Governance Standard · v1.3.26 · Production AI Agents

Build AI agents that are accountable, bounded, tested, verifiable, and ready for production.

Start with the proportional control standard, add the implementation toolkit, learn the operating method, or apply it to your real architecture — including Microsoft Entra identity controls — with expert guidance.

Most teams deploying agentic AI have none of this in place

Engineering teams are deploying agents at pace, while Security and Risk teams do not yet know what questions to ask. Enterprise security assumed a logged-in user is human — that assumption is already broken.

No agent identity Agents share credentials or borrow a human's login — no way to prove who did what.
No least-privilege enforcement Agents hold broader permissions than their task requires, with no review gate.
No evaluation evidence "It's live" isn't the same as proven safe against a golden case catalog.
No escalation path When something goes wrong, there's no defined human to stop it.
Zombie agents Agents from finished projects still holding live credentials and tool access.
No proportional controls One-size-fits-all policies either over-constrain low-risk agents or leave high-risk ones under-controlled.
No audit trail No repeatable process to show a regulator, auditor, or board what controls exist.

Get the charter

Single-organization license. Secure checkout by Stripe — your email is collected automatically at checkout so we know where to send your files. The implementation course (Tiers 3–5 and standalone) launches September 18, 2026 and is already substantially complete. Charter, toolkit, and Entra edition ship immediately.

Track 1 · Core Framework & Implementation Toolkit

1. The Charter

The standard · v1.3.26.822
$297
  • Editable charter (Word) + PDF reference
  • Proportional, risk-triggered safeguards on a stable control baseline
  • Identity, ownership, and least-privilege requirements
  • Three-layer verifier architecture (Pre-Action, State, Trajectory)
  • Golden Case evaluation, failure taxonomy, release thresholds
  • Escalation matrix + time-bounded exception governance
  • Lifecycle, decommissioning, and residual-access controls
Pay $297 →

Best for: technical founders, SMBs, advisors who self-implement

2. Implementation Kit

The working system · v1.3.26.822
$697
  • Everything in Tier 1
  • Operational toolkit: Start Here readiness snapshot, Digital Passport (core + advanced + conditional controls), Registry Checklist, Evaluation Scorecard, Failure Analysis, Escalation Matrix, Production Approval, Charter Completion Map
  • Conditional security controls (Signed Release Package, Multi-Agent Lineage, MCP Attestation, Conditional Audit Payload, Automated Access Revocation) — apply only when triggered
  • Quick-start workflow + risk-proportionate guidance
Pay $697 →

Best for: security/IT/compliance/product teams implementing independently

Track 2 · Enterprise Identity & Applied Expert Judgment
ENTERPRISE IDENTITY

5. Enterprise Identity Edition

Microsoft Entra · v1.3.26.8.22
$2,997self-serve edition
  • Everything in Tier 3 with the Entra-specific charter and toolkit
  • Tenant-verifiable identity record: blueprint, agent identity, Sponsor vs technical Owner
  • Conditional Access targeting + tested block path; compensating controls for gaps
  • Authentication pattern, residual-access / revocation test evidence requirements
  • Entra-aligned Digital Passport, Registry Checklist, and escalation triggers
  • Customer verification prompts for licensing, roles, preview status, and workload support
Pay $2,997 (Self-Serve) →

Best for: CIOs/CISOs/identity architects on Microsoft 365, Azure & Entra

Executive Advisory Upgrade

Enterprise Identity Readiness Review — $6,997

Add a 60–90 minute architecture workshop on one agent design, a comprehensive written gap assessment, and a prioritized remediation roadmap directly applied to your Microsoft Entra & infrastructure environment. Comparable management consulting engagements run $15,000–$30,000 for a single system.

Get the Readiness Review — $6,997 →
Instant checkout & scheduling link by email
Standalone Self-Paced Course

From Document to Deployment: Implementing Agentic AI with Governance and Observability

Looking only for the video instruction and worked exercises without the governance templates? Access self-paced modules aligned to the Governance Toolkit with a full course answer key. Launches September 18, 2026.

$797 course only
Enroll in Course →
Working sessions and architecture workshops (Tiers 4 & 5 Readiness Review) run 60–90 minutes each.
Limited to 4 total sessions per week to protect session quality — availability shown upon checkout.

