Commit envelopes
Matrix Scroll signs every agent-assisted merge — actor, tool, and scope in an Ed25519 envelope your assessor verifies offline.
PyPI SDK ↗FS AI RMF maps evidence for regulated fintech — a door-opener, not the spearhead. Lead with agent authorization; use this checklist when your buyer asks about Treasury-endorsed AI governance. Matrix Scroll signs merges locally; SSX360 hosts authorization records, Scroll Gate CI, and audit packs assessors verify offline. We map a deliberate SDLC / change-management slice of FS AI RMF — the part institutions struggle to defend when agents land on protected branches.
Voluntary framework — produces evidence aligned to FS AI RMF control objectives; not certified by CRI or Treasury. Scoped to SDLC / change-management only (not all 230 objectives).
For CRI / ecosystem reviewers
Matrix Scroll signs every agent-assisted merge — actor, tool, and scope in an Ed25519 envelope your assessor verifies offline.
PyPI SDK ↗Protected branches gate merges before deploy. Copilot, Cursor, and agent tools on main need examiner-ready proof — not policy slides alone.
CI integrationExport ssx360.evidence-pack.v1 JSON with compliance_mappings for FS AI RMF — verify in browser or CLI without trusting SSX360.
Sample packMapped to official FS AI RMF Risk & Control Matrix v1.0 reference IDs for AI-authored code changes — scoped to the SDLC slice, not the full 230 objectives. Full draft mapping · feedback welcome at mission@ssx360.com
| RCM ID | Control theme | SSX360 evidence |
|---|---|---|
| MG-4.1.4 | Change management for AI systems — updates run through structured, documented, trackable processes | Envelope provenance.actor_type, provenance.tool on every agent-assisted merge |
| MG-1.1.2 | Go/No-Go decision criteria — clear thresholds gate whether a change proceeds, pauses, or is rejected | Scroll Gate blocked / review events in ledger |
| GV-1.4.3 | Documentation repository with access controls, kept ready for oversight and audit | Signed evidence pack + detached signature |
| GV-1.6.1 | Inventory of systems/tooling with responsible owners and dependencies tracked | MCP / hook metadata in envelope (declared tool identity) |
| GV-1.6.2 | High-risk / mission-critical systems get enhanced oversight, control, and reporting | financial-infra policy rule outcomes on payments/**, ledger/** |
| GV-1.4.2 | Documentation standards covering monitoring and change-management activity | compliance_mappings[] includes FS AI RMF entry |
| MS-2.1.3 | Centralized, version-controlled, access-controlled repository enabling independent review | matrixscroll verify / browser verifier at ssx360.com/verify |
Voluntary framework guidance for fintech and regulated teams evaluating agent-assisted code change evidence in the United States. Not legal advice; not certification.