Skip to content
PROOF // Aerospace & Defense Manufacturing ITAR-adjacent aerospace & defense contract manufacturer · on-prem and air-gapped data requirements · multi-program supplier base
← All Proof

CHAPTER 03 · BUILD

Agents Shipped Inside the Existing Stack

The first system, and the two right behind it, run inside the program office's existing systems — no new platform, no data leaving the approved boundary. Each one is real and running.


THE AGENTS · 3 FOR THIS WORKFLOW

Access adjudication alone runs a four-agent review before a human makes the final call — the count maps to how many distinct checks the process demands. Each agent is its own identity with its own scoped tools and permissions.

01

Supplier Risk Monitoring

Status Runs continuously
Impact Manual news/financial scan → automated alert
Team Automated, 1 human review
02

Software Supply-Chain Risk (SBOM)

Status Repo scanned in minutes
Impact Manual audit → automated exec brief
Team Automated, 1 human review
03

Facility Access Adjudication

Status Every request reviewed
Impact Manual approval chain → automated, audited ruling
Team 4-agent review, 1 human final sign-off

IT DOESN'T STOP AT A REPORT

The Agent Takes the Action

A brief is one output. Most of what these agents do is take the next action inside the approved boundary — and on anything sensitive, a human makes the final call before it happens.

agent inbox — this morning
DATA VIEW

Open the risk ticket

A scored supplier or software finding is filed in the tracker with its evidence attached.

Ran automatically

Draft the supplier notice

Prepares the outreach for the program buyer to review and send — nothing leaves the boundary on its own.

Revoke facility access

On a confirmed violation the entitlement is cut — after a human's final sign-off, never before.

File the compliance record

Writes the audited entry, with citations, that the program office has to keep anyway.

Ran automatically

PRODUCTION TRACE

Supplier Risk Monitoring

Every step below runs against the plant's real data — the exact sequence, in order.

live.internal — this morning
DATA VIEW

30

Suppliers monitored

2

Risk alerts today

4

SBOM scans completed

6

Access requests reviewed

2 items need your judgment

S-118 Tier-2 supplier risk score crossed threshold on titanium forgings
High
S-119 SBOM scan flagged a KEV-listed vulnerability in the avionics build
Medium

Ingest signals

Automated

Public financial, regulatory, and disruption signals pulled continuously across every supplier — the same public data feeds a risk analyst would check by hand.

Score risk

Automated

Each of the 30 monitored suppliers gets a risk signal scored against the parts and programs it feeds.

Propose response

Automated

When a supplier crosses a risk threshold, the system proposes a specific response — alternate sourcing, expedite, or escalate.

Program manager review

Reviewer input

Nothing executes without sign-off. The proposal is reviewed against program impact before anything moves.

Execute & log

Automated

Approved actions execute and the outcome logs back in, sharpening the next risk score.

REAL OUTPUT · SOFTWARE SUPPLY-CHAIN RISK (SBOM)

One Example, Fully Processed

When a job calls for a written artifact, this is what the system produces — everything it finds, structured for the action it triggers next.

Repo Scan — Avionics Control Module

GitHub repository · Scanned in 47s · Cross-referenced against NVD, CISA KEV, EPSS, OSV

DATA VIEW

Software Components Flagged

Component Version Known Vulnerability Severity Scan Confidence
libavcodec 4.4.1 CVE match, CISA KEV-listed Critical 97%
openssl 1.1.1t CVE match, one version behind patch High 93%
log4j-core 2.17.0 No known CVE Low 95%
curl 7.81.0 CVE match, low exploit prediction Medium 88%
internal-telemetry-lib 0.9.3 Unscanned — private package Unknown 41%

Executive Risk Brief

This repository scan found five components in the build, one with a KEV-listed critical vulnerability that needs a decision before this ships, and one private package that couldn't be verified against public vulnerability databases. Everything else is inside acceptable risk tolerance for this program.

Before This Ships

libavcodec 4.4.1 has a CISA KEV-listed critical vulnerability — this is being actively exploited in the wild. Patch or accept the risk in writing before ship.
internal-telemetry-lib couldn't be checked against public vulnerability databases — it's a private package. Needs a manual security review, not an automated pass.
openssl is one minor version behind the patched release — low urgency, but worth bundling into the next scheduled update.

LIVE — EVERY DECISION AUDITED IN PRODUCTION

Facility Access Adjudication — What's Next

Physical access requests to controlled areas used to go through a checklist approval — fast, but not built to catch the request that looks fine on paper and isn't.

A 4-agent review — intake, access architect, adversarial red-teamer, final approver — checks every request against the facility's SOP corpus. The red-teamer's whole job is to find reasons the request shouldn't be approved before the approver ever sees it.

A real request, from intake to final ruling

A contractor requests badge access to a controlled fabrication bay. Four ranked findings shaped the outcome:

DATA VIEW
1 Adversarial check: contractor's clearance doesn't cover this specific bay Blocks approval until resolved
2 SOP citation: escort-required zone after hours Approved with escort condition attached
3 Facility catalog: bay shares egress with a restricted area Flagged for security review, not blocking
4 Historical pattern: similar requests approved 41 times prior year Used as context only, not a deciding factor

WHAT CHANGED

Time returned

~85% of manual supplier-risk research time

Program managers got the time back for supplier relationships and technical reviews, not spreadsheet monitoring.

Operating complexity

A word-of-mouth risk signal became a same-day, cited alert

Where this stands

First system live and cleared for use in 30 days

CHAPTER 03 OF 5

UP NEXT · TEAM VIEW

See what actually changed for the people doing the work, role by role.

Continue to Team View