NEW

Start with the pressure: sales, launch, abuse, agents, data, or guardrails

example

Publication DSL Block Gallery

A single example file demonstrating every official v1 block.

Public sample
Client deliverable
public-sample
Reviewed 2026-05-25

Synthetic sample AI risk register for a customer-facing AI copilot using retrieval, model routing, tool access, approval workflows, and AI trace logging.

System
Northstar Support Cloud / Customer Support Copilot
Environment
Production pilot
Primary owner
Product Security

# Publication DSL Block Gallery

Official Block

Section Opener

This opens a major section with visual weight.

Note

Callout

Use callouts for short, important interpretive notes.
Metrics

Stat Grid

Risks reviewed
12
Findings validated
7
Evidence gaps
5
Blockers
3
Quote
The best reports are not longer. They are more structured.
Sample
Checklist

Checklist

Trust boundary map exists
Permission matrix exists
Risk register has owners
Evidence pack has buyer answers
Decision · conditional

Decision Box

Proceed after high-risk retrieval and tool-action controls are validated.

Finding · high

Finding Card

Evidence: sample-evidence

This block represents a single structured finding.

Findings

Finding Grid

Finding · medium

Nested Finding One

Evidence: sample-evidence-one

Nested finding body.

Finding · high

Nested Finding Two

Evidence: sample-evidence-two

Nested finding body.

Risk register

Risk Register

Synthetic sample AI risk register for a customer-facing AI copilot using retrieval, model routing, tool access, approval workflows, and AI trace logging.
Risks
8
Open
7
Critical
2
Decisions
3
Roadmap
5
Controls
0
RiskDomainSeverityDecisionOwnerStatus
Retrieval can expose content the user cannot access directly
The retrieval layer uses tenant and source filters, but the evidence does not yet prove authorization survives indexing, chunking, semantic retrieval, reranking, and prompt assembly.
RAG and data accesscriticalmitigateSearch Platformopen
Agent tool authority can exceed the intended user action
Tool access is not yet consistently separated into read, suggest, draft, queue, approve, and execute action classes.
Agentic workflow controlscriticalmitigateAI Platform Engineeringopen
Human approval lacks enough context to be meaningful
Approval screens do not always show evidence, target object, before/after diff, model rationale, blast radius, and rollback path.
OversighthighmitigateProduct Operationsopen
AI traces may store sensitive customer and operational data
Prompts, retrieved snippets, model outputs, tool calls, and approval records may contain sensitive information but do not yet have AI-specific classification, retention, and access rules.
Logging and evidencehighmitigateSecurity Engineeringopen
Model provider boundary is not expressed clearly enough for buyers
The provider contract may be acceptable, but the current buyer-facing language is too scattered to answer procurement questions quickly.
Third-party riskhighmitigateVendor Managementopen
Prompt injection and retrieval abuse tests are not release gates
AI abuse tests exist as a draft plan but are not enforced as release gates for prompt, retrieval, and tool changes.
Security testinghighmitigateProduct Securityopen
AI incident response is not yet operationalized
The incident response process does not yet define AI-specific triggers, evidence preservation, user notification triggers, or trace reconstruction steps.
OperationsmediummitigateSecurity Operationsplanned
Sales answers may drift from engineering reality
AI security questionnaire answers are not yet controlled through a single evidence pack, creating risk of inconsistent customer-facing claims.
Enterprise reviewmediummitigateTrust and Securityopen
Prove retrieval authorization
P1
Search Platform · 2026-06-15
Enforce agent action classes
P2
AI Platform Engineering · 2026-06-20
Upgrade approval context
P3
Product Operations · 2026-06-25
Classify AI traces
P4
Security Engineering · 2026-06-30
Evidence pack

