{
  "version": "1.0.0",
  "publishedOn": "2026-08-21",
  "lastVerifiedOn": "2026-08-21",
  "purpose": "Produce a deterministic, evidence-linked control plan from declared AI-agent capabilities and boundaries.",
  "statuses": ["CONTROL_PLAN_READY", "INSUFFICIENT_SCOPE_EVIDENCE"],
  "procedure": [
    "Require one yes, no or unknown answer for every criterion; never infer an omitted answer as no.",
    "Evaluate every mapping relation whose predicates all exactly match the supplied answers.",
    "Use the union of all matching mappings and retain every activating mapping ID when more than one relation selects a control.",
    "Resolve requirement level to required when any activating mapping is required, otherwise recommended.",
    "Order selected controls by first matching mapping priority, then layer order and control order.",
    "Return INSUFFICIENT_SCOPE_EVIDENCE and list unresolved inputs when any core answer is unknown; otherwise return CONTROL_PLAN_READY.",
    "Export the frozen result record to JSON, CSV or Markdown without re-running or reinterpreting the mapping."
  ],
  "statusesExplained": {
    "CONTROL_PLAN_READY": "All declared core inputs are known and the deterministic control plan is ready for owner assignment and system-specific review.",
    "INSUFFICIENT_SCOPE_EVIDENCE": "At least one core capability or boundary remains unknown; the displayed plan is provisional and can omit controls whose conditions cannot yet match."
  },
  "boundaries": [
    "Decision support, not certification, compliance, a penetration test, legal advice or proof that a system is secure.",
    "The mapper does not produce a security, confidence or percentage score.",
    "A suggested owner role is not a real assignment; an accountable person must accept the work in the delivery system.",
    "A control description is not implementation evidence. Release gates require artifacts and verification from the deployed environment.",
    "Sources define bounded claims and design inputs; their inclusion does not imply OWASP, NIST, MCP or SLSA endorsement.",
    "Threat modeling, regulatory interpretation, data classification and impact thresholds remain organization- and system-specific."
  ],
  "registryVersions": {
    "criteria": "1.0.0", "layers": "1.0.0", "threats": "1.0.0", "controls": "1.0.0", "mappings": "1.0.0", "profiles": "1.0.0", "incidents": "1.0.0", "claims": "1.0.0", "sources": "1.0.0"
  },
  "exportSchemaVersion": "1.0.0",
  "maintenance": {
    "owner": "Pharos Production editorial engineering",
    "reviewTrigger": "Review when a cited source changes status, a control's evidence contract changes or a new agent capability creates a distinct mapping branch.",
    "corrections": "Report a factual or mapping correction through the contact path on the published methodology page; accepted changes receive a new registry version and date."
  }
}
