Syntony
Resonance
Public preview Illustrative system Syntonyresearch.ai ↗
AI red-team risk mapping

Resonance

See how an AI failure can move through a customer’s system, then connect the test evidence to controls, owners, decisions, and re-testing.

EvaluateGovernAssure
Illustrative deployment

Customer service agent with retrieval and account tools

The preview is deliberately specific enough to inspect, but uses no customer data, incidents, or measured probabilities.
ObjectiveResolve customer questions and routine account requestsEscalate when identity, policy, or consequence exceeds the agent’s authority.
Privileged accessRead account data; propose CRM and account changesWrite actions require explicit authorization and confirmation.
Critical assetsCustomer data, account state, policy guidanceAlso protects decision integrity and customer trust.
Material changesModel, prompt, corpus, tool, identity, workflowAny can invalidate earlier assurance evidence.
System boundary + threat hypotheses

Customer system and attack-path map

Select a path to trace preconditions, propagation, unsafe outcome, evidence, and the governance response.

Current-state hypothesis before control effectiveness is tested.
P1 · Indirect prompt injection → privileged action Evaluate view · trace the test path and capture points
Illustrative customer service AI system and red-team risk paths A customer service AI system spanning external inputs, channel and identity, model orchestration and retrieval, enterprise tools, and operations and governance. Selecting a risk path highlights how a failure could propagate. CUSTOMER SYSTEM BOUNDARY EXTERNAL CHANNEL + IDENTITY AI EXECUTION ENTERPRISE TOOLS OPERATIONS + GOVERNANCE Customer INTENT + DATA External content UNTRUSTED SOURCE Service channel WEB / CHAT / VOICE Identity context SESSION + AUTH Corpus ingestion PARSE + INDEX Agent orchestrator MODEL + PROMPT + ROUTER Retrieval QUERY + RANK Knowledge base POLICY + GUIDANCE Account API READ + PROPOSE WRITE CRM workflow CASE + RECORD CHANGE Human escalation QUEUE + HANDOFF Evidence store TRACES + CONTROL LOGS Decision + re-test OWNER + TRIGGER PROVENANCE GATE SCOPED TOOL TOKEN STEP-UP CONFIRMATION DIFF + ROLLBACK TRACE REDACTION ESCALATION THRESHOLD P1 UNSAFE OUTCOME: PRIVILEGED ACTION OUTSIDE CUSTOMER INTENT
System dependency Selected risk path Control or governance path
Map lines express testable hypotheses. They do not establish causality or control effectiveness.
The assurance chain

From red-team result to governance action

The chain updates with the selected path. Each link must be explicit for a finding to change how the system is governed.

01 · FindingAttack path changes a privileged action

Trace whether injected content affects tool choice or arguments.

02 · EvidenceMinimum viable packet

Retrieved chunk, provenance, model trace, authorization result, side-effect log.

03 · OwnerNamed decision rights

AI product owner + Product security

04 · ControlClaim to validate

Untrusted content cannot authorize a privileged tool action.

05 · DecisionOperational gate

Keep writes behind confirmation until the control claim passes.

06 · Re-testChange trigger

Re-run after model, router, corpus pipeline, or tool-permission changes.

Prioritized test register

Six paths through one system

This is a scoped starting set, not an exhaustive taxonomy. A real engagement adds paths from architecture review, threat intelligence, incidents, stakeholder concerns, and observed behavior.

PathUnsafe outcomePriority lensControl evidenceDecision gateAccountable owners
How Resonance is used

A model that stays attached to evidence

System mapping is useful only when it sharpens testing and survives contact with operational decision-making.

ScopeBound the system

Identify actors, assets, trust boundaries, dependencies, privileged actions, and the system changes that matter.

TestMake risk falsifiable

Express each concern as an attack path with preconditions, a test sequence, an unsafe outcome, and required evidence.

DecideConnect control claims

Link findings to the owner with authority, the control claim being relied on, and the decision the evidence should change.

MaintainDefine assurance triggers

Record residual uncertainty and re-run the relevant tests when models, prompts, tools, data, permissions, or workflows change.

Resonance for a real system

Map the paths that matter before the next evaluation.

A client engagement replaces this illustrative model with your architecture, threat hypotheses, evidence sources, controls, owners, and review cadence.

Discuss a system