OSuite Runtime Exposure

OSuite Runtime Exposure Report

Connect an agent and run one governed action to build the first runtime exposure map.

Workspace: unknown Generated: 2026-08-04T07:10:50.720Z Exposure score: 0/100 Status: not_started

AI Runtime Inventory

No AI runtime exposure surface has been discovered yet.

Agents0
Runtime adapters19
Coverage tiermanaged
Active sessions4
Systems touched0
Governed actions0
High-impact systems0

No records in this section.

SessionAgentRuntime laneStatusSignaturePosture
00a631a5-ae38-47f0-8849-0b96f24ac8ebcodex-cli-prod-smokeClaude Code Hooksactiveworkspace_key_optionalenforce
d54e5524-7d98-4bf2-b483-7e01f020b629codex-cli-prod-smokeClaude Code Hooksactiveworkspace_key_optionalenforce
671ab267-4845-47f9-b017-7d17e442c81acodex-cli-prod-smokeClaude Code Hooksactiveworkspace_key_optionalenforce
f7a64600-7032-42ce-bcaa-c1e8a2978a4cclaude-hooks-demoClaude Code Hooksactiveworkspace_key_optionalenforce

Runtime Coverage

Runtime Coverage separates Reference adapters, Managed OSuite adapters, and Enterprise custom adapters so customers can see which action lanes are understood, supported, and production-governed. Current top active tier: Managed OSuite adapters.

Status: active Selected tier: managed
MetricValue
Reference lanes0
Managed lanes8
Enterprise custom lanes11
Connected coverage1/19
Runtime sessions4
Covered agents0
TierCountUser pathStudio behavior
Reference adapters0Install osuite-cava-core, define or reuse parser packs, run local canonicalization and receipt checks.Shown as reference coverage only; high-impact production lanes should not be marked fully governed from this tier alone.
Managed OSuite adapters8Use the one-line installer or connector flow; OSuite maintains parser updates and evidence quality.Appears as Runtime Coverage with parser posture, evidence gaps, unsupported actions, and remediation paths.
Enterprise custom adapters11Map sample events into CAVA fields, validate coverage, version the adapter, and deploy through OSuite.Appears as customer runtime coverage with field mapping, versioning, approval routing, and proof export.
Runtime laneTierParser postureStatusDisclosure
Claude Connectors DirectoryManaged OSuite adaptersmanagedreadyManaged pack: OSuite maintains parser updates, coverage diagnostics, proof export, and policy routing.
ChatGPT Apps ConnectorManaged OSuite adaptersmanagedreadyManaged pack: OSuite maintains parser updates, coverage diagnostics, proof export, and policy routing.
Codex Remote ConnectorManaged OSuite adaptersmanagedreadyManaged pack: OSuite maintains parser updates, coverage diagnostics, proof export, and policy routing.
Claude Desktop ExtensionManaged OSuite adaptersmanagedreadyManaged pack: OSuite maintains parser updates, coverage diagnostics, proof export, and policy routing.
Claude Code HooksManaged OSuite adaptersmanagedconnectedManaged pack: OSuite maintains parser updates, coverage diagnostics, proof export, and policy routing.
Codex PluginManaged OSuite adaptersmanagedreadyManaged pack: OSuite maintains parser updates, coverage diagnostics, proof export, and policy routing.
Codex HooksManaged OSuite adaptersmanagedreadyManaged pack: OSuite maintains parser updates, coverage diagnostics, proof export, and policy routing.
Azure FoundryEnterprise custom adaptersenterprise_customreadyEnterprise custom pack: OSuite maps private runtime fields, customer schemas, and sensitive business systems.
Gemini Enterprise Agent PlatformEnterprise custom adaptersenterprise_customplannedEnterprise custom pack: OSuite maps private runtime fields, customer schemas, and sensitive business systems.
Bedrock AgentCoreEnterprise custom adaptersenterprise_customplannedEnterprise custom pack: OSuite maps private runtime fields, customer schemas, and sensitive business systems.
OpenAI Agents SDKManaged OSuite adaptersmanagedplannedManaged pack: OSuite maintains parser updates, coverage diagnostics, proof export, and policy routing.
OpenAI APIEnterprise custom adaptersenterprise_customplannedEnterprise custom pack: OSuite maps private runtime fields, customer schemas, and sensitive business systems.

Governance Capital

What survives if AI budgets, providers, or internal sponsors change: the controlled runtime inventory, action authority, approval leases, exposure history, and evidence record.

Surface: AI Deployment Survival Score: 16/100 Status: exposed
DimensionScoreStatusWhy it matters
Runtime control assets21/100exposedIf the organization cannot see the runtime estate, AI budget cuts or provider swaps turn into another discovery project.
Bounded authority0/100not_startedTrust is easier to preserve after an incident when approvals are scoped, time-bound, and replay-resistant.
Evidence durability0/100not_startedA pilot becomes defensible only when the team can prove what happened without reconstructing it manually.
Runtime portability92/100strongPortability keeps OSuite from depending on a single agent vendor cycle.
Exposure resilience0/100not_startedWhen AI hype corrects, teams keep the systems that can show controlled blast radius and remediation progress.
Policy-to-runtime binding0/100not_startedPolicy language becomes capital only when it changes runtime behavior and leaves evidence.
Survival testPostureExplanation
Budget correctionneeds proofReduce proof gaps and observe-only lanes before using OSuite as a budget-defense artifact.
Provider churnportableThe governance object can survive a runtime or model-provider change.
Incident reviewfragileClose evidence durability and approval binding before relying on post-incident reconstruction.
Procurement diligenceneeds hardeningMap policy profile, runtime decisions, and proof closure into one exportable packet.

Top Runtime Exposures

No exposure backlog item is currently active.

No records in this section.

Vendor and Runtime Dependency Risk

3 dependency lane(s) are visible across providers, runtimes, tools, systems, approvals, and evidence.

LaneCountRiskExamples
Model and agent providers5distributedOpenAI / Codex, Anthropic / Claude, Microsoft / Azure, LangGraph, MCP tool servers
Runtime adapters19controlledClaude Connectors Directory, ChatGPT Apps Connector, Codex Remote Connector, Claude Desktop Extension, Claude Code Hooks, Codex Plugin
MCP and tool servers3reviewClaude Connectors Directory, ChatGPT Apps Connector, Codex Remote Connector
External and business systems0not_startedn/a
Approval and authority lanes0not_startedPCAA, policy profile, Action Gate Lease
Evidence and receipts0not_startedCAVA receipt, PCAA proof bundle, decision record

Approval Lease Posture

No governed action has reached the runtime firewall yet.

LaneCountMeaning
Allow with proof0Action may continue when CAVA meaning, policy profile, and proof closure agree.
Ask for approval0Execution waits for a PCAA-recognized authority instead of trusting the agent runtime alone.
Block or fail closed0High-risk allow paths are treated as firewall defects until a bounded approval exists.
Observe only0OSuite can record evidence but cannot yet enforce before execution on this lane.
Expired or unbound0Unsigned actions or proof gaps cannot be reused as durable approvals.

External Verifier Coverage

No external verifier checkpoint has been attached to recent runtime actions yet.

Coverage: 0% Expected source: independent_mediator Independent mediator: 0 Verified refs: 0 Mapping pending: 0 Execution divergence: 0

No records in this section.

Recommended Remediation

Run at least one governed action before remediation can be recommended.

No records in this section.