Validator Control Panel

Independent checkpoints — not normal agents.

Validators are independent nodes. They do not produce business answers — they verify the work of crews and agents, decide whether rework is needed, and gate human approval.

Core Validators

9
Schema Validator
Pass
Checks
  • Output completeness
  • Required fields present
  • Correct structure
Auto-pass
Tool Permission Validator
Pass
Checks
  • Only allowed tools used
  • No restricted APIs called
Auto-pass
Best-Practice Validator
Warning
Checks
  • CVD / Well-Architected alignment
  • Reference pattern followed
Error
Landing zone OU structure not aligned with reference
Rework
Risk Validator
Pass
Checks
  • Risks classified Low/Med/High
  • High-risk items flagged
Auto-pass
Confidence Validator
Warning
Checks
  • Confidence ≥ threshold (0.75)
  • Assumptions stated
Error
FinOps confidence 0.68 < 0.75
Rework
Human Approval Validator
Pass
Checks
  • Human approval gates respected
  • No auto-commit on high-risk
Human approval
Commercial Commitment Validator
Fail
Checks
  • No final pricing without Finance + MD
  • No discount > policy
Error
Pre-Sales attempted to commit final BoM price
ReworkEscalateHuman approval
Security Exception Validator
Pass
Checks
  • No unapproved exceptions
  • CISO sign-off recorded
Auto-pass
Legal Clause Validator
Warning
Checks
  • Non-standard clauses flagged
  • Fallback wording proposed
Error
Liability cap below standard floor
EscalateHuman approval

Cloud Validators

5
AWS Well-Architected Validator
Warning
Checks
  • 5-pillar coverage
  • Reference pattern alignment
Rework
Landing Zone Validator
Pass
Checks
  • OU structure
  • Guardrails enforced
  • Identity baseline
Auto-pass
Migration Readiness Validator
Pass
Checks
  • 6Rs assessment present
  • Wave plan + rollback
Auto-pass
FinOps Validator
Warning
Checks
  • Tag policy enforced
  • RI/SP coverage modelled
  • Anomaly alerts
Rework
Cloud-Ops Readiness Validator
Pass
Checks
  • Monitoring scope
  • Runbooks exist
  • On-call rota
Auto-pass

Software Validators

4
Software Architecture Validator
Pass
Checks
  • Module decomposition
  • Bounded contexts
Auto-pass
API Integration Validator
Pass
Checks
  • Contract present
  • Versioning + idempotency
Auto-pass
NFR Validator
Warning
Checks
  • Latency / throughput / availability budgets
Rework
Delivery Estimate Validator
Pass
Checks
  • Assumptions stated
  • Risk-adjusted estimate
Auto-pass

AI/Data Validators

6
RAG Grounding Validator
Warning
Checks
  • Citations present
  • No ungrounded answers
Rework
Data Source Validator
Pass
Checks
  • Source-of-truth identified
  • Freshness window
Auto-pass
Model Selection Validator
Pass
Checks
  • Cost / quality / latency rationale
Auto-pass
Guardrails Validator
Warning
Checks
  • PII redaction
  • Prompt-injection defenses
Rework
Token Cost Validator
Pass
Checks
  • Token projection
  • Caching strategy
Auto-pass
Evaluation Plan Validator
Pass
Checks
  • Eval set defined
  • Metrics + thresholds
Auto-pass

Security Validators

6
Zero Trust Validator
Pass
Checks
  • Identity-aware access
  • No implicit trust
Auto-pass
IAM/PAM Validator
Warning
Checks
  • Least privilege
  • JIT access
Rework
SOC/SIEM Validator
Pass
Checks
  • Centralised logging
  • Detections in place
Auto-pass
Compliance Mapping Validator
Warning
Checks
  • ISO/SOC2/GDPR mapping
Rework
Vulnerability Risk Validator
Pass
Checks
  • SAST/DAST coverage
  • Critical CVE remediation
Auto-pass
Data Privacy Validator
Warning
Checks
  • Data classification
  • DPIA where required
Rework

Rework Loop visualization

  1. 1 Cloud Crew produces architecture + landing zone
  2. 2 Security Validator flags missing private endpoints
  3. 3 Rework routed back to Cloud Crew AND Security Crew
  4. 4 Updated recommendation generated with controls
  5. 5 Validator runs again → Pass
  6. 6 Approval Router decides next step

Agent Inclusion / Exclusion logic

Request: "Design AWS-based RAG assistant integrated with CRM."
Included
AI / Data CrewAI architecture and RAG design required
Cloud CrewAWS hosting and landing zone required
Software CrewCRM integration and APIs required
Security CrewData privacy and access control required
Optional
Legal AgentCustomer data and privacy terms may be involved
Finance AgentCost estimate may be requested
Excluded
Cisco CrewNo Cisco / network requirement detected
HR AgentNo HR process involved
Triggers
Mentions 'data privacy' → include Security Crew
Mentions 'AWS' → include Cloud Crew
Mentions 'CRM' → include Software Crew
Escalation
Risk = High → MD approval
Confidence < 0.75 → Coordinator rework
Unapproved security exception → CISO