Connect an agent and run one governed action to build the first runtime exposure map.
No AI runtime exposure surface has been discovered yet.
No records in this section.
| Session | Agent | Runtime lane | Status | Signature | Posture |
|---|---|---|---|---|---|
| 00a631a5-ae38-47f0-8849-0b96f24ac8eb | codex-cli-prod-smoke | Claude Code Hooks | active | workspace_key_optional | enforce |
| d54e5524-7d98-4bf2-b483-7e01f020b629 | codex-cli-prod-smoke | Claude Code Hooks | active | workspace_key_optional | enforce |
| 671ab267-4845-47f9-b017-7d17e442c81a | codex-cli-prod-smoke | Claude Code Hooks | active | workspace_key_optional | enforce |
| f7a64600-7032-42ce-bcaa-c1e8a2978a4c | claude-hooks-demo | Claude Code Hooks | active | workspace_key_optional | enforce |
Runtime Coverage separates Reference adapters, Managed OSuite adapters, and Enterprise custom adapters so customers can see which action lanes are understood, supported, and production-governed. Current top active tier: Managed OSuite adapters.
| Metric | Value |
|---|---|
| Reference lanes | 0 |
| Managed lanes | 8 |
| Enterprise custom lanes | 11 |
| Connected coverage | 1/19 |
| Runtime sessions | 4 |
| Covered agents | 0 |
| Tier | Count | User path | Studio behavior |
|---|---|---|---|
| Reference adapters | 0 | Install osuite-cava-core, define or reuse parser packs, run local canonicalization and receipt checks. | Shown as reference coverage only; high-impact production lanes should not be marked fully governed from this tier alone. |
| Managed OSuite adapters | 8 | Use the one-line installer or connector flow; OSuite maintains parser updates and evidence quality. | Appears as Runtime Coverage with parser posture, evidence gaps, unsupported actions, and remediation paths. |
| Enterprise custom adapters | 11 | Map sample events into CAVA fields, validate coverage, version the adapter, and deploy through OSuite. | Appears as customer runtime coverage with field mapping, versioning, approval routing, and proof export. |
| Runtime lane | Tier | Parser posture | Status | Disclosure |
|---|---|---|---|---|
| Claude Connectors Directory | Managed OSuite adapters | managed | ready | Managed pack: OSuite maintains parser updates, coverage diagnostics, proof export, and policy routing. |
| ChatGPT Apps Connector | Managed OSuite adapters | managed | ready | Managed pack: OSuite maintains parser updates, coverage diagnostics, proof export, and policy routing. |
| Codex Remote Connector | Managed OSuite adapters | managed | ready | Managed pack: OSuite maintains parser updates, coverage diagnostics, proof export, and policy routing. |
| Claude Desktop Extension | Managed OSuite adapters | managed | ready | Managed pack: OSuite maintains parser updates, coverage diagnostics, proof export, and policy routing. |
| Claude Code Hooks | Managed OSuite adapters | managed | connected | Managed pack: OSuite maintains parser updates, coverage diagnostics, proof export, and policy routing. |
| Codex Plugin | Managed OSuite adapters | managed | ready | Managed pack: OSuite maintains parser updates, coverage diagnostics, proof export, and policy routing. |
| Codex Hooks | Managed OSuite adapters | managed | ready | Managed pack: OSuite maintains parser updates, coverage diagnostics, proof export, and policy routing. |
| Azure Foundry | Enterprise custom adapters | enterprise_custom | ready | Enterprise custom pack: OSuite maps private runtime fields, customer schemas, and sensitive business systems. |
| Gemini Enterprise Agent Platform | Enterprise custom adapters | enterprise_custom | planned | Enterprise custom pack: OSuite maps private runtime fields, customer schemas, and sensitive business systems. |
| Bedrock AgentCore | Enterprise custom adapters | enterprise_custom | planned | Enterprise custom pack: OSuite maps private runtime fields, customer schemas, and sensitive business systems. |
| OpenAI Agents SDK | Managed OSuite adapters | managed | planned | Managed pack: OSuite maintains parser updates, coverage diagnostics, proof export, and policy routing. |
| OpenAI API | Enterprise custom adapters | enterprise_custom | planned | Enterprise custom pack: OSuite maps private runtime fields, customer schemas, and sensitive business systems. |
What survives if AI budgets, providers, or internal sponsors change: the controlled runtime inventory, action authority, approval leases, exposure history, and evidence record.
| Dimension | Score | Status | Why it matters |
|---|---|---|---|
| Runtime control assets | 21/100 | exposed | If the organization cannot see the runtime estate, AI budget cuts or provider swaps turn into another discovery project. |
| Bounded authority | 0/100 | not_started | Trust is easier to preserve after an incident when approvals are scoped, time-bound, and replay-resistant. |
| Evidence durability | 0/100 | not_started | A pilot becomes defensible only when the team can prove what happened without reconstructing it manually. |
| Runtime portability | 92/100 | strong | Portability keeps OSuite from depending on a single agent vendor cycle. |
| Exposure resilience | 0/100 | not_started | When AI hype corrects, teams keep the systems that can show controlled blast radius and remediation progress. |
| Policy-to-runtime binding | 0/100 | not_started | Policy language becomes capital only when it changes runtime behavior and leaves evidence. |
| Survival test | Posture | Explanation |
|---|---|---|
| Budget correction | needs proof | Reduce proof gaps and observe-only lanes before using OSuite as a budget-defense artifact. |
| Provider churn | portable | The governance object can survive a runtime or model-provider change. |
| Incident review | fragile | Close evidence durability and approval binding before relying on post-incident reconstruction. |
| Procurement diligence | needs hardening | Map policy profile, runtime decisions, and proof closure into one exportable packet. |
No exposure backlog item is currently active.
No records in this section.
3 dependency lane(s) are visible across providers, runtimes, tools, systems, approvals, and evidence.
| Lane | Count | Risk | Examples |
|---|---|---|---|
| Model and agent providers | 5 | distributed | OpenAI / Codex, Anthropic / Claude, Microsoft / Azure, LangGraph, MCP tool servers |
| Runtime adapters | 19 | controlled | Claude Connectors Directory, ChatGPT Apps Connector, Codex Remote Connector, Claude Desktop Extension, Claude Code Hooks, Codex Plugin |
| MCP and tool servers | 3 | review | Claude Connectors Directory, ChatGPT Apps Connector, Codex Remote Connector |
| External and business systems | 0 | not_started | n/a |
| Approval and authority lanes | 0 | not_started | PCAA, policy profile, Action Gate Lease |
| Evidence and receipts | 0 | not_started | CAVA receipt, PCAA proof bundle, decision record |
No governed action has reached the runtime firewall yet.
| Lane | Count | Meaning |
|---|---|---|
| Allow with proof | 0 | Action may continue when CAVA meaning, policy profile, and proof closure agree. |
| Ask for approval | 0 | Execution waits for a PCAA-recognized authority instead of trusting the agent runtime alone. |
| Block or fail closed | 0 | High-risk allow paths are treated as firewall defects until a bounded approval exists. |
| Observe only | 0 | OSuite can record evidence but cannot yet enforce before execution on this lane. |
| Expired or unbound | 0 | Unsigned actions or proof gaps cannot be reused as durable approvals. |
No external verifier checkpoint has been attached to recent runtime actions yet.
No records in this section.
Run at least one governed action before remediation can be recommended.
No records in this section.