Federated consortium accountability controls

Loading…

A federation of peer institutions cannot use the customer-and-provider split that the other control sets on this site assume. Every layer here divides into two governing domains instead: a Shared Commons that stays open and independently usable, and Participant Sovereign Assets that each participant controls unless it voluntarily contributes them. The controls below assign accountability inside that division, drawing on Project Tapestry's TAP-010.

Proposed extension, and the source is still in draft. This control set is not part of CoSAI SRF v1.0 and has not been endorsed by CoSAI or by the AI Alliance. Its source documents carry status Proposed and name a Tapestry Governance Committee that is not yet seated, so several controls below record a duty whose mechanism the source leaves unresolved. Those are marked Open. Where two source documents state incompatible requirements, the control is marked Conflicted and records both positions rather than picking one.
Machine-readable. Raw schema: tapestry-controls.json. Node contribution manifests are published as OSCAL component definitions, which let a participant assert which controls it implements, and at which disclosure tier, without shipping the underlying evidence. The declared rules in the schema are enforced by build/verify_tapestry_accountability.py.

The five disclosure tiers, on two axes

TAP-010 lists five ways evidence about a contribution can be handled, ordered by audience. Audience is not the same thing as assurance, so the table below scores each tier twice. Strength is how well the tier resists a participant that misstates its own compliance, which is the property TAP-010 cares about when it asks for guarantees independent of organizational goodwill. Disclosure is how far the underlying evidence has to travel. Shaded rows are the tiers that another tier beats on both axes at once.

Tier Who sees the evidence Strength Disclosure Limit

Loading…

Loading controls…