Skip to main content

Trust Lifecycle

The Trust Lifecycle is OpenBox's governance model. It provides a structured approach to establishing, maintaining, and evolving trust in AI agents through 5 phases.

Access each phase via the tabs in Agent Detail.

┌─────────┐    ┌───────────┐    ┌─────────┐    ┌────────┐    ┌───────┐
│ ASSESS │ → │ AUTHORIZE │ → │ MONITOR │ → │ VERIFY │ → │ ADAPT │
│ │ │ │ │ │ │ │ │ │
│ Initial │ │ Configure │ │ Runtime │ │ Goal │ │ Trust │
│ Risk │ │ Controls │ │ Observe │ │ Check │ │ Evolve│
└─────────┘ └───────────┘ └─────────┘ └────────┘ └───────┘
↑ │
└────────────────────────────────────────────────────────────┘
Continuous Improvement

Phase Overview

PhaseTabPurposeKey Activities
AssessAssessEstablish baseline riskAIVSS configuration, risk profiling
AuthorizeAuthorizeDefine allowed behaviorsGuardrails, policies, behavioral rules
MonitorMonitorObserve runtime executionSessions, metrics, telemetry
VerifyVerifyValidate goal alignmentDrift detection, attestation
AdaptAdaptEvolve trust over timePolicy suggestions, trust recovery

Trust Score

The Trust Score (0-100) aggregates across the lifecycle:

Trust Score = (AIVSS × 40%) + (Behavioral × 35%) + (Alignment × 25%)
ComponentPhaseDescription
AIVSSAssessInherent risk based on capabilities and access
BehavioralAuthorize + MonitorCompliance with policies and rules
AlignmentVerifyConsistency with stated goals

Trust Tiers

The Trust Score maps to Trust Tiers that determine governance strictness:

TierScore RangeGovernance Level
Tier 190-100Minimal constraints, high autonomy
Tier 275-89Standard policies, normal monitoring
Tier 350-74Enhanced controls, frequent checks
Tier 425-49Strict governance, HITL required
Untrusted0-24Supervised mode, all actions require approval

Lifecycle Flow

New Agents

  1. Assess - Configure AIVSS and risk profile
  2. Authorize - Set up initial guardrails and policies
  3. Agent begins operation
  4. Monitor - Observe sessions and metrics
  5. Verify - Check goal alignment
  6. Adapt - Review suggestions, adjust policies

Ongoing Governance

The lifecycle is continuous. As agents operate:

  • Behavioral scores update based on compliance
  • Alignment scores update based on goal checks
  • Trust Tiers adjust automatically
  • Policy suggestions emerge from patterns

In Agent Detail, click the phase tabs:

  • Assess - View/edit risk configuration
  • Authorize - Manage guardrails, policies, behavioral rules
  • Monitor - View sessions, metrics, telemetry
  • Verify - Check alignment, view attestations
  • Adapt - Review suggestions, handle approvals

Next Steps

Follow the Trust Lifecycle phases in order:

  1. Assess - Start here to understand your agent's risk profile
  2. Authorize - Then configure what your agent is allowed to perform
  3. Monitor - Watch your agent operate in real-time
  4. Verify - Validate goal alignment
  5. Adapt - Evolve trust based on behavior