Skip to main content
Signature Product Capability

AI Action & Access Map

See how identities, permissions, AI actions, APIs, data and consequences connect. The Map shows what your AI systems and agents can reach, what controls apply, and what the evidence actually establishes.

What the Map Shows

Seven layers that define what evidence establishes about your AI

The AI Action & Access Map connects the layers that determine what an AI system or agent can reach, what it can change, and what happens when it acts. Each layer is backed by evidence — and each layer can have gaps.

Identity & Access

Who and what can act. Human identities, service accounts, API keys, OAuth scopes, and machine credentials that establish who can request an action.

Agents & Models

The AI systems and agents that initiate or mediate actions. LLMs, orchestration layers, agent frameworks, and model endpoints in the request path.

Tools & APIs / MCP

The tools, functions, APIs, and MCP servers the agent can invoke. Each tool is a potential action surface with its own access scope and consequence profile.

Data & State

The data stores, knowledge bases, vector indexes, and shared state the agent can read from or write to. Data access shapes what the agent can influence.

Consequences

The real-world outcomes an action can trigger — a payment, a deployment, a message sent, a record modified, a system shutdown. Consequences define what is at stake.

Evidence Basis

What the evidence actually establishes about each node and edge. Static analysis, runtime observation, credential evidence, and policy — each with its own coverage and limitations.

Unknowns

What is NOT established. Missing runtime evidence, unobserved paths, untested tools, and gaps between what credentials allow and what was actually observed. Unknowns are first-class citizens.

How It Works

From connected evidence to a map you can act on

1

Connect evidence sources

HAIEC builds the Map from the evidence available for the evaluated system. Depending on the connected sources, that may include source analysis, policy, identity/access information, credential evidence, tool definitions, provider evidence, and runtime observations.

2

HAIEC builds the map

The Map joins supported evidence where correlation is established and preserves unresolved or missing relationships explicitly.

3

See what is established — and what is not

Each node and edge shows its evidence basis. Unknowns, partial coverage, and unobserved paths are visible, not hidden.

4

Assure within evaluated scope

The Map feeds canonical Assurance evaluation. ALLOW means allowed within evaluated scope and available evidence — nothing more.

The Map is not a claim

It is an evidence-bound representation

  • Permission is not delegation. Credential evidence establishes what the credential evidence supports.
  • Static analysis shows what the code is capable of. Runtime observation shows what actually happened. They are different evidence types.
  • Unknown is not PASS. Missing runtime evidence is not “did not happen.” The Map preserves these distinctions.
  • Framework mapping is not certification. The Map supports assurance work — it does not replace professional judgment.

See the Map in action

Explore a sample AI Action & Access Map to see how identities, permissions, AI actions, APIs, data, and consequences connect — or scope an enterprise POC for your own systems.