# Threat model summary (ASR/VRM pointer)

**Status:** index / mapping aid  
**Non-claim:** this summary is not a certification report and does not claim
SOC 2, ISO 27001, HIPAA, or PCI compliance.

## Canonical sources

| Document | Role |
|----------|------|
| [ADR 0008 — Safe agentic roles](../../adr/0008-safe-agentic-roles.md) | Agentic authority, SEC-AG-001…004, plane separation |
| [Threat model](../../security/threat-model.md) | Mission, assets, trust zones, SEC-106 handling |
| [Agentic authority matrix](../../security/agentic-authority-matrix.yaml) | Machine-readable role permissions |
| [Invariants](../../security/invariants.md) | Non-waivable SEC-* / SEC-AI-* / SEC-AG-* |
| [Requirements matrix](../../security/requirements-matrix.yaml) | Tests + phase gates |
| [DFD notes](dfd.md) | UDS broker, one-way telemetry, zero-egress sensor |

## Agentic deltas (Phase 0)

- Four specialized roles; no unbounded “agent framework”
- Signed scenario manifests only; investigator tools read-only
- Decoy-touch-only auto-containment; AGTI scrub before leave-tenant
- Sensor remains standalone (Ops/PLG never mandatory to bind ports)
