Assurance Case

Can I actually sign off this stack as production-ready?

Every other AgentSmack meta-layer answers a different question — the kill-chain answers how exploitable, the risk register fix first, blast-radius how bad, attacker-economics adversary ROI. None answer the literal CISO sign-off question: argue, with explicit evidence and explicit open objections, that this stack is production-ready. This is that artifact — a GSN-style assurance case: the top claim decomposes into one sub-claim per production dimension, each Supported by covered surfaces or marked an open Defeater. It is non-launderable: a single blocking issue or blocked dimension refutes the top claim regardless of a high headline score, and a thin, mostly-untested run degrades to argument unsupported — never a green light. It adds no new surface and no new dimension — a pure argument OVER the scorecard and findings you already have. Fill a sample to watch the argument compose with no live infra.

Have the surface signals but want the headline number first? Compose the production scorecard →

Assurance case — the production sign-off argument

No assurance input yet — compose a scorecard and its findings to build the production-readiness argument. An untested stack is reported argument unsupported, never a green light.

Related read-only meta-lenses over the same run: Production Scorecard · Risk Register · Attack-Path / Kill-Chain.