← Explore
Risk Assessment

usecase

Risk Assessment

Risk classes that gate what agents may do next

Most risk assessment produces a register that goes stale in a drawer. In CueCrux, the assessment is wired into execution: every plan and work item carries a risk class, and the class has consequences. Low-risk work proceeds on agent authority; high-risk work routes through a human gate that cannot auto-approve past a timeout, with the approval recorded as a signed fact.

The assessments themselves are evidence-backed. When agents evaluate likelihood and impact against regulatory sources, incident histories, and internal records, each entry in the register carries receipts explaining why the risk was identified and how it was scored. A risk committee reviewing the register can drill from any line to its evidence rather than debating adjectives.

Because everything sits on the receipt spine, the register has a live relationship with reality: assessments are dated, attributable, and diffable across review cycles, and the record shows which gated decisions were actually taken under each risk class. Accepted risks are decision records with names attached.

For teams operating under the EU AI Act's risk-management posture, this is Article 9 as running machinery: classification, mitigation through gates, and a hash-chained record that the process operated continuously rather than annually.