# Publication DSL Block Gallery
Section Opener
This opens a major section with visual weight.
Callout
Stat Grid
“The best reports are not longer. They are more structured.”
Checklist
Decision Box
Proceed after high-risk retrieval and tool-action controls are validated.
Finding Card
This block represents a single structured finding.
Finding Grid
Nested Finding One
Nested finding body.
Nested Finding Two
Nested finding body.
Risk Register
| Risk | Domain | Severity | Decision | Owner | Status |
|---|---|---|---|---|---|
Retrieval can expose content the user cannot access directly The retrieval layer uses tenant and source filters, but the evidence does not yet prove authorization survives indexing, chunking, semantic retrieval, reranking, and prompt assembly. | RAG and data access | critical | mitigate | Search Platform | open |
Agent tool authority can exceed the intended user action Tool access is not yet consistently separated into read, suggest, draft, queue, approve, and execute action classes. | Agentic workflow controls | critical | mitigate | AI Platform Engineering | open |
Human approval lacks enough context to be meaningful Approval screens do not always show evidence, target object, before/after diff, model rationale, blast radius, and rollback path. | Oversight | high | mitigate | Product Operations | open |
AI traces may store sensitive customer and operational data Prompts, retrieved snippets, model outputs, tool calls, and approval records may contain sensitive information but do not yet have AI-specific classification, retention, and access rules. | Logging and evidence | high | mitigate | Security Engineering | open |
Model provider boundary is not expressed clearly enough for buyers The provider contract may be acceptable, but the current buyer-facing language is too scattered to answer procurement questions quickly. | Third-party risk | high | mitigate | Vendor Management | open |
Prompt injection and retrieval abuse tests are not release gates AI abuse tests exist as a draft plan but are not enforced as release gates for prompt, retrieval, and tool changes. | Security testing | high | mitigate | Product Security | open |
AI incident response is not yet operationalized The incident response process does not yet define AI-specific triggers, evidence preservation, user notification triggers, or trace reconstruction steps. | Operations | medium | mitigate | Security Operations | planned |
Sales answers may drift from engineering reality AI security questionnaire answers are not yet controlled through a single evidence pack, creating risk of inconsistent customer-facing claims. | Enterprise review | medium | mitigate | Trust and Security | open |
Evidence Pack
Control Map
Permission Matrix
| Agent | Tool | Action | Scope | Approval | Risk | Owner |
|---|---|---|---|---|---|---|
| Support Copilot | Case Management API | read | tenant-scoped support cases visible to the authenticated user | no | medium | Support Platform |
| Support Copilot | Customer Messaging | draft | draft response text for the active case only | yes, before send | high | Product Operations |
| Support Copilot | Customer Messaging | execute | send customer-visible response | yes, human-only approval | critical | Product Operations |
| Support Copilot | Case Management API | queue | priority, category, routing tags, summary fields | yes for priority and routing changes | high | Support Platform |
| Support Copilot | CRM | read | account profile and entitlement fields needed for support context | no | medium | Revenue Operations |
| Support Copilot | CRM | execute | update account fields | yes, restricted to human operators | critical | Revenue Operations |
| Support Copilot | Billing System | read | plan, invoice status, entitlement flags | no for entitlement lookups | high | Finance Systems |
| Support Copilot | Billing System | execute | issue credits, refunds, plan changes | human-only approval and finance policy gate | critical | Finance Systems |
| Support Copilot | Notification Service | queue | internal team notification for escalation only | no for internal escalation templates | medium | Product Operations |
| Support Copilot | External Webhook | execute | third-party workflow triggers | yes, security-reviewed allowlist only | critical | Integration Platform |
Trust Boundary Map
Chart
publication-dsl
Example publication chart
| label | value |
|---|---|
| Planning | 12 |
| Partial | 27 |
| Implemented | 41 |
| Validated | 19 |
Table
| Control | Status | Owner |
|---|---|---|
| Retrieval authorization | Partial | AI Platform |
| Tool permissions | Missing | AI Platform |
| AI traces | Partial | Security Engineering |
Artifact
A linked artifact reference.
Recommendation Grid
- Scope the review around authority, data, and evidence.
- Test the paths that cross trust boundaries.
- Retest after the control changes.
Failure Mode List
- Retrieved content can override context handling.
- Tool output can be mistaken for policy.
- Evidence can be lost before retest.
Question Set
- Which control runs outside the model?
- What evidence proves the control ran?
- Who owns retest after remediation?
Test Plan
- Attempt unauthorized retrieval across tenant boundaries.
- Replay tool-call requests with low-privilege users.
- Force malformed output through the downstream parser.
Control Evidence Map
- Retrieval authorization: access-boundary test results.
- Tool authorization: permission matrix and trace sample.
- Output validation: schema-failure log and release gate.
Artifact List
- AI system inventory.
- Trust-boundary map.
- Remediation backlog.
Domain Playbook
Use domain playbooks to collect the inspection, testing, controls, evidence, and output shape for applied work.
Definition List
- Context authority
- The level of influence a context source is allowed to have over model behavior.
- Evidence artifact
- A durable record that shows a control, check, approval, or retest occurred.
Related Paths
| Type | Paths |
|---|---|
| Workbench | Threat Canvas, Runtime Proxy |
| Services | AI Product Security Assessment |
Comparison Matrix
| Field Guide | Handbook |
|---|---|
| Applied checks and evidence. | Conceptual background and vocabulary. |
Audience Action Grid
| Audience | Action |
|---|---|
| CISO | Require evidence artifacts for AI risk claims. |
| Product security | Turn findings into backlog and retest criteria. |
Claim Ledger
Use claim cards when report findings need public-safety status and confidence.
Claim Card
- Claim: Public hiring signals can support directional market claims when the caveat travels with the finding.