Steward Agent blast-radius intelligence
Identitylegacy_bot
Owner
Unassigned — investigate
Review state
pending
Effective accessDirect + delegated
  • read_archive direct grant
Granted vs. NeededLLM-assisted signal

Declared need

  • retrieves documents from retired product archive

Concrete grant gap

No tool-ID-level gap was asserted. Treat capability inferences as review context, not a fact.

Cited findings

Why this card needs attention

high risk 30/100 Orphaned agent Deterministic check

Ownerless agent has no accountable reviewer

The LegacyBot agent lacks an assigned owner, so no individual is accountable for its access rights or activity. This creates a compliance gap (missing reviewer for access certification) and increases the risk of undetected misuse or unauthorized data exposure through the agent's operations.

Recommended actionAssign a named owner in the fleet inventory, update the agent's governance record, and include the agent in the regular access certification process to ensure accountability.
Evidence agentlegacy_bot
Control frameworks context, not certification NIST SP 800-53 Rev. 5 · AC-2 Account Management SOC 2 Trust Services Criteria (2017) · CC6.2 User registration and authorization ISO/IEC 27001:2022 · A.5.16 Identity management SOX ITGC · Access accountability Accountable ownership of access
Accountability — named owner required for agent access certification