Governance maturity model

How governed is governed enough?

Agent governance isn't binary. It's a ladder — from having a record of what an agent did, to proving that record to someone who has no reason to trust you. Four stages, each satisfied by real, live, signed EcoCloud primitives.

The honest part

This page organizes 60+ live governance endpoints into four stages of adoption. Stages 1–2 are scored automatically and continuously by the signed Agent Readiness Index — try it below. Stages 3–4 aren't in that automated score yet — every primitive is real, live, and linked, but rolling them into one continuous number is on the roadmap, not built. We're telling you that up front rather than implying a score we don't compute.

The four stages

Each stage is a genuine capability tier, not a marketing label — you can't skip to Stage 3 without Stage 1's ledger existing underneath it.

1
RecordedScored below

Every agent action produces a signed, hash-chained receipt. Not a log line someone could quietly edit — a cryptographic record.

Proves to an auditor: "this event happened, in this order, and hasn't been altered since."

3
ProvableSelf-assessed

Beyond "we have a record" — anyone can verify integrity offline, with zero trust in EcoCloud's servers or database, and without seeing data they're not entitled to.

Proves to an auditor: "verify this yourself against our public key — you don't have to take our word, or even query our systems."

4
Continuous & cross-orgSelf-assessed

Assurance doesn't stop at deployment, and it doesn't stop at your org chart — anomalies are watched continuously, and policy composes cleanly across organizational boundaries.

Proves to an auditor: "this isn't a point-in-time attestation — it's watched, and it holds up when a second party's policy is in the mix."

Score a real workspace

The Agent Readiness Index measures Stage 1–2 automatically, across five dimensions, from your actual configuration — not a questionnaire. Every score cites the real state it was computed from, and the whole attestation is signed so it can't be quietly inflated.

Agent Readiness Index

This runs the live public demo endpoint. Present your own workspace credential to /api/v1/agent/readiness to score your real posture instead.

Not run yet — click "Run the live demo" for a real signed attestation.
What's scored

The five dimensions map exactly onto Stage 1–2: Auditability is Stage 1 (Recorded). Policy, Identity, Reversibility & Injection Resilience are Stage 2 (Enforced).

What isn't, yet

Stage 3–4 primitives above are real and live, but folding "do you use append-only proofs / cross-org composition" into one continuous number is roadmap, not shipped. Use the chips above to self-assess today.

Start at whatever stage you're actually at

No one arrives at Stage 4. Most teams start at Stage 1 — a signed record of what already happens — and enforce as they earn trust in the gate.

5-minute startSee every kernel