From the Book

AACG Toolkit

Practical templates for Agentic AI Control & Governance. These are the appendix-driven tools from ABC's of AI Security & Governance.

Fill out each template interactively and download as PDF for your governance documentation.

Agent/System Card

Appendix C

A 1-2 page document that captures identity, purpose, authority envelope, consequential actions, monitoring, and containment for each agent or AI system.

Required for every registered agent. Provides at-a-glance governance view.

Action Class Catalog

Appendix B

Enterprise-wide definitions of consequential action classes with default tiers, gates, verification requirements, logging standards, and rollback procedures.

Define once, apply everywhere. Prevents "one-off" rules and makes approvals auditable.

Risk Acceptance Memo

Appendix D

Formal documentation of accepted risks with business justification, controls in place, compensating controls, scope, duration, and approver sign-off.

Required when accepting residual risk for Tier 4-5 systems or when waiving controls.

Assurance Pack

Appendix E

A 10-item exportable evidence bundle proving governance and control: registry entries, traces, eval results, drill records, and exception status.

Export within hours for customer assurance requests, audits, or incident response.

Incident Response Playbook

Appendix F

Step-by-step playbook for agentic incidents: containment, evidence preservation, investigation, rollback, communications, and corrective actions.

Prepare before incidents occur. Cover leakage, unauthorized actions, spoofing, poisoning, chaining runaway, and drift.

Vendor Questionnaire

Appendix G

ACR/STRIKE-aligned questions for vendor procurement: enforcement, evidence export, connector governance, model updates, data handling, incident response, and testing rights.

Use before purchasing agentic SaaS or AI platforms to ensure governance is implementable.

Need context?

These templates are most effective when used alongside the doctrine in the book. Each chapter explains when and how to apply these artifacts.

Learn more about the book →

© 2026 Adam DiStefano