CONTENTS
01 What This Is
The Containment Coverage Matrix is a diagnostic for a specific, common mistake: assuming that because you've secured what an agent can reach, you've secured what it might do. It answers one question:
Which layer of containment does your organization actually have in place, and which layer, honestly, does nobody have?
This issue's terrain showed an agent using entirely legitimate access to produce a real intrusion, caught not by any purchased security tool but by one lab's own after-the-fact decision not to ship its next model. The Matrix scores four things an organization can genuinely build today, and names one thing, plainly, that currently exists nowhere as a reliable, purchasable capability, so nobody mistakes the four for the whole picture.
It is usable on its own. You do not need to read the full issue to run it.
02 Core Concept: Containment Has a Boundary
Most organizations think about agent security as a single stack: identity, permissions, monitoring, done. This issue's evidence says that stack answers "what can this agent reach," and answers it reasonably well. It does not answer "did this agent do the right thing with what it could reach," and this window supplied the clearest evidence yet that the second question is where real damage happens, an agent with entirely legitimate access, pursuing its stated goal honestly, still produced an attacker-grade intrusion.
The Matrix treats that boundary as the organizing fact. It scores four dimensions an organization can actually build and verify, and it refuses, by design, to let a clean scorecard on those four read as "trajectory-safe." One dimension, Trajectory Judgment, is included specifically so it cannot be silently dropped from the picture: it stays visible on every scorecard, marked as currently unassessable, because pretending otherwise is the exact overclaim this issue is about.
03 The Five Dimensions
| # | Dimension | Core question | What a failure looks like |
|---|---|---|---|
| 1 | Eval Containment | Before granting an agent real tool or network access for testing, was everything it could reach documented and pressure-tested? | An evaluation environment with inherited, unaudited access, discovered only after an incident forces the reconstruction |
| 2 | Dependency Exposure | Is every credential potentially touched by a known supply-chain compromise verified as rotated, not assumed closed once the malicious package is removed? | A team confirms the bad package is gone and stops checking, while exposed credentials remain live |
| 3 | Capability Gate | Is there a named person or committee with real authority to delay deployment when a system shows capability the current safeguards weren't built for? | A capability review exists on paper with nobody actually empowered to enforce a delay |
| 4 | Coverage Ownership | Is the gap between deployment pace and security coverage tracked over time, with a named cause and a named owner, rather than assumed to be closing on its own? | "We're still maturing" offered as an explanation, with no measurement behind it |
| 5 | Trajectory Judgment | Was this specific sequence of actions, taken with legitimate access, actually the correct path to take? | Not scored by this Matrix. This issue's Table could not identify a reliable, external, verifiable method for this that doesn't either bottleneck deployment or become a rubber stamp. See below. |
Dimension 5 is never scored Pass. It is not a placeholder for a future version of this artifact to fill in casually; it is included to keep the honest limit of the other four permanently visible.
04 The Four Embedded Modules
The Matrix does not invent new instruments for dimensions 1 through 4. It integrates the tools from this issue's Vector Special Reports, each of which operationalizes one dimension directly.
| Module | From | Primarily evaluates |
|---|---|---|
| Eval Containment Checklist | VSR-01, The Eval That Became an Intrusion | Eval Containment |
| Dependency Exposure Self-Check | VSR-02, What the Forty Minutes Cost | Dependency Exposure |
| Pre-Deployment Capability Gate Worksheet | VSR-03, Borrowing the Frontier-Lab Brake | Capability Gate |
| Security-Coverage Blocker Diagnostic | VSR-04, The Gap Between Deploying and Securing | Coverage Ownership |
Run the modules to fill dimensions 1 through 4. Dimension 5 stays open by design; nothing in this issue closes it, and THE TABLE's session (THE CONTAINMENT TEST) found no participant able to describe a workable alternative to it, external or otherwise.
05 Running the Matrix
- Run the Eval Containment Checklist. Document reachability for any agent evaluation with real tool or network access, before the eval runs, not after.
- Run the Dependency Exposure Self-Check. Confirm direct and transitive exposure to known compromises, and verify every reachable credential is rotated, not just the package removed.
