Complete reference for everything Rivaro detects: 8 risk domains, 17 risk categories, 80+ detection types, severity levels, lifecycle stages, and data classifications.
Detection Taxonomy
Every detection is classified along four dimensions:
| Dimension | What it answers | Values |
|---|
| Risk Domain | What area of risk? | 8 domains |
| Risk Category | What specific risk pattern? | 17 categories |
| Detection Type | What exactly was found? | 80+ types |
| Severity | How serious? | LOW, MEDIUM, HIGH, CRITICAL |
Additionally, detections are tagged with:
| Dimension | What it answers | Values |
|---|
| Lifecycle | Where in the data flow? | INGRESS, EGRESS, DEPLOYMENT, TRAINING |
| Data Classification | What kind of data? | PII, PHI, FINANCIAL, CREDENTIALS, INTELLECTUAL_PROPERTY, NONE |
Risk Domains
Risk domains are the highest-level grouping — eight areas of AI risk. They align with NIST AI RMF and the EU AI Act's distinction between safety, fundamental rights, and cybersecurity.
DATA_PROTECTION
Data Protection Risk — Unauthorized access, exposure, or movement of sensitive data. The most common risk domain. Covers PII, PHI, financial data, credentials, and any sensitive information flowing through AI systems.
SYSTEM_INTEGRITY
System Integrity Risk — Unauthorized modification of infrastructure, configurations, or production systems. Covers agents making unauthorized changes: shell commands, database writes, file modifications, infrastructure misconfigurations.
AUTONOMOUS_ACTION
Autonomous Action Risk — High-impact state transitions executed without appropriate control. Covers AI-initiated financial actions (refunds, payouts, transfers, charges, subscription changes), irreversible decisions (account closures, contract execution), and actions that should require human approval.
IDENTITY_TRUST
Identity & Trust Boundary Risk — Agents operating outside declared roles, scopes, or trust boundaries. Covers role escalation, agents acting outside their intended scope, and unapproved external communications.
ADVERSARIAL
Adversarial Manipulation Risk — External inputs altering agent behavior or bypassing controls. Covers prompt injection, jailbreaks, policy evasion attempts, supply-chain tool drift, context-integrity tampering, and any technique designed to manipulate the AI system.
CONTENT_SAFETY
Content Safety Risk — Violations of safety guidelines, content policies, or ethical boundaries, regardless of intent. Covers toxic content, hate speech, harmful instructions, bias, and self-harm content — whether generated or ingested.
GOVERNANCE
Governance & Shadow Risk — AI usage occurring outside approved or monitored infrastructure. Covers shadow AI bots, unregistered models, hardcoded API keys in source, MCP servers without authentication, agents with unrestricted execution.
REGULATED_OUTPUT_GOVERNANCE
Regulated Output Governance Risk — AI-authored regulated documents that fail structural, evidentiary, scope, or provenance conformance. Covers documents the AI produces that would fail an auditor's review — missing required fields, format violations, cross-field inconsistency, unsupported assertions, scope overreach, and unattested field provenance. This is the document-conformance toolkit (AAA) surface.
Risk Categories
Each risk domain contains specific risk categories (17 total). Risk categories are the stable governance layer — detection types map into them but the categories themselves change rarely.
