CHAPTER 03 · BUILD
Agents Shipped Inside the Existing Stack
The first system, and the two right behind it, run inside the program office's existing systems — no new platform, no data leaving the approved boundary. Each one is real and running.
THE AGENTS · 3 FOR THIS WORKFLOW
Access adjudication alone runs a four-agent review before a human makes the final call — the count maps to how many distinct checks the process demands. Each agent is its own identity with its own scoped tools and permissions.
Supplier Risk Monitoring
Software Supply-Chain Risk (SBOM)
Facility Access Adjudication
IT DOESN'T STOP AT A REPORT
The Agent Takes the Action
A brief is one output. Most of what these agents do is take the next action inside the approved boundary — and on anything sensitive, a human makes the final call before it happens.
Open the risk ticket
A scored supplier or software finding is filed in the tracker with its evidence attached.
Draft the supplier notice
Prepares the outreach for the program buyer to review and send — nothing leaves the boundary on its own.
Revoke facility access
On a confirmed violation the entitlement is cut — after a human's final sign-off, never before.
File the compliance record
Writes the audited entry, with citations, that the program office has to keep anyway.
PRODUCTION TRACE
Supplier Risk Monitoring
Every step below runs against the plant's real data — the exact sequence, in order.
30
Suppliers monitored
2
Risk alerts today
4
SBOM scans completed
6
Access requests reviewed
2 items need your judgment
Ingest signals
AutomatedPublic financial, regulatory, and disruption signals pulled continuously across every supplier — the same public data feeds a risk analyst would check by hand.
Score risk
AutomatedEach of the 30 monitored suppliers gets a risk signal scored against the parts and programs it feeds.
Propose response
AutomatedWhen a supplier crosses a risk threshold, the system proposes a specific response — alternate sourcing, expedite, or escalate.
Program manager review
Reviewer inputNothing executes without sign-off. The proposal is reviewed against program impact before anything moves.
Execute & log
AutomatedApproved actions execute and the outcome logs back in, sharpening the next risk score.
REAL OUTPUT · SOFTWARE SUPPLY-CHAIN RISK (SBOM)
One Example, Fully Processed
When a job calls for a written artifact, this is what the system produces — everything it finds, structured for the action it triggers next.
Repo Scan — Avionics Control Module
GitHub repository · Scanned in 47s · Cross-referenced against NVD, CISA KEV, EPSS, OSV
Software Components Flagged
| Component | Version | Known Vulnerability | Severity | Scan Confidence |
|---|---|---|---|---|
| libavcodec | 4.4.1 | CVE match, CISA KEV-listed | Critical | 97% |
| openssl | 1.1.1t | CVE match, one version behind patch | High | 93% |
| log4j-core | 2.17.0 | No known CVE | Low | 95% |
| curl | 7.81.0 | CVE match, low exploit prediction | Medium | 88% |
| internal-telemetry-lib | 0.9.3 | Unscanned — private package | Unknown | 41% |
Executive Risk Brief
This repository scan found five components in the build, one with a KEV-listed critical vulnerability that needs a decision before this ships, and one private package that couldn't be verified against public vulnerability databases. Everything else is inside acceptable risk tolerance for this program.
Before This Ships
LIVE — EVERY DECISION AUDITED IN PRODUCTION
Facility Access Adjudication — What's Next
Physical access requests to controlled areas used to go through a checklist approval — fast, but not built to catch the request that looks fine on paper and isn't.
A 4-agent review — intake, access architect, adversarial red-teamer, final approver — checks every request against the facility's SOP corpus. The red-teamer's whole job is to find reasons the request shouldn't be approved before the approver ever sees it.
A real request, from intake to final ruling
A contractor requests badge access to a controlled fabrication bay. Four ranked findings shaped the outcome:
WHAT CHANGED
Time returned
~85% of manual supplier-risk research time
Program managers got the time back for supplier relationships and technical reviews, not spreadsheet monitoring.
Operating complexity
A word-of-mouth risk signal became a same-day, cited alert
Where this stands
First system live and cleared for use in 30 days
UP NEXT · TEAM VIEW