Credibility Partner Review

Is SMERC worth testing in shadow mode?

This page gives CISOs, security architects, platform leaders, reliability teams, and AI-governance reviewers a focused path for challenging SMERC before any pilot. The ask is simple: inspect the evidence, challenge the scenarios, and decide whether metadata-only shadow-mode testing is worth discussing.

ALLOW THROTTLE FREEZE DENY ESCALATE

Positioning

Runtime permission infrastructure for automated actions

SMERC scores whether AI-agent and automation actions are recoverable enough to execute before they create real side effects. The first practical wedge is GitHub Actions and AI-assisted software delivery in shadow mode.

Governance Pattern Atlas

One mechanism across five enterprise disciplines

The atlas consolidates five benchmark families into one evidence package. The point is not to claim SMERC replaces these disciplines. The point is to show the same recoverability mechanism appearing at the action boundary.

Discipline Scenarios Deltas Delta Rate Strongest Example
AML-inspired financial governance 8 2 25% Digital-asset withdrawal -> FREEZE
Change-management-inspired production governance 8 7 87.5% Weak-rollback database migration -> DENY
Security-response-inspired automation governance 8 4 50% Customer breach notification -> DENY
Model-risk-inspired AI governance 8 6 75% Unapproved customer email model -> DENY
SRE/incident-management-inspired reliability governance 8 5 62.5% Production queue deletion -> DENY

Total: 40 scenarios, 24 decision deltas, 60% weighted delta rate.

30-Minute Review Path

What to inspect

  • Read the plain-English overview and Governance Pattern Atlas.
  • Inspect the consolidated benchmark evidence.
  • Inspect the recoverability scoring engine and action-language boundary.
  • Inspect the GitHub Actions pilot path and Governance Routing Workbench execution controls.
  • Inspect the Decision Lifecycle Ledger and governance report path.
  • Answer whether metadata-only shadow-mode testing is worth discussing.

What SMERC is not claiming

  • Not production-certified.
  • Not customer-validated yet.
  • Not a replacement for OPA, IAM, GRC, SIEM, SOAR, EDR, ServiceNow, Jira, AML, or model-risk systems.
  • Not claiming incident reduction, compliance attestation, or product-market fit.
  • Not recommended for enforcement before shadow-mode calibration.

Questions for the reviewer

  • Do these scenarios resemble actions your team sees or expects?
  • Where would SMERC create useful restraint versus noise?
  • Which inputs need customer-specific calibration?
  • Which workflow should be tested first?
  • What existing control already solves this problem?

Suggested outreach paragraph

I am looking for a credibility review of SMERC, a runtime permission layer for AI-agent and automation actions. The current prototype scores whether proposed actions are recoverable enough to allow, throttle, freeze, deny, or escalate before execution. The first pilot wedge is GitHub Actions shadow-mode scoring for AI-assisted code, deployment, and infrastructure workflows. I am not asking you to treat this as production-ready. I am asking whether the evidence package is credible enough to test against metadata-only examples from a real workflow.