74%
say AI agents often receive more access than necessary
Cloud Security Alliance, 2026MCV-1 / SSX360 methodology
MCV-1 is SSX360's scoped method for tracing a machine action from stated intent through delegated authority to the resulting record. We report what the evidence supports, what is missing, and what cannot be concluded.

What the mark means
The mark is not issued as a standalone image. Each issued lockup includes a registry ID and URL that resolve to the scope, method version, assessor, dates, status, and signed record.
MCV-1 does not treat a signature as authorization by itself. It checks the full sequence and records the first unsupported link.
01
Decision owner, requested outcome, and source record
02
Permitted systems, constraints, validity, and revocation
03
Observed action, machine identity, target, and result
04
Source register, checksums, signature results, and gaps
74%
say AI agents often receive more access than necessary
Cloud Security Alliance, 202668%
cannot clearly distinguish AI agent activity from human activity
Cloud Security Alliance, 2026$10.22M
average U.S. breach cost in 2025; 97% reporting an AI-related incident lacked proper AI access controls
IBM Cost of a Data Breach Report, 2025Each criterion names the test and the report output. A missing record is a finding, not a reason to infer the intended result.
MCV-1.1
Identify the person or governed system that initiated the request, the intended outcome, and the record that expresses that intent.
Report output
Owner and source record named, or an evidence gap recorded
MCV-1.2
Identify what authority was delegated, which systems and actions it covered, its constraints, validity period, and revocation path.
Report output
Authority boundary reconstructed and exceptions listed
MCV-1.3
Bind the observed machine identity, action, target, and result to the authority record that preceded them. Verify signatures where signed records exist.
Report output
Action linkage supported, contradicted, or not evidenced
MCV-1.4
Check that the authority was valid when the action occurred and that expiry, replay protection, and revocation evidence are available where the system claims them.
Report output
Time and validity findings with source timestamps
MCV-1.5
Reconstruct the sequence across human, service, and machine identities, then identify missing, ambiguous, overwritten, or shared records.
Report output
Sequence map and ranked evidence gaps
MCV-1.6
Export the method version, source register, files, checksums, signature results, findings, and stated limits so another reviewer can repeat the checks.
Report output
Signed report and offline-reviewable evidence package
These mappings identify control evidence that may support a separate review. They are evidence mapping, not a certification claim. Certification under any scheme named here comes from that scheme's own accredited assessors.
Return to the full service list or begin with the scoped MCV-1 inquiry.
Request an MCV-1 scope