How far can you responsibly go?
Governance is not one dial. It is a relationship between what you are deploying and how mature your capability to govern it is — the two axes of the OWASP Enterprise Adoption Maturity Model.
Select an adoption tier and a governance maturity level to read the posture: whether that deployment is safely governed, thinly governed, or should not run at all. The direction of travel across the whole model is from static, document-driven oversight toward adaptive, telemetry-backed control loops.
Adoption tier — what are we deploying?
- AT0
Shadow AI
No organizational awareness or approval; users self-adopting outside governance. A pre-existing condition to discover, not a chosen tier.
Personal ChatGPT/Gemini/Claude on corporate data, browser AI extensions, unapproved plugins
- AT1
Vendor Embedded Assistant
Fully vendor-controlled; you consume, you do not build.
M365 Copilot, GitHub Copilot, Salesforce Einstein
- AT2
Platform Integrated
AI-native platform working on your data; cannot execute arbitrary code.
Custom GPTs, Amazon Q Business, Vertex AI Agents
- AT3
Citizen Developer Agent
Low-code/no-code; a user configures flows and prompts, not code, acting on real organizational data.
Power Automate + AI Builder, Copilot Studio, ServiceNow AI Agents
- AT4
Code Executing Agent
Generates and executes code with local or cloud privileges.
Open Interpreter, Claude Code, Copilot Workspace, Devin
- AT5
Custom In-House Agent
You built it; you control identity, tools, and boundaries.
LangChain/LangGraph agents, AutoGen orchestrations, Bedrock Agents
- AT6
Externally Extended Agent
Connects to external tools and services across trust boundaries.
Agents with MCP servers, plugin-enabled apps, third-party APIs
- AT7
Multi-Agent Orchestration
Multiple agents coordinate within your organization.
CrewAI workflows, AutoGen teams, LangGraph multi-agent graphs
- AT8
Federated / Cross-Boundary
Agents operate across organizational boundaries.
Cross-org supply-chain agents, federated financial networks, multi-tenant marketplaces
Governance maturity — how mature is our capability to govern?
- L0
Unaware & Ad Hoc
No formal recognition of agentic-specific risk; shadow experiments, no policies, guardrails, or AI-SBOMs.
- L1
Experimentation without Guardrails
Pilots lacking autonomy limits, decision scopes, or escalation; generic policy, no continuous monitoring; diffuse accountability.
- L2
Policy-Defined, Human-in-the-Loop
Formal policies mapped to regulation; mandatory HITL for high-impact actions; a named owner; AI-SBOM — but periodic monitoring.
- L3
Integrated, Continuous Oversight
Agentic AI as critical infrastructure; real-time drift dashboards, kill switches, governance-as-code.
- L4
Adaptive, Self-Regulating
Governance at model speed; guardrails auto-tuned from telemetry, cryptographic agent identity, tamper-evident trails.
The governance posture matrix
The nine adoption tiers collapse into five bands (rows); the five maturity levels into four (columns). Each cell reads off whether that combination is safely governed. Select a row or column to focus it.
How to use it
- 01Assess Shadow AI (AT0) exposure first — assume it exists.
- 02Rate your governance maturity, 0 to 4.
- 03Classify each agent by tier — most organizations span several at once.
- 04For any deployment in an insufficient cell, raise maturity or reduce complexity. AT0 is eliminated, not governed.
Where this model assesses organizational readiness, the OWASP Threat Defense COMPASS (v1.0, 2025) operationalizes threat prioritization for a specific deployment — a spreadsheet dashboard that consolidates threats, defenses, and mitigations into a repeatable prioritization runbook. The tactical companion to this strategic self-assessment.
Security