Three grades, written as a vector.
The temptation the entire series has resisted is the scalar — the one agentic maturity number a steering committee can carry into a slide. The alternative is not more numbers; it is the right number of them, kept in the right shape. We call that shape the maturity vector: three components, one per unit, each on its own scale, presented together and never added. Program maturity, agent maturity, fabric maturity — a triple, not a total. The term is ours; the discipline it enforces is the whole point of the series.
A vector is the correct object because it preserves exactly what the scalar destroys: the identity of each component. You can read a vector component by component, compare two estates dimension by dimension, and watch one component move without pretending the others moved with it. None of that survives compression to a single number.
Reading each component
Each component is read on the scale its unit established, and the series has already supplied the rubric for all three.
The program component is read the way its two stewards grade it: OWASP’s deployment-against-governance matrix — is any workflow operating in a red cell — and SANS’s weakest-link capping, which holds the grade down to its weakest pillar. A program component is a defended position, not a self-reported stage.
The agent component is read as earned trust: where each agent sits on CSA’s ladder, from read-only intern upward, and whether the autonomy it holds is covered by an explicit, revocable certificate. This component is rarely a single value — an estate runs many agents at different rungs — so it is read as a distribution, with the least-proven agent holding the most autonomy as the figure that matters.
The fabric component is read by failure signature, because its steward’s meter is unfinished. Against the categories the empirical record supplies — system-design soundness, inter-agent alignment, task verification (Cemri et al., NeurIPS 2025) — and against the interoperability standards NIST is still assembling. A fabric component near the floor is the one most likely to take the estate down, whatever the other two read.
The container fallacy, as standing discipline
The vector has one rule that governs every reading of it: a high component never certifies another component, and never certifies a specific decision inside its own unit. This is the container fallacy the series named early — the organizational grade is a container that does not reach the individual decision — promoted here from a caution to a standing operating rule. A Stage 4 program does not make an unproven agent safe. A flagship agent at the top of the ladder does not make the fabric coordinate. A mature fabric does not retroactively earn an agent its autonomy. The components are read together; they are not allowed to vouch for one another.
This is what makes the vector more than a formatting choice. It is the data structure that holds the independence the series spent four posts establishing. Collapse it, and the independence is lost — the strongest component silently speaks for the weakest, which is the exact failure the single number produces.
What a board does with three numbers
A board does not need to become fluent in three maturity models to use the vector. It needs two habits. The first is to read the components, not the average — there is no average, and the request for one is the request the architect declines. The second is to let the weakest component govern the risk posture. An estate with a strong program, well-earned agents, and a floor-level fabric is a floor-level-fabric estate for the purposes of what can go wrong; the coordination layer is where the empirical failure concentrates, and a high program grade does not buy it down.
Read this way, the vector turns three uncomfortable facts into three actionable ones. A weak program component points at governance work. A skewed agent distribution points at an autonomy grant to revoke. A floor-level fabric component points at the coordination layer to instrument before the next agent is added. The single number pointed at none of them, because it had averaged all three away.
Where the method ends
This post is the method, not the instrument. Reading the vector well in a specific estate — the questions to ask, the evidence to demand for each component, the thresholds that move a component off the floor — is the work of a diagnostic, and a diagnostic assumes the architecture it is run against. That instrument is the subject of a forthcoming companion to this series; it is deliberately held separate, because a checklist published without the architecture behind it becomes a box-ticking exercise of exactly the kind this series argues against.
What the series establishes and the companion will operationalize is one discipline, stated once more: there is no shared zero, there is no single grade, and the deliverable an architect owes is the vector. Three meters. Read all three.
The deliverable is the vector, never the scalar. Report three grades on three scales; let the weakest component govern the risk posture; and treat any high component as certifying only itself — never another unit, and never a specific decision within its own.
When a board asks for the one number, the right answer is not a better number. It is the three.