Data Protection
| Category | Description | Lifecycle |
|---|
EXTERNAL_DATA_EXFILTRATION | Sensitive data leaving approved boundaries via external tools, APIs, or channels | EGRESS, TRAINING |
SENSITIVE_DATA_BOUNDARY_VIOLATION | Data accessed outside intended domain, role, or dataset scope | INGRESS, EGRESS |
CROSS_AGENT_DATA_LEAKAGE | Improper data passing between agents or models without guardrails | INGRESS, EGRESS |
System Integrity
| Category | Description | Lifecycle |
|---|
UNAUTHORIZED_SYSTEM_MODIFICATION | Changes to production systems, CI/CD, configs, or repos without approval | EGRESS |
PRIVILEGED_TOOL_MISUSE | High-impact tools (shell, DB write, admin APIs, persistence mechanisms) invoked outside allowed scope | EGRESS |
INFRASTRUCTURE_MISCONFIGURATION | Cloud or system security misconfigurations detected during discovery (state findings, not action events) | DEPLOYMENT |
OPERATIONAL_ANOMALY | Rate limits exceeded, resource abuse, behavioral drift, availability threats | INGRESS, EGRESS |
Autonomous Action
| Category | Description | Lifecycle |
|---|
AUTONOMOUS_FINANCIAL_ACTION | AI-initiated financial movement (payment rails, token transfer, treasury API, refunds, payouts, transfers, charges, subscription changes) | EGRESS |
HIGH_RISK_AUTONOMOUS_DECISION | Irreversible state transition without human approval (contract, account closure, infrastructure shutdown, constitution violation) | EGRESS |
Identity & Trust
| Category | Description | Lifecycle |
|---|
IDENTITY_ROLE_ESCALATION | Agent acting outside assigned persona, scope, or declared capabilities | INGRESS, EGRESS |
UNAPPROVED_EXTERNAL_COMMUNICATION | Data sent externally without policy alignment (Slack, email, webhook, third-party API, web fetch/search/browse, messaging tools) | EGRESS |
Adversarial
| Category | Description | Lifecycle |
|---|
PROMPT_INJECTION_EXPLOIT | Agent behavior altered by malicious or untrusted input (system prompt override, RAG manipulation, instruction hijack, novel attack patterns) | INGRESS |
POLICY_EVASION_ATTEMPT | Deliberate attempt to bypass controls (encoding, fragmentation, retry loops, tool chaining, supply-chain drift, context-integrity tampering, decision bypass) | INGRESS, EGRESS |
Content Safety
| Category | Description | Lifecycle |
|---|
AI_SAFETY_VIOLATION | Toxic content, hate speech, bias, self-harm encouragement, or harmful content generated or ingested by the AI | INGRESS, EGRESS |
Governance
| Category | Description | Lifecycle |
|---|
UNREGISTERED_SHADOW_AI | AI activity outside approved adapters, agents, or infrastructure (shadow bots, hardcoded keys, public AI repos, no-auth MCP servers, unrestricted-execution agents) | DEPLOYMENT |
Regulated Output Governance
| Category | Description | Lifecycle |
|---|
REGULATED_ARTIFACT_NONCONFORMANCE | AI-authored or AI-ingested regulated documents fail structural, enum, cross-field, evidence, or scope conformance against the bound schema | INGRESS, EGRESS |
REGULATED_OUTPUT_PROVENANCE_VIOLATION | AI-authored regulated document field cannot be tied to an attested ActionRecord-backed source — fabricated or unattested provenance | EGRESS |
Detection Types
Detection types are the most granular level — the specific thing that was found. Each detection type carries:
- A default risk category — which governance object it rolls up to (some types remap per lifecycle inside
ViolationManagementService)
- A data classification — what kind of data is involved (or
NONE if not data-related)
- An optional capability surface — for agent actions (e.g.
EXECUTE_SYSTEM, INITIATE_PAYMENT)
- An optional boundary surface — for boundary detections (e.g.
INJECTION_DEFENSE, EXFILTRATION_DEFENSE)
Default category: SENSITIVE_DATA_BOUNDARY_VIOLATION · Data classification: PII
| Type | What it catches |
|---|
PII_EMAIL | Email addresses |
PII_SSN | Social Security numbers |
PII_PHONE | Phone numbers |
PII_ADDRESS | Physical addresses |
PII_DATE_OF_BIRTH | Dates of birth |
PII_FULL_NAME | Full names |
PII_DRIVERS_LICENSE | Driver's license numbers |
PII_PASSPORT | Passport numbers |
