01 / Source and scope
Who acts, and what changes?
Principal and authority origin
Security team assessing an AI workflow. Organization threat-modeling process.
Consequential action
Test an attacker path to a protected tool.
02 / Action-time control
Make the requested effect testable.
ATLAS is a knowledge base of adversary tactics and techniques, not a compliance requirement. Map relevant techniques to the specific lower-trust input, agent privilege and enforcement boundary.
OriginOrganization threat-modeling process
RequestTest an attacker path to a protected tool
DecisionEvaluate and enforce before effect
03 / Evidence and responsibility
Permission, execution, and outcome are separate.
Threat scenario, negative test, detection and observed result.
ProofGrid addresses action authorization where integrated; detection and broader AI security remain operator duties.
Primary source