HiveCraft

How the model is shaped

Four groups, thirteen dimensions, plain language first.

The model splits concerns into operational, knowledge, risk, and outcome groups so single-axis claims cannot stand in for the whole picture. Below: a short overview, and the technical detail behind it on demand.

Why a structured model?

Single-number maturity claims invite over-statement. The model splits concerns into four groups, asks for minimum coverage in each, and stays cross-walked to standards your auditors already know. The visitor sees plain phrasing first; the structural detail lives behind a single toggle.

What follows is the everyday-language version. The technical layer is one click away.

Show the technical detail behind this

Structure at a glance

Groups
4
Dimensions
13
Categories
38
Items
99
Levels
6
Hive-Types
9

Group A

Operational

Day-to-day discipline of running an agentic-software-development practice — the engineering hygiene that keeps the hive accountable, repeatable, and recoverable.

L4 group-floor required to claim L4+ overall

D1 · Group A Operational

Versioning & Reproducibility

7 items

Reproducible builds, prompt/code/model version-pinning, deterministic re-runs, and artifact lineage.

3 categories · Indicative cross-walk: ISO 27001:2022 A.8.32, NIST SSDF PO.3, CMMI CM

D2 · Group A Operational

Observability & Telemetry

8 items

Run-level traces, agent invocation logs, cost / latency / quality metrics, and live drift signals.

3 categories · Indicative cross-walk: NIST CSF 2.0 DE.CM, SPACE framework, MLOps maturity (level 2+)

D3 · Group A Operational

Continuous Integration

6 items

Automated test gates, prompt regression suites, eval-on-commit, and merge protections.

2 categories · Indicative cross-walk: NIST SSDF PW.7, CMMI PR

D4 · Group A Operational

Deployment & Release

8 items

Progressive rollout, blue/green or canary release, rollback playbooks, and deployment audit trails.

3 categories · Indicative cross-walk: ISO 27001:2022 A.8.31, NIST SP 800-53 CM-3, MLOps maturity

Group B

Knowledge

How the hive captures, validates, and propagates knowledge across humans and agents — KB curation, lessons, retrievability, and onboarding semantics.

L3 group-floor required to claim L4+ overall

D5 · Group B Knowledge

KB Curation & Lessons

8 items

KB section discipline, lessons capture, deprecation hygiene, and read-tracking discipline.

3 categories · Indicative cross-walk: ISO 9001 7.1.6, COBIT 2019 BAI08

D6 · Group B Knowledge

Retrieval & Grounding

8 items

Retrieval quality, grounding traceability, citation discipline, and hallucination-control evidence.

3 categories · Indicative cross-walk: NIST AI RMF 1.0 (MAP/MEASURE), ISO/IEC 25010

D7 · Group B Knowledge

Onboarding & Pedagogy

9 items

Stakeholder onboarding, agent-orientation paths, role-based training, and pedagogy evidence.

3 categories · Indicative cross-walk: ISO 9001 7.2, CMMI OT

Group C

Risk

How the hive manages security, regulatory, ethical, and operational risk — drift, red-teaming, jurisdictional obligations, and AI disclosure.

L4 group-floor required to claim L4+ overall

D8 · Group C Risk

Security & Hardening

7 items

Secret hygiene, supply-chain security, agent permission scoping, and hardening drift detection.

2 categories · Indicative cross-walk: ISO 27001:2022 A.5/A.8, NIST CSF 2.0 PR.AA, PCI DSS, CIS Benchmarks

D9 · Group C Risk

Compliance & Jurisdiction

10 items

GDPR, EU AI Act, sector-specific regimes, jurisdiction-obligation registry, and DPIA evidence.

4 categories · Indicative cross-walk: GDPR Art. 6/7/13/14/30/32, EU AI Act Art. 9/15/16/26/50, ISO 27701, ISO 42001

D10 · Group C Risk

Risk Register & Tabletops

8 items

Active risk register, scheduled red-team exercises, tabletop simulations, and post-mortem feedback.

3 categories · Indicative cross-walk: ISO 31000, ISO 22301, NIST CSF 2.0 ID.RA, MITRE ATT&CK Navigator

D11 · Group C Risk

AI Disclosure & Transparency

7 items

Public AI-disclosure artifacts, decision-explainability, model cards, and use-case transparency.

2 categories · Indicative cross-walk: EU AI Act Art. 50, NIST AI RMF (GOVERN), Microsoft RAI MM

Group D

Outcome

Outcomes the practice produces for stakeholders: deliverable acceptance, customer feedback loops, business-level impact.

L3 group-floor required to claim L4+ overall

D12 · Group D Outcome

Deliverable Acceptance

5 items

Stakeholder-acknowledged acceptance of deliverables, signed sign-offs, and rejection-rate tracking.

3 categories · Indicative cross-walk: ISO 9001 8.6, CMMI VV

D13 · Group D Outcome

Stakeholder Outcomes

9 items

Customer-impact metrics, business-value tracking, stakeholder feedback loops, and outcome-based KPIs.

4 categories · Indicative cross-walk: SOC 2 (CC), SPACE framework, CMMI OPP

Browse individual dimensions.

Each dimension has its own short summary, with the deeper category and item-count detail behind a disclosure-toggle on the dimensions page.