Evidence Pack

Synthetic sample evidence pack for answering enterprise AI security review, procurement, legal, and trust-center questions.
implemented
12
partial
8
missing
4
planned
5
retrieval authorization evidenceagent permission matrix completionAI trace retention and access policybuyer-ready model provider boundary statement
AI system inventory
implemented
Product Security"What AI features are in scope for this product?"
Model provider boundary statement
partial
Vendor Management"Is customer data used to train third-party models?"
Gateway-only model access
implemented
AI Platform Engineering"Can product services call the model provider directly?"
Authorization-preserving retrieval
partial
Search Platform"Can the AI system retrieve data the user cannot access directly?"
Prompt injection and retrieval abuse testing
partial
Product Security"Do you test the AI feature against prompt injection and context manipulation?"
Agent tool permission policy
partial
AI Platform Engineering"What actions can the AI system take?"
Human approval for sensitive actions
partial
Product Operations"Which AI actions require human review?"
AI trace logging
implemented
Security Engineering"Can you reconstruct AI decisions and tool actions?"
Buyer question
draft
Is customer data used to train foundation models?
Vendor Management
Buyer question
partial
Can a user receive information through AI that they cannot access directly?
Search Platform
Buyer question
partial
Can the AI system take actions in customer environments?
AI Platform Engineering
Buyer question
implemented
Can AI interactions be audited?
Security Engineering
inventory
AI System Inventory Record
available · Product Security
architecture
Model Routing Architecture
available · AI Platform Engineering
test-evidence
RAG Authorization Test Plan
needs-validation · Search Platform
matrix
Agent Tool Permission Matrix
draft · AI Platform Engineering
logging-evidence
AI Trace Schema
available · Security Engineering
Control map

Control Map

Synthetic sample evidence pack for answering enterprise AI security review, procurement, legal, and trust-center questions.
AI system inventory
implemented
"What AI features are in scope for this product?"
Model provider boundary statement
partial
"Is customer data used to train third-party models?"
Gateway-only model access
implemented
"Can product services call the model provider directly?"
Authorization-preserving retrieval
partial
"Can the AI system retrieve data the user cannot access directly?"
Prompt injection and retrieval abuse testing
partial
"Do you test the AI feature against prompt injection and context manipulation?"
Agent tool permission policy
partial
"What actions can the AI system take?"
Human approval for sensitive actions
partial
"Which AI actions require human review?"
AI trace logging
implemented
"Can you reconstruct AI decisions and tool actions?"
Agent permission matrix

Permission Matrix

Synthetic sample permission matrix for an AI copilot with retrieval, case-management, customer messaging, CRM, billing, and notification tool access.
Principle
Separate reading, suggesting, drafting, queuing, approving, and executing. Do not treat all tool access as one permission.
Default posture
deny-by-default
Approval model
Human approval required for customer-visible, billing-impacting, destructive, privileged, or cross-tenant actions.
ReadSuggestDraftQueueApproveExecute
AgentToolActionScopeApprovalRiskOwner
Support CopilotCase Management APIreadtenant-scoped support cases visible to the authenticated usernomediumSupport Platform
Support CopilotCustomer Messagingdraftdraft response text for the active case onlyyes, before sendhighProduct Operations
Support CopilotCustomer Messagingexecutesend customer-visible responseyes, human-only approvalcriticalProduct Operations
Support CopilotCase Management APIqueuepriority, category, routing tags, summary fieldsyes for priority and routing changeshighSupport Platform
Support CopilotCRMreadaccount profile and entitlement fields needed for support contextnomediumRevenue Operations
Support CopilotCRMexecuteupdate account fieldsyes, restricted to human operatorscriticalRevenue Operations
Support CopilotBilling Systemreadplan, invoice status, entitlement flagsno for entitlement lookupshighFinance Systems
Support CopilotBilling Systemexecuteissue credits, refunds, plan changeshuman-only approval and finance policy gatecriticalFinance Systems
Support CopilotNotification Servicequeueinternal team notification for escalation onlyno for internal escalation templatesmediumProduct Operations
Support CopilotExternal Webhookexecutethird-party workflow triggersyes, security-reviewed allowlist onlycriticalIntegration Platform
Approval requirement
Approval
Approval requirement
Approval
Trust boundary map