PII_CREDIT_CARD | Credit card numbers |
Default category: SENSITIVE_DATA_BOUNDARY_VIOLATION · Data classification: PHI
| Type | What it catches |
|---|
PHI_MEDICAL_RECORD | Medical record numbers |
PHI_HEALTH_INSURANCE | Health insurance IDs |
PHI_PRESCRIPTION | Prescription information |
PHI_DIAGNOSIS | Medical diagnoses |
PHI_TREATMENT | Treatment details |
Financial Data
Default category: SENSITIVE_DATA_BOUNDARY_VIOLATION · Data classification: FINANCIAL
| Type | What it catches |
|---|
FINANCIAL_BANK_ACCOUNT | Bank account numbers |
FINANCIAL_ROUTING | Routing numbers |
FINANCIAL_INVESTMENT | Investment account details |
FINANCIAL_TAX_ID | Tax identification numbers |
Credentials & Secrets
Default category: SENSITIVE_DATA_BOUNDARY_VIOLATION · Data classification: CREDENTIALS
| Type | What it catches |
|---|
CREDENTIALS_API_KEY | API keys |
CREDENTIALS_PASSWORD | Passwords |
CREDENTIALS_TOKEN | Authentication tokens |
CREDENTIALS_SSH_KEY | SSH keys |
CREDENTIALS_AWS_KEY | AWS access keys |
Intellectual Property
Default category: SENSITIVE_DATA_BOUNDARY_VIOLATION · Data classification: INTELLECTUAL_PROPERTY
| Type | What it catches |
|---|
IP_TRADEMARK | Trademark content |
IP_COPYRIGHT | Copyrighted material |
IP_PATENT | Patent information |
IP_TRADE_SECRET | Trade secrets |
Adversarial / Security
| Type | Default category | What it catches |
|---|
SECURITY_PROMPT_INJECTION | PROMPT_INJECTION_EXPLOIT | Prompt injection attacks (boundary: INJECTION_DEFENSE) |
SECURITY_JAILBREAK | PROMPT_INJECTION_EXPLOIT | Jailbreak attempts (boundary: INJECTION_DEFENSE) |
SECURITY_AUTHENTICATION_BYPASS | PROMPT_INJECTION_EXPLOIT | Authentication bypass (boundary: AUTH_BOUNDARY) |
SECURITY_RESOURCE_ABUSE | POLICY_EVASION_ATTEMPT | Resource abuse patterns (boundary: RESOURCE_BOUNDARY) |
SECURITY_FINANCIAL_FRAUD | POLICY_EVASION_ATTEMPT | Financial fraud patterns (boundary: FRAUD_THRESHOLD) |
SECURITY_DECISION_BYPASS | POLICY_EVASION_ATTEMPT | Decision bypass — unmatched tool result (boundary: AUTH_BOUNDARY) |
SUPPLY_CHAIN_TOOL_DRIFT | POLICY_EVASION_ATTEMPT | Tool schema drift (supply-chain compromise) |
CONTEXT_INTEGRITY_VIOLATION | POLICY_EVASION_ATTEMPT | Context integrity violation (tampered session context) |
BEHAVIORAL_NOVEL_ATTACK_PATTERN | PROMPT_INJECTION_EXPLOIT | Previously unseen attack patterns |
BEHAVIORAL_ATTACK_CHAIN | POLICY_EVASION_ATTEMPT | Coordinated attack patterns across multiple turns |
BEHAVIORAL_INTENT_DRIFT | POLICY_EVASION_ATTEMPT | Declining alignment trend over a session |
Data Exfiltration
| Type | Default category | What it catches |
|---|
SECURITY_DATA_EXFILTRATION | EXTERNAL_DATA_EXFILTRATION | Explicit exfiltration patterns (boundary: EXFILTRATION_DEFENSE) |
SECURITY_DLP_BYPASS | EXTERNAL_DATA_EXFILTRATION | DLP bypass attempts |
SECURITY_SYSTEM_INPUT_LEAKAGE | EXTERNAL_DATA_EXFILTRATION | System prompt or input leakage |
MULTI_AGENT_COORDINATED_EXFIL | EXTERNAL_DATA_EXFILTRATION | Multi-agent coordinated data exfiltration |
Multi-Agent Risk
| Type | Default category | What it catches |
|---|
MULTI_AGENT_COORDINATED_EXFIL | EXTERNAL_DATA_EXFILTRATION | Multi-agent coordinated exfiltration |
MULTI_AGENT_PRIVILEGE_RELAY | PRIVILEGED_TOOL_MISUSE | Privilege relay between agents (one agent acting on another's behalf to escalate) |
Content Safety
Default category: AI_SAFETY_VIOLATION
| Type | What it catches |
|---|
SECURITY_TOXIC_CONTENT | Toxic or harmful content (boundary: CONTENT_SAFETY) |
SECURITY_HARMFUL_INSTRUCTIONS | Instructions for harmful activities |
Default category: PRIVILEGED_TOOL_MISUSE
| Type | What it catches |
|---|
AGENT_TOOL_SHELL_EXEC | Shell command execution |
AGENT_TOOL_FILE_DELETE | File deletion |
AGENT_TOOL_DATABASE_WRITE | Database write operations |
AGENT_TOOL_DATABASE_QUERY | Database queries |
AGENT_TOOL_CODE_EDIT | Code modifications |
AGENT_TOOL_MCP | MCP tool invocations |
Default category: PRIVILEGED_TOOL_MISUSE · Default action: BLOCK (always high-risk)
| Type | What it catches |
|---|
AGENT_TOOL_PERSISTENCE_SHELL | Shell-level persistