Agent-agnostic production runtime map

What controls exist? What evidence survives?

The matrix compares control surfaces across AI runtimes and real production workflows without pretending that vendor documentation, direct observation, independent testing, and verified control posture are the same thing.

Truth boundary: this is not a safety leaderboard, certification, endorsement, or universal score. Cells describe evidence state. A documented control is not automatically effective. A tested control applies only to the tested scope and conditions.
Production runtime control coverage

Compare the operating surface.

NULLWORKS sits across the matrix as an independent operational-assurance layer. The runtime may be CIRIS, a commercial provider stack, an open-source framework, or a homegrown system. The object under test is the consequential operating loop: agents, tools, data, humans, authority, evidence, recovery, and change.

Key // tap any item for detail
TTESTED

NULLWORKS independently exercised a relevant control surface.

DDOCUMENTED

A public source documents the control or capability. Documentation is not independent verification.

OOBSERVED

Behavior or interface was directly observed but not necessarily falsification-tested.

FGAP

Expected behavior or a tested claim did not survive the specific test condition.

UUNKNOWN

Evidence is insufficient or has not yet been acquired.

VVARIES

Portability or control depends materially on configuration, provider, integration, or deployment design.

Runtime / systemAuthorityAccessDataEvidenceRecoveryContinuityStop / revokeHuman escalationPortable state
Open-source governed agent runtime
TESTED
TTTTTTTTT
OpenAI agent stack
Commercial model + agent/tool ecosystem
DOC REVIEW
DDDDUDDDV
Anthropic agent stack
Commercial model + agent/tool ecosystem
DOC REVIEW
DDDDUDDDV
Google agent stack
Commercial model + agent/tool ecosystem
DOC REVIEW
DDDDUDDDV
Agents + tools + humans + workflow
UNKNOWN
UUUUUUUUU
Open-source governed agent runtime
TESTED
AuthorityT
AccessT
DataT
EvidenceT
RecoveryT
ContinuityT
Stop / revokeT
Human escalationT
Portable stateT
OpenAI agent stack
Commercial model + agent/tool ecosystem
DOC REVIEW
AuthorityD
AccessD
DataD
EvidenceD
RecoveryU
ContinuityD
Stop / revokeD
Human escalationD
Portable stateV
Anthropic agent stack
Commercial model + agent/tool ecosystem
DOC REVIEW
AuthorityD
AccessD
DataD
EvidenceD
RecoveryU
ContinuityD
Stop / revokeD
Human escalationD
Portable stateV
Google agent stack
Commercial model + agent/tool ecosystem
DOC REVIEW
AuthorityD
AccessD
DataD
EvidenceD
RecoveryU
ContinuityD
Stop / revokeD
Human escalationD
Portable stateV
Agents + tools + humans + workflow
UNKNOWN
AuthorityU
AccessU
DataU
EvidenceU
RecoveryU
ContinuityU
Stop / revokeU
Human escalationU
Portable stateU

CIRIS

NULLWORKS has independently exercised a pinned CIRIS release. Public proof is sanitized; testing applies to the reviewed revisions, not every current or future release.

OpenAI agent stack

Public-documentation coverage only in this matrix version. No broad NULLWORKS independent-control claim is implied.

Anthropic agent stack

Public-documentation coverage only in this matrix version. No broad NULLWORKS independent-control claim is implied.

Google agent stack

Public-documentation coverage only in this matrix version. No broad NULLWORKS independent-control claim is implied.

Your production system

This is the row the free triage begins to populate. Paid assurance acquires evidence and attempts to move important cells from claimed or unknown to independently supported.

Commercial bridge

From comparison to evidence.

01 / FIND

Locate your runtime, framework, or operating pattern.

02 / COMPARE

See what is documented, tested, variable, or unknown.

03 / TRIAGE

Run the 18-question self-reported control diagnostic.

04 / TEST

Acquire evidence and falsify the important assumptions.

05 / RECEIPT

Retest repairs and preserve the changed control state.