How the Charter compares

Most alternatives solve one slice — identity, scoring, or discovery. The Charter ties identity, proportional authorization, evaluation evidence, verifiers, and lifecycle into one operational control framework compatible with NIST AI RMF 1.0. The Entra edition adds tenant-verifiable identity and Conditional Access evidence without replacing the evaluation or State/Trajectory layers. A free one-page AIRM ↔ AI RMF Crosswalk is available on request after purchase.

← Swipe to compare all frameworks →
Dimension AIRM Charter (v1.3.26.x) PDFShield Agent Passport Passport Alliance (APIS) Microsoft Entra Agent ID IETF AREG Spec
Primary focus Complete operational risk control framework with proportional safeguards Dynamic risk scoring & automated rate-limiting Open protocol for inter-org agent identity Enterprise IAM & lifecycle sponsorship Catalog discovery & schema resolution
Agent identity & passport Digital Passport tied to release version + Entra tenant-verifiable record Ed25519 verifiable URL & badge DID-based credential & mandate Entra ID non-human principal Lightweight metadata record
Runtime boundary controls Three-Layer Verifiers (Pre-Action, State, Trajectory) + external execution authority MCP firewall & HTTP rate limiting Mandate scope verification OAuth scopes & Access Packages None (out of scope for AREG)
MCP behavioral attestation Declared-vs-observed capability comparison; suspend + re-attest on divergence Basic tool monitoring Linked capability profiles Native MCP authentication References ACPM/MCP roadmaps
Performance & evaluation Golden Cases, pass@k / pass^k, tool & argument accuracy, trajectory quality, segmented analysis Operational health metrics Not covered Not covered Not covered
Task lineage & handoffs Multi-agent lineage + explicit authority transfer; zero-trust provenance Session event logging Delegation chain verification Agent-to-agent (A2A) identities Pointer resolution

Sources reflect each vendor's own published documentation as of this writing; comparison provided for orientation, not as a substitute for your own evaluation.

How delivery works

Checkout is instant for Tiers 1–5 self-serve. Fulfillment is handled promptly — files are dispatched by email shortly after payment.

1
Pay securely via Stripe Click the button for your chosen tier above. Stripe collects your email automatically at checkout.
2
You get a confirmation email Charter and toolkit files are sent to your checkout email within 2 hours (same day, business hours). Course access links for Tiers 3–5 and the standalone course go out on launch day (September 18, 2026).
3
Tier 4 & Tier 5 buyers get a scheduling link For your 60–90 min working session or architecture workshop, an automated calendar scheduling link goes out in the same email.
4
Readiness Review (Tier 5 upgrade) Your written gap assessment and prioritized remediation roadmap are delivered after the workshop, typically within 5 business days.
5
Questions or immediate support? Contact support@retrospxt.com anytime with your payment confirmation.

Frequently Asked Questions

Everything you need to know about licensing, implementation, compliance alignment, and delivery.

Is this legal advice?

No. This is an operational governance and risk engineering template. Have counsel and your compliance function review it before formal institutional adoption.

Can I use this for client work?

Yes — the license covers use inside your own organization or for a single named client engagement. It does not permit resale, white-label syndication, or public redistribution as your own downloadable commercial template.

What if I want to upgrade tiers later?

Email your original Stripe receipt to support@retrospxt.com and pay only the difference — you will receive the upgraded files and scheduling link right away.

Do you offer refunds?

Because this is an instantly delivered digital governance template containing proprietary worksheets, sales are final once files are dispatched. If files are missing, corrupted, or incompatible, our team resolves it immediately.

Why is Tier 4/5 session availability limited?

Working sessions and architecture workshops are delivered live, 1-on-1 by real senior risk architects, never outsourced or pre-recorded. Capping volume at 4 sessions per week protects deep technical preparation for each engagement.

What does "proportional" mean in the controls?

Five conditional safeguards (signed release package, multi-agent lineage, MCP behavioral attestation, conditional audit payload, automated access revocation) apply only when their documented risk or operating trigger is present. Everyday internal agents stay lightweight; higher-risk autonomous agents get the full rigorous evidence requirements.

Is this aligned with the NIST AI Risk Management Framework?

Yes — specifically designed for compatibility with NIST AI RMF 1.0 (Govern, Map, Measure, Manage). The Charter supplies concrete operational controls for production agents (identity, evaluation evidence, verifiers, lifecycle, proportional safeguards) that the base framework leaves to organizational implementation. A one-page AIRM ↔ AI RMF Crosswalk is available on request after purchase — reply to your confirmation email or contact support@retrospxt.com.