Expanded External Framework Intake
Purpose
This page prevents the External Frameworks section from appearing artificially small.
The current registered framework list contains frameworks that already have wiki pages, mappings, or fixtures. The broader observatory should also track candidate frameworks that may become relevant to runtime governance, AI safety, auditability, authorization, provenance, privacy, supply-chain integrity, identity, assurance, policy-as-code, agent security, model evaluation, and regulatory governance.
The full visible list is maintained in the External Framework Candidate Directory.
Current Visible Scope
registered framework and crosswalk entries: 19
additional source-required candidates: 42
total visible observatory entries: 61
intake classes represented: 10
The registered and candidate sets have different evidence states. The combined count is for observatory visibility and work planning only.
Candidate inclusion is not validation.
candidate != sourced page
candidate != framework equivalence
candidate != endorsement
candidate != certification
candidate != execution authority
candidate != StegVerse standing
Intake Classes
| Intake Class | Meaning |
|---|---|
| runtime_governance | Evaluates or constrains actions, tool use, paths, or execution. |
| policy_as_code | Represents machine-readable rules, obligations, policies, or controls. |
| provenance_and_trace | Preserves origin, trace, lineage, custody, or reconstruction evidence. |
| identity_and_authority | Represents identity, delegation, authorization, credentials, or access. |
| risk_and_assurance | Provides risk management, assurance, audit, controls, or certification context. |
| threat_and_security | Provides adversarial, vulnerability, or attack-defense knowledge. |
| privacy_and_data_governance | Provides data handling, privacy, consent, retention, or disclosure controls. |
| model_eval_and_monitoring | Evaluates model behavior, regressions, safety, robustness, or drift. |
| regulatory_and_standards | Provides legal, standards, or sector-governance requirements. |
| agent_protocols | Defines agent communication, tool invocation, delegation, or interoperability. |
Candidate Status
| Status | Meaning |
|---|---|
| candidate_unsourced | Name or category identified; no canonical source attached. |
| source_required | Candidate should not be used until a public canonical source is attached. |
| sourced_intake | Canonical source attached but no page/mapping exists. |
| page_candidate | Candidate should receive an external-framework page. |
| mapping_candidate | Candidate should receive benchmark mapping. |
| fixture_candidate | Candidate should receive fixture examples. |
| rejected_or_deferred | Candidate intentionally excluded or deferred with reason. |
Candidate Families To Expand
policy-as-code and authorization engines
identity, trust, and delegation frameworks
software supply-chain and provenance systems
AI safety evaluation suites
agent security and tool-governance frameworks
privacy and data governance frameworks
cloud governance and zero-trust frameworks
audit, assurance, and compliance frameworks
incident response and threat-modeling frameworks
model monitoring and drift-detection frameworks
sector-specific AI governance frameworks
Intake Rule
New external framework candidates should enter as intake records first.
A candidate may move to a full external-framework page only after:
canonical source identified
published scope captured
non-claims recorded
relationship to StegVerse classified
benchmark relevance determined
authority boundary preserved
Non-Claims
This intake page does not certify external frameworks.
This intake page does not rank external frameworks.
This intake page does not claim equivalence with StegVerse.
This intake page does not grant execution authority.
This intake page does not make unsourced candidates usable evidence.
The combined observatory count is not a compatibility or quality score.
External-framework intake is observatory work. Publication does not create standing. Standing must be reconstructed from source, evidence, authority, admissibility, and current commit-time conditions.