A chatbot answers questions. An agent takes actions — across systems, on our data, on behalf of real people. It can only act safely on what we've made explicit. This framework is that map. Without it, agentic AI is unsafe or useless.
Our systems always assumed a person in the loop — someone who knew which system was authoritative and what must never be touched without approval. That knowledge lived in people's heads.
An agent has no such person. It only knows what we've written down — everything else, it guesses. On real students and real money, guessing is not acceptable.
Each of an agent's four hardest questions has an answer in the model. Two come from HERM, one from the model's local extensions, and one from the workflow layer. The model isn't adjacent to AI readiness. It is the foundation for it.
An agent needs a bounded, named set of things it can act on, not free rein. The capability model (BRM), with each system's application and technology placement (ARM, TRM), is that inventory.
When a fact lives in five systems, the agent must know which is authoritative — or it acts on stale data. The data model settles that.
Guardrails exist only if the boundary is written down. Classification and criticality are local extensions, not part of HERM. They tell an agent where to stop and what never to expose.
"Onboard this student" is meaningless without the sequence. Workflows are optional in the base model, but once agents act, they become essential: they are the plans an agent follows and show where a person stays in the loop.
The model tells an agent what exists and where the boundaries are. Safe agentic AI also needs controls that live elsewhere:
Each agent needs its own identity and the least access it needs, granted and revoked like a person's.
A record of what each agent read, changed, and why, kept where it can be reviewed.
Knowing the source of record doesn't make its data accurate. Stewards still have to keep it clean.
Who approves an agent's use, which decisions stay with people, and how exceptions are handled.
For those controls, see the Campus AI Framework, a companion playbook by the same author. It covers AI principles, policy, risk and data governance, roles, maturity assessment, and an AI registry, with alignment to NIST AI RMF and ISO/IEC 42001.
Campus AI Framework ↗To document each AI deployment, see the Campus AI Registry, also by the same author. It pairs with this model directly: any system marked AI-assisted or agentic here should have a system card there, linked to the service cards people see and the model cards behind it. The registry's visibility labels decide what gets published, and its risk profiles for teaching, research, administration, and agentic use add context that this model's classification and recovery tier don't cover.
Campus AI Registry ↗Acts on a picture it inferred, with no source of truth to be checked against.
Has no way to know a record is sensitive or a system is business-critical.
Automates the overlaps and gaps along with everything else — faster.
Leaves no traceable account of what it touched or why.
Reasons over an authoritative model — the source of record is declared, not guessed.
Reads sensitivity and criticality as guardrails before it acts.
Follows mapped workflows, with human checkpoints where they belong.
Has a scoped blast radius — you know what a mistake could reach in advance.
You don't get ready for agentic AI by buying agents. You get ready by mapping the estate they'll act on.
The work in this framework is the foundation of AI readiness. Every dimension recorded here is one an agent can reason over, safely and on your terms. Pair it with the identity, logging, and governance controls above, set out in the Campus AI Framework.