Agents / mcit

Assurance Agent

Agent runGovernanceGovernment-RestrictedLimited riskGov Reuse61 runs/30d

Runs the automated check battery on every submitted asset and composed workflow: quality against the declared benchmarks, security and supply-chain integrity of the artefact, bias and Responsible AI screening, and malicious-content scanning. Assembles the check report and flags anomalies against comparable assets.

Governs the marketplace

Agent runAll governance agents →

An agent executes the process end to end and logs what it did. No human is in the path, because there is no discretion to exercise and no consequence to carry.

Acts for
Governance & Certification
Action class
read-only
Decisions / 30d
61
Safe-state returns / 30d
1

Processes covered

  • Automated assurance: quality, security, bias, malicious content, supply chain
  • Conformance testing of composed workflows

Stages:publishcompose

Memory

Retains check reports for the life of the asset version; purged on retirement.

Safe state

Marks the check as 'not run' and blocks routing to sign-off when any scanner is unavailable, rather than passing the stage.

Reviewer time per case: 0 min with this agent, 75 without.

Tools

  • Artefact and image scanner
  • SBOM and signature verifier
  • Benchmark harness
  • Bias and RAI screening suite
  • Check-report writer

Data access scope

  • Read-only: artefacts, SBOMs, evaluation datasets referenced in the manifest
  • Read-only: check reports of comparable certified assets
  • Write: check report attached to the case only

Guardrails

  • A failed security or malicious-content check blocks routing to sign-off automatically
  • Never modifies an artefact; findings are reported, not fixed
  • Anomaly flags always show the comparable set they were judged against

Human-in-the-loop

  • Governance officer reads the check report before any sign-off

Orchestration

Trigger / IntakeLLM Orchestratorfanar-gov-7b-instructArtefact and image scannerSBOM and signature verifierBenchmark harnessBias and RAI screening suiteHumansign-off

Every tool call is scoped by the declared data access above; the orchestrator cannot reach systems outside it. Owning entity: MCIT.

Live demo run

Watch the agent execute a real scenario step by step, every tool call, validation, and human checkpoint is traced and auditable. Typical run: ~6.9s.

Owning entity

mcMCIT

Updated 2026-07-30. Run traces retained 24 months for audit under the platform governance policy.

Community · 0 threads

Questions, findings and requests from the entities that use this asset. Owners reply here; threads with upvotes surface to the owning entity's inbox.

No threads yet. Be the first entity to ask, or to share what you found.