ARC Agent Governance

Roadmap

ARC Agent Governance is at the beta stage. This page is the real plan, not a marketing page — items move only when they actually ship. Anything not listed here is not planned, and the fastest way to change that is to open an issue.

Shipped

  • Deterministic rule engine with 19 published rule ids
  • Agent / tool / data inventory from prose or sanitized JSON
  • Evidence-backed findings — every finding quotes your own words
  • Published scoring rubric with per-dimension explanations
  • MCP governance checks (allowlist, auth, trust boundary)
  • Sequenced recommendations tied to the findings that produced them
  • Honest limitations block, including what could not be seen
  • Free public API plus JSON and Markdown export
  • Golden evaluation suite (25+ cases) and adversarial inputs

Next

  • Expanded rule pack from real submissions and reported false positives
  • Optional model-assisted narrative — phrasing only, never a new claim or number
  • Shareable report link with an expiring, revocable URL
  • PDF export in addition to Markdown and JSON
  • Production deploy with verified live URL

Later

  • Structured form input as an alternative to free text / JSON
  • Document upload, once a safe parsing path is in place
  • Comparison between two assessments over time
  • Read-only repository and config integrations
  • Deeper integration with the other ARC Labs assessments

Deliberately not doing

These are out of scope by design, not by backlog order.

  • Penetration testing
  • Exploitation
  • Credential harvesting
  • Arbitrary code execution
  • Automatic remediation
  • Unsupported compliance certification

Shape this

A wrong finding is more useful to us than a compliment. Tell us what the rules got wrong, or open a pull request against the rule pack.