evaluation pattern · L2ET Research Method Signal
Frontier AI evaluation must separate capability, autonomy and tool authority
Evaluation plans should test task success, refusal boundaries, tool-use failure, deception pressure, escalation behavior and monitoring before production use.
confidence: high
action: apply
score: 93
Frontier AI, AI Governance
tools/frontier-ai-evaluation-plannerframeworks/frontier-ai-evaluation-model
open related instrument →
control pattern · L2ET Research Method Signal
Agentic systems need explicit permission boundaries before deployment
Tool-using systems should define permitted actions, forbidden actions, approval gates, logs, rollback and emergency disable paths before business use.
confidence: high
action: apply
score: 92
Frontier AI, Agentic AI, AI Governance
tools/agentic-ai-permission-boundary-designerframeworks/agentic-ai-control-architecture
open related instrument →
threat model · L2ET Research Method Signal
RAG reliability begins with source trust and contamination mapping
Retrieval poisoning, source decay, prompt injection, citation failure and index contamination are separate failure paths and should be tested separately.
confidence: high
action: apply
score: 90
AI Governance, RAG Security
tools/rag-contamination-threat-modelframeworks/rag-security-assurance-layer
open related instrument →
evidence pattern · L2ET Research Method Signal
AI governance decisions need evidence artifacts, not only policy language
Use-case intake, risk classification, data cards, evaluation results, release decisions and monitoring evidence are the practical substrate of AI oversight.
confidence: high
action: apply
score: 91
AI Governance, Standards and Regulation
tools/ai-governance-evidence-mapperframeworks/ai-governance-operating-model
open related instrument →
resilience pattern · L2ET Research Method Signal
Cyber resilience depends on telemetry coverage before incident response starts
Identity, endpoint, network, cloud, email and application logs must be mapped before an incident, otherwise timeline reconstruction becomes guesswork.
confidence: high
action: apply
score: 88
Cybersecurity, DFIR
tools/cyber-telemetry-coverage-maptools/dfir-timeline-consistency-checker
open related instrument →
evidence pattern · L2ET Research Method Signal
DFIR timelines fail when clocks, evidence sources and log integrity are not controlled
Time-source normalization, immutable records, chain-of-custody notes and gap identification should be performed before conclusions are drawn.
confidence: high
action: apply
score: 87
DFIR, Cybersecurity
tools/dfir-timeline-consistency-checkerframeworks/dfir-evidence-and-resilience-model
open related instrument →
method pattern · L2ET Research Method Signal
Threat hunting needs falsifiable hypotheses rather than keyword fishing
A good hunt starts with a suspected behavior, available telemetry, expected observations, disconfirmation criteria and evidence needed to escalate.
confidence: high
action: review
score: 86
Cybersecurity, DFIR
tools/threat-hunting-hypothesis-buildertools/cyber-telemetry-coverage-map
open related instrument →
transition pattern · L2ET Research Method Signal
PQC transition begins with cryptographic inventory and evidence
Before algorithm migration, teams need a cryptographic bill of materials, supplier evidence, certificate dependency mapping and data-lifetime prioritization.
confidence: high
action: apply
score: 91
Post-Quantum Cryptography, Enterprise Resilience
tools/crypto-exposure-mapperframeworks/pqc-transition-operating-model
open related instrument →
resource model · L2ET Research Method Signal
Quantum computing claims should be checked against qubits, depth and error assumptions
A useful quantum computation discussion needs logical qubits, gate counts, error budget, circuit depth, shots and fault-tolerance assumptions.
confidence: high
action: review
score: 89
Quantum Computing, Frontier and Theoretical Physics
tools/quantum-circuit-resource-estimatorframeworks/quantum-computing-resource-model
open related instrument →