit | VSR-01, The Scope That Was Too Wide | Grant Fit |
| Runtime Binding Test | VSR-02, The Approval That Wasn't Runtime-Bound | Runtime Binding |
| Control Coverage Map | VSR-03, What Scoping Doesn't Touch | Category Coverage |
| Agent Lifecycle Register | VSR-04, The Identity That Outlived Its Purpose | Lifecycle Currency |
| Attestation boundary check | THE TABLE, The Substitution Test (The Compliance Auditor's turn) | Attestation Scope |
Run the modules to fill dimensions 1 through 5. Dimension 6 stays open by design; nothing in this issue closes it, and this issue's research did not find a reliable, general-purpose method that does, per the Table's Infrastructure Engineer finding.
05 Running the Matrix
- Run the Grant-vs-Use Gap Audit. Compare granted capability against exercised capability over a review window. Unjustified gaps count against Grant Fit.
- Run the Runtime Binding Test. Classify each approval gate as design-time trust or genuinely runtime-bound.
- Run the Control Coverage Map. Sort recent incidents or near-misses by failure category; check whether access control was ever the right lever for each one.
- Check the Lifecycle Register. Confirm a named current owner, an accurate purpose, and a review date inside the recommended window.
- State the Attestation Scope out loud. Write, in one sentence, exactly what this agent's current governance certifies. If that sentence is broader than "granted access matches approved scope," Attestation Scope fails, regardless of how the agent is actually behaving.
- Record Completion Judgment as Unassessable. Do not attempt to score it as Pass. If your organization has a genuine, reliable method for automatically judging whether specific in-scope actions were correct, that is new information this issue's Table did not have; note it and treat it as a real update to this artifact, not a routine entry.
- Apply the verdict rule below.
06 Dimension Verdicts
| Rating | Meaning |
|---|---|
| Pass | Meets the standard for this dimension. |
| Caution | Meets it with a noted weakness that should be funded or fixed. |
| Fail | Does not meet the standard. |
| Unassessable | Not evaluable, either from missing instrumentation (dimensions 1 to 5) or, for dimension 6 specifically, by design. |
07 The Coverage Verdict
The verdict is deliberately capped. No combination of scores on this Matrix produces a verdict that reads as "safe" or "fully assured," because that claim is exactly what dimension 6 keeps open.
| Verdict | Condition |
|---|---|
| Overclaimed | Attestation Scope (5) is Fail, regardless of scores elsewhere. The governance in place is being described, internally or externally, as covering more than it does. This is the worst verdict on the Matrix, ahead of any technical gap, because it is the one this issue is named for. |
| Scoped, Not Governed | Attestation Scope passes, but one or more of Grant Fit, Runtime Binding, Category Coverage, or Lifecycle Currency (1 to 4) is Fail. The access program itself has a real, fixable gap. |
| Scoped and Governed | Dimensions 1 through 5 all Pass or Caution with a named remediation. This is the best verdict the Matrix can return. It is explicitly not "Assured" or "Safe." Dimension 6 remains open on every scorecard that reaches this verdict. |
The decisive line: this Matrix has no verdict that means "nothing left to check." The best outcome it can certify is that the governable half of the problem is genuinely governed, stated plainly, with the ungoverned half still named on the page.
08 Reading the Matrix Against a Result
- Grant Fit Pass, Attestation Scope Fail → Overclaimed. The access program may be working correctly; what's broken is what people are allowed to believe it proves.
- Category Coverage Fail → the organization is spending remediation effort on access tooling for a failure access tooling was never built to reach. Redirect the budget, per the Control Coverage Map, before buying more of the same fix.
- All of 1 to 5 Pass → Scoped and Governed. A real, creditable state. Still not evidence that any specific action taken inside that scope was correct.
- Dimension 6 scored anything other than Unassessable → stop and check the claim behind that score before trusting it. As of this issue, nothing reliably supports it.
09 How This Relates to the VSR Stack and the Table
The four Vector Special Reports each supply one instrument for one dimension. The Matrix is where their findings combine into a single governance-coverage verdict, and where the boundary the Table found gets encoded structurally rather than left as a caveat in a report nobody rereads.
THE SUBSTITUTION TEST, this issue's Table, debated the principle the Matrix operationalizes: whether "we scoped it right" is an adequate defense, and who answers for it when it isn't. The Matrix is the instrument that turns that debate into a scorecard an operator can actually run, one that cannot be gamed into claiming more than it knows.
10 Closing Principle
Score what your governance actually covers, not what you'd like it to mean. The gap between the two is where the next incident lives.
An access review tells you what an agent was allowed to touch. It does not tell you what the agent did once it got there. Score the boundary honestly, leave the ungoverned dimension visible instead of hidden, and a passed audit stops being the end of the conversation about safety and becomes what it always should have been: one input into it.