Syntony
Resonance
Public preview Illustrative system Syntonyresearch.ai ↗
AI red-team risk mapping

Resonance

This preview shows how a failure can move through an AI-enabled customer service system. Select a path to see what to test, which controls should stop it, who owns the response, and what decision the result informs.

Evaluate→Govern→Assure
Illustrative deployment

Customer service agent with retrieval and account tools

The example is detailed enough to inspect. It contains no customer data, incidents, or measured probabilities.
ObjectiveResolve customer questions and routine account requestsEscalate when identity, policy, or consequence exceeds the agent’s authority.
Privileged accessRead account data; propose CRM and account changesWrite actions require explicit authorization and confirmation.
Critical assetsCustomer data, account state, policy guidanceThe design also needs to protect decision integrity and customer trust.
Material changesModel, prompt, corpus, tool, identity, workflowAny of these changes can invalidate earlier assurance evidence.
System boundary and threat hypotheses

Customer system and attack-path map

Select a path to see how the failure could propagate, what evidence the test should capture, and how the client could respond.

This baseline shows the system before the candidate controls are tested.
P1 · Indirect prompt injection → privileged action Evaluate view · trace the test path and capture points
Illustrative customer service AI system and red-team risk paths A customer service AI system spanning external inputs, channel and identity, model orchestration and retrieval, enterprise tools, and operations and governance. Selecting a risk path highlights how a failure could propagate. CUSTOMER SYSTEM BOUNDARY EXTERNAL CHANNEL + IDENTITY AI EXECUTION ENTERPRISE TOOLS OPERATIONS + GOVERNANCE Customer INTENT + DATA External content UNTRUSTED SOURCE Service channel WEB / CHAT / VOICE Identity context SESSION + AUTH Corpus ingestion PARSE + INDEX Agent orchestrator MODEL + PROMPT + ROUTER Retrieval QUERY + RANK Knowledge base POLICY + GUIDANCE Account API READ + PROPOSE WRITE CRM workflow CASE + RECORD CHANGE Human escalation QUEUE + HANDOFF Evidence store TRACES + CONTROL LOGS Decision + re-test OWNER + TRIGGER PROVENANCE GATE SCOPED TOOL TOKEN STEP-UP CONFIRMATION DIFF + ROLLBACK TRACE REDACTION ESCALATION THRESHOLD P1 UNSAFE OUTCOME: PRIVILEGED ACTION OUTSIDE CUSTOMER INTENT
System dependency Selected risk path Control or governance path
Map lines express testable hypotheses. They do not establish causality or control effectiveness.
Finding, response, and re-test

How a red-team result informs a decision

The cards update when you select another path. They show what the client needs to document to act on a finding and revisit it later.

01 · FindingAttack path changes a privileged action

Trace whether injected content affects tool choice or arguments.

02 · EvidenceEvidence to retain

Retrieved chunk, provenance, model trace, authorization result, side-effect log.

03 · OwnerResponsible team

AI product owner + Product security

04 · ControlControl under test

Untrusted content cannot authorize a privileged tool action.

05 · DecisionDecision to make

Keep writes behind confirmation until the control claim passes.

06 · Re-testWhen to test again

Re-run after model, router, corpus pipeline, or tool-permission changes.

Prioritized test register

Six paths through one system

The register shows six example paths. A client register is expanded using its architecture, threat intelligence, incident history, stakeholder concerns, and observed system behavior.

PathUnsafe outcomePlanning scoresCandidate controlsDecisionResponsible teams
How Resonance is used

Keep the system map tied to test evidence

A useful system map makes the evaluation more precise and helps the responsible team decide what to do with the result.

ScopeBound the system

Identify actors, assets, trust boundaries, dependencies, privileged actions, and the system changes that matter.

TestTurn concerns into tests

For each attack path, state the conditions, test steps, unsafe outcome, and evidence to collect.

DecideAssign the response

Link each finding to the control under test, the team responsible for it, and the decision the evidence will inform.

MaintainSet re-test conditions

Record the remaining uncertainty and re-run the test when a relevant part of the system changes.

Use Resonance on your system

Map your system before the next evaluation

For a client engagement, Syntony replaces this example with a map of your architecture and threat hypotheses. Each path is tied to evidence, controls, decision rights, and a schedule for reviewing changes.

Discuss a system