Resources · Tools
Tool categories, by layer.
The reference tool categories that fill each layer of the stack, with the examples the Body of Knowledge names. The category is the substance; the brands are illustrative. See how they fit together in the stack.
The five layers
Each category is keyed to the layer it serves. The colour ticks throughout follow this legend.
- L1 Govern-as-Code
- L2 Inventory & Transparency
- L3 Evals & Red Teaming as Evidence
- L4 Runtime Controls & Observability
- L5 Assurance & Continuous Compliance
-
Policy engines
- OPA/Rego
- Cedar
-
Machine-readable policy artefacts (proposed)
- Policy Cards
-
Registries and governance suites
- ServiceNow
- Credo AI
-
Agent-discovery tools
- Zenity
-
AIBOM formats and generators
- CycloneDX ML-BOM
- SPDX 3.0 AI profile
- OWASP AIBOM generator
-
Evaluation frameworks
- Inspect
- promptfoo
- DeepEval
-
Adversarial and vulnerability probes
- Garak
- Mindgard
- Giskard
-
Retrieval-augmented quality
- Ragas
-
Guardrail frameworks
- NVIDIA NeMo Guardrails
- Meta LlamaFirewall
- Lakera
-
Observability
- Langfuse
- Arize Phoenix
- OpenTelemetry
-
Agent workload identity
- SPIFFE/SPIRE
- Microsoft Entra Agent ID
- Okta Agent SSO
-
Evidence format
- OSCAL
-
GRC and AI-governance suites
- Vanta
- Drata
- OneTrust
- watsonx.governance
- Holistic AI
- Saidot