Control index
Stable Kiyo control IDs identify advisory obligations, not ISO clauses or native enforcement. Every ID has exactly one canonical definition. This page is generated from framework/control-index.md at the documented revision; each link opens the defining section on GitHub.
| Property | Value |
|---|---|
| ID scheme | KIYO-<FAMILY>-NNN |
| Total IDs | 68 |
| Status of every ID | ACTIVE / none — authored instruction, no replacement. ACTIVE is not tested agent compliance |
| Stability rule | IDs are kept when files move or wording is clarified; never renumbered or reused. A materially different obligation gets a new ID with migration history |
Requirement references (REQ-###) point into the framework’s requirement register. They show scope, not acceptance.
Core rules
Section titled “Core rules”| Control ID | Title (canonical definition) | Related requirements |
|---|---|---|
KIYO-FACT-001 |
Evidence and knowledge classes | REQ-008, REQ-019, REQ-020 |
KIYO-FACT-002 |
Discover before asking | REQ-008, REQ-013, REQ-032 |
KIYO-FACT-003 |
Bound environment claims | REQ-013, REQ-019, REQ-020 |
KIYO-FACT-004 |
Honest checks and closure | REQ-040, REQ-041, REQ-044 |
KIYO-DEC-001 |
Intended behavior and conflicts | REQ-019, REQ-022, REQ-049 |
KIYO-ENG-001 |
Existing safe patterns, principle 6 | REQ-033 |
KIYO-ENG-002 |
Make behavior and acceptance traceable | REQ-031, REQ-032 |
KIYO-ENG-003 |
Preserve safe boundaries and explicit design intent | REQ-033, REQ-035 |
KIYO-ENG-004 |
Keep changed code clear, bounded and safe | REQ-033, REQ-036, REQ-053 |
KIYO-ENG-005 |
Match checks to behavior, risk and observed results | REQ-038, REQ-040, REQ-041 |
KIYO-ENG-006 |
Evaluate affected quality with proportionate evidence | REQ-036, REQ-056 |
KIYO-ENG-007 |
Preserve human work and keep the diff necessary | REQ-030, REQ-034 |
KIYO-CHG-001 |
Minimum change, principle 7 | REQ-015, REQ-030, REQ-034 |
KIYO-SAFE-001 |
Read-only intent | REQ-027, REQ-028, REQ-041 |
KIYO-AUTH-001 |
Native hierarchy | REQ-007, REQ-011, REQ-051 |
KIYO-AUTH-002 |
Policy provenance | REQ-011, REQ-054 |
KIYO-AUTH-003 |
Scoped approvals | REQ-049, REQ-051, REQ-052 |
KIYO-AUTH-004 |
Concrete approval scope and reuse | REQ-049, REQ-052 |
KIYO-TRUST-001 |
Embedded instructions | REQ-012, REQ-058, REQ-062 |
KIYO-LOAD-001 |
Relevant context | REQ-009, REQ-014 |
KIYO-LOAD-002 |
Kiyo budgets | REQ-009, REQ-014, REQ-030 |
KIYO-ACT-001 |
Activation evidence | REQ-005, REQ-009, REQ-010 |
Memory
Section titled “Memory”| Control ID | Title (canonical definition) | Related requirements |
|---|---|---|
KIYO-MEM-001 |
Memory with evidence | REQ-016, REQ-017, REQ-023, REQ-024 |
KIYO-MEM-002 |
Canonical store and scope | REQ-017, REQ-024 |
KIYO-MEM-003 |
Entry evidence and dates | REQ-019, REQ-020, REQ-024 |
KIYO-MEM-004 |
Observation and decision drift | REQ-016, REQ-021, REQ-022 |
KIYO-MEM-005 |
Authorized minimal writes | REQ-023, REQ-024, REQ-027, REQ-075 |
KIYO-MEM-006 |
Memory Impact | REQ-023, REQ-044 |
KIYO-MEM-007 |
Durable minimized content | REQ-018, REQ-046, REQ-062 |
KIYO-MEM-008 |
Scoped Memory modes and preserved history | REQ-017, REQ-020, REQ-023, REQ-024, REQ-027, REQ-075 |
Governance
Section titled “Governance”| Control ID | Title (canonical definition) | Related requirements |
|---|---|---|
KIYO-GOV-001 |
Advisory AI governance | REQ-007, REQ-011, REQ-046, REQ-054 |
KIYO-GOV-002 |
Kiyo governance modes | REQ-027, REQ-047 |
KIYO-RISK-001 |
Contextual risk assessment | REQ-035, REQ-048 |
KIYO-ACTION-001 |
Preparation versus effects | REQ-041, REQ-048, REQ-052 |
KIYO-DATA-001 |
Content-based data handling | REQ-046, REQ-050, REQ-055 |
KIYO-PERM-001 |
Necessary authorized capabilities | REQ-007, REQ-041, REQ-051 |