Trust Boundary Map

Synthetic sample trust boundary data for a customer-facing AI copilot using retrieval, model-provider routing, workflow tools, approval screens, and AI trace logging.
Nodes
8
Boundaries
5
Flows
7
Controls
5
actor
Authenticated User
medium
application
SaaS Web Application
medium
control-point
AI Gateway
critical
data-store
Retrieval Index
critical
third-party-service
Model Provider
high
tool-surface
Workflow Tools
critical
human-review
Approval Console
high
observability-store
AI Trace Store
high
Prompt submitted
Session auth, tenant scope, request validation
medium
Prompt envelope created
Gateway-only model access, request classification, tenant binding
high
Retrieval query
Authorization-preserving retrieval filters, source ACL tests
critical
Model call
Data minimization, provider boundary, training exclusion statement
high
Tool plan prepared
Permission matrix, action class policy, tool allowlist
critical
Approval request
Human approval with evidence bundle and reviewer identity
high
Boundary
Tenant Boundary
Separates one customer tenant's data, retrieval results, logs, and tool actions from another tenant.
Boundary
Retrieval Authorization Boundary
Ensures source-system authorization survives indexing, chunking, retrieval, reranking, and prompt assembly.
Boundary
Model Provider Boundary
Controls what data leaves the product boundary and how model provider commitments are represented to buyers.
Boundary
Tool Authority Boundary
Separates text generation from state-changing tool authority.
Chart

Chart

Illustrative chart payload for validating chart rendering in publication blocks.

publication-dsl

Example publication chart

export.v_chart_example
Source: export.v_chart_example
Illustrative chart data for DSL examples only.
Source data
labelvalue
Planning12
Partial27
Implemented41
Validated19

Table

ControlStatusOwner
Retrieval authorizationPartialAI Platform
Tool permissionsMissingAI Platform
AI tracesPartialSecurity Engineering
Artifact

Artifact

A linked artifact reference.

/deliverables/ai-trust-boundary-map
Recommendation Grid

Recommendation Grid

  • Scope the review around authority, data, and evidence.
  • Test the paths that cross trust boundaries.
  • Retest after the control changes.
Failure Mode List

Failure Mode List

  • Retrieved content can override context handling.
  • Tool output can be mistaken for policy.
  • Evidence can be lost before retest.
Question Set

Question Set

  • Which control runs outside the model?
  • What evidence proves the control ran?
  • Who owns retest after remediation?
Test Plan

Test Plan

  • Attempt unauthorized retrieval across tenant boundaries.
  • Replay tool-call requests with low-privilege users.
  • Force malformed output through the downstream parser.
Control Evidence Map

Control Evidence Map

  • Retrieval authorization: access-boundary test results.
  • Tool authorization: permission matrix and trace sample.
  • Output validation: schema-failure log and release gate.
Artifact List

Artifact List

  • AI system inventory.
  • Trust-boundary map.
  • Remediation backlog.

Domain Playbook

Use domain playbooks to collect the inspection, testing, controls, evidence, and output shape for applied work.

Definition List

Definition List

Context authority
The level of influence a context source is allowed to have over model behavior.
Evidence artifact
A durable record that shows a control, check, approval, or retest occurred.
Related Paths

Related Paths

TypePaths
WorkbenchThreat Canvas, Runtime Proxy
ServicesAI Product Security Assessment
Comparison Matrix

Comparison Matrix

Field GuideHandbook
Applied checks and evidence.Conceptual background and vocabulary.
Audience Action Grid

Audience Action Grid

AudienceAction
CISORequire evidence artifacts for AI risk claims.
Product securityTurn findings into backlog and retest criteria.

Claim Ledger

Use claim cards when report findings need public-safety status and confidence.

Claim Card

Claim Card

  • Claim: Public hiring signals can support directional market claims when the caveat travels with the finding.
Note

Caveat Box

Based on analyzed job-description signals, not proof of any individual company's internal security maturity.