Risk owner designation
Every production agent has a designated technical owner and a business owner, documented in an agent registry.
A named individual — not a team or a role queue — is the accountable risk owner for each agent. The risk owner has the documented authority to suspend the agent at any time without further approval, and is the point of contact for HI-AAF assessors during a Letter of Assessment.
Risk owner is recorded in the agent registry with current contact information; the suspend authority has been exercised in at least one drill or live incident; succession is documented.