KIYO-DEP-001 |
Dependency justification | REQ-003, REQ-053, REQ-059 |
KIYO-PROVIDER-001 |
Provider evidence and limits | REQ-013, REQ-055 |
KIYO-POLICY-001 |
Scoped policy resolution | REQ-011, REQ-049, REQ-054, REQ-055, REQ-073 |
KIYO-CONFIG-001 |
One project configuration | REQ-017, REQ-037, REQ-054, REQ-068 |
Security
Section titled “Security”| Control ID | Title (canonical definition) | Related requirements |
|---|---|---|
KIYO-SEC-001 |
Establish trust from evidence | REQ-058 |
KIYO-SEC-002 |
Compare honest metadata with the actual payload | REQ-061, REQ-067 |
KIYO-SEC-003 |
Preserve the authority boundary across retrieved content | REQ-012, REQ-062 |
KIYO-SEC-004 |
Bind source review to the actual artifact | REQ-053, REQ-059 |
KIYO-SEC-005 |
Reassess changed content and scope before reuse | REQ-049, REQ-064 |
KIYO-SEC-006 |
Establish required host controls or hold dependent execution | REQ-007, REQ-051, REQ-063 |
KIYO-SEC-007 |
Keep review layers and blind spots explicit | REQ-040, REQ-065, REQ-077 |
KIYO-SEC-008 |
Keep accountable optional file records | REQ-049, REQ-066 |
KIYO-SEC-009 |
Verify each platform control independently | REQ-005, REQ-067 |
KIYO-SEC-010 |
Review application behavior separately from agent skills | REQ-057, REQ-073 |
KIYO-SEC-011 |
Bound Security submodes and assurance | REQ-027, REQ-042, REQ-058, REQ-065, REQ-073 |
Routing and workflows
Section titled “Routing and workflows”| Control ID | Title (canonical definition) | Related requirements |
|---|---|---|
KIYO-ROUTE-001 |
Select a workflow without granting authority | REQ-025, REQ-026, REQ-027, REQ-028 |
KIYO-FLOW-001 |
Reduce ceremony without skipping controls | REQ-029, REQ-030, REQ-035 |
KIYO-FLOW-002 |
Sequence authorized changes through actual evidence | REQ-027, REQ-033, REQ-034, REQ-035, REQ-041, REQ-042 |
KIYO-FLOW-003 |
Complete analysis without introducing mutation | REQ-027, REQ-028, REQ-044 |
KIYO-FLOW-004 |
Classify failures and bound repair cycles | REQ-029, REQ-039, REQ-040 |
KIYO-FLOW-005 |
Handoff facts and authorized next actions | REQ-014, REQ-044, REQ-045 |
KIYO-INIT-001 |
Initialize only evidenced and authorized project state | REQ-015, REQ-016, REQ-017, REQ-024, REQ-027, REQ-068 |
KIYO-REQ-001 |
Define evidenced requirements without authorizing implementation | REQ-026, REQ-027, REQ-031, REQ-032, REQ-044, REQ-069 |
KIYO-IMPL-001 |
Bind daily engineering to intent, baseline and checked scope | REQ-015, REQ-023, REQ-027, REQ-029, REQ-034, REQ-035, REQ-070 |
KIYO-REVIEW-001 |
Read-only bounded review | REQ-028, REQ-040, REQ-041, REQ-044, REQ-071 |
KIYO-TEST-001 |
Test modes and actual evidence | REQ-027, REQ-038, REQ-039, REQ-040, REQ-041, REQ-072 |
KIYO-ARCH-001 |
Observed architecture versus approved intent | REQ-019, REQ-022, REQ-027, REQ-033, REQ-074 |
Engineering profiles
Section titled “Engineering profiles”| Control ID | Title (canonical definition) | Related requirements |
|---|---|---|
KIYO-PROF-001 |
Bind profiles to evidence without forcing a stack | REQ-037, REQ-054 |
Verification, completion, reporting
Section titled “Verification, completion, reporting”| Control ID | Title (canonical definition) | Related requirements |
|---|---|---|
KIYO-VERIFY-001 |
Record scoped observations for every check | REQ-040, REQ-041, REQ-043, REQ-077 |
KIYO-VERIFY-002 |
Bind results to the checked state and baseline | REQ-039, REQ-040, REQ-044 |
KIYO-DONE-001 |
Close the agreed workflow against current required evidence | REQ-023, REQ-042, REQ-044, REQ-045 |
KIYO-REPORT-001 |
Report scoped work without manufacturing an audit trail | REQ-043, REQ-045, REQ-046, REQ-049 |
Related
Section titled “Related”- Status vocabulary
- Concept map: the ten bootstrap rules in context