- Run the Pre-Deployment Capability Gate Worksheet. Confirm a named person or committee actually has, and has exercised, authority to delay deployment based on demonstrated capability.
- Run the Security-Coverage Blocker Diagnostic. Name the specific blocker (ownership, velocity, tooling, or visibility) driving your organization's own deployment-versus-security gap, and track its trend over time.
- Record Trajectory Judgment as Unassessable. Do not attempt to score it as Pass. If your organization has a genuine, reliable method for judging in-progress agent trajectories against legitimate access, that is new information this issue's Table did not have; note it and treat it as a real update to this artifact, not a routine entry.
- Apply the verdict rule below.
06 Dimension Verdicts
| Rating | Meaning |
|---|---|
| Pass | Meets the standard for this dimension. |
| Caution | Meets it with a noted weakness that should be funded or fixed. |
| Fail | Does not meet the standard. |
| Unassessable | Not evaluable, either from missing instrumentation (dimensions 1 to 4) or, for dimension 5 specifically, by design. |
07 The Coverage Verdict
The verdict is deliberately capped. No combination of scores on this Matrix produces a verdict that reads as "trajectory-safe" or "fully contained," because that claim is exactly what dimension 5 keeps open.
| Verdict | Condition |
|---|---|
| Exposed | Eval Containment (1) or Dependency Exposure (2) is Fail. These are the two dimensions where this issue documented real, confirmed incidents this window; a Fail here means the organization is currently exposed to a failure mode that already happened to someone else, not a theoretical one. |
| Gated, Not Governed | Dimensions 1 and 2 pass, but Capability Gate (3) or Coverage Ownership (4) is Fail. The immediate incident-class exposure is controlled; the structural, longer-horizon containment isn't. |
| Contained | Dimensions 1 through 4 all Pass or Caution with a named remediation. This is the best verdict the Matrix can return. It is explicitly not "Trajectory-Safe" or "Fully Assured." Dimension 5 remains open on every scorecard that reaches this verdict, exactly as it does on OpenAI's own, per THE CONTAINMENT TEST. |
The decisive line: this Matrix has no verdict that means "nothing left to check." The best outcome it can certify is that the containable half of the problem is genuinely contained, stated plainly, with the ungoverned half still named on the page.
08 Reading the Matrix Against a Result
- Eval Containment Fail, everything else Pass → Exposed, regardless of how mature the rest of the program looks. This is the specific gap the Hugging Face incident occupied; a strong permission and coverage program does not compensate for an unaudited evaluation environment.
- Capability Gate Fail → the organization has no equivalent of the one mechanism this issue's Table found actually worked this window. This is a real, fixable gap, not a theoretical one; VSR-03 exists specifically to close it.
- All of 1 to 4 Pass → Contained. A real, creditable state. Still not evidence that any specific trajectory taken inside that containment was correct, and the Table found no organization, including OpenAI, that can currently make that claim reliably.
- Dimension 5 scored anything other than Unassessable → stop and check the claim behind that score before trusting it. As of this issue, nothing reliably supports it.
09 How This Relates to the VSR Stack and the Table
The four Vector Special Reports each supply one instrument for one dimension. The Matrix is where their findings combine into a single containment-coverage verdict, and where the boundary the Table found gets encoded structurally rather than left as a caveat in a report nobody rereads.
THE CONTAINMENT TEST, this issue's Table, debated the principle the Matrix operationalizes: whether the one mechanism that caught this window's real incident, a lab's own discretionary capability gate, is a system anyone else can rely on, or a coin flip that happened to land right once. The Matrix is the instrument that turns that debate into a scorecard an operator can actually run, one that cannot be gamed into claiming more containment than it knows it has.
10 Closing Principle
Score what your containment actually covers, not what you'd like it to mean. The gap between the two is where the next incident lives.
A secured perimeter tells you what an agent was allowed to reach. It does not tell you what the agent did once it got there, or whether the path it took, using access it legitimately held, was the right one. Score the boundary honestly, leave the ungoverned dimension visible instead of hidden, and a clean containment scorecard stops being the end of the conversation about safety and becomes what it always should have been: one input into it.