AI 中文总结
针对智能体工程系统输出保障碎片化问题,提出敏捷-V保障脊柱,一种跨领域转换契约,通过证据门控和效果边界重检实现授权转换,贡献词汇、架构和评估议程。
AI 中文摘要
智能体工程系统可以编辑代码仓库、运行工具和测试、构建固件、综合原理图,并准备可部署或可制造的工件。因此,保障问题正从智能体能否产生输出,转变为工程生命周期是否有理由基于关于该输出的声明而采取行动。当前的产品和标准提供了沙箱、审批、钩子、追踪、策略执行、证明、物料清单和保障表示,但这些能力仍然分散。本文提出了敏捷-V保障脊柱(Agile-V Assurance Spine),这是一个针对软件、固件和PCB工程的跨领域转换契约。证据仅在通过权威来源配置文件确立所需属性、绑定到确切工件和冻结的策略基线、相对于声明的依赖保持最新,并满足风险适当的独立性和权威性时,才被接纳。门控决策被记录为收据;审批和例外具有精确范围和时间限制;授权在合并、部署、烧录、发布或制造之前,在效果边界处重新检查。对当代研究、商业平台、开源基础设施和标准的有限回顾,将该模型定位在证据门控生命周期控制、持续保障、运行时准入、来源和AI/ML清单的背景下。本文贡献了精确的词汇表、组合架构、领域配置文件、到开源实现的映射,以及对抗性评估议程。它不声称监管合规性或已证明的生产优越性。
英文摘要
Agentic engineering systems can edit repositories, run tools and tests, build firmware, synthesize schematics, and prepare deployable or manufacturable artifacts. The assurance problem is therefore shifting from whether an agent can produce an output to whether an engineering lifecycle is justified in acting on claims about that output. Current products and standards provide sandboxes, approvals, hooks, traces, policy enforcement, attestations, bills of materials, and assurance representations, but these capabilities remain fragmented. This paper presents the Agile-V Assurance Spine, a cross-domain transition contract for software, firmware, and PCB engineering. Evidence is admitted only when it establishes required properties through an authoritative source profile, is bound to the exact artifact and frozen policy baseline, remains current with respect to declared dependencies, and satisfies risk-appropriate independence and authority. Gate decisions are recorded as receipts; approvals and exceptions are exact-scope and time-bounded; and authorization is rechecked at the effect boundary before merge, deployment, flashing, release, or fabrication. A bounded review of contemporary research, commercial platforms, open-source infrastructure, and standards positions the model relative to evidence-gated lifecycle control, continuous assurance, runtime admission, provenance, and AI/ML inventories. The paper contributes a precise vocabulary, compositional architecture, domain profiles, mapping to open-source implementations, and an adversarial evaluation agenda. It does not claim regulatory conformity or demonstrated production superiority.
Comments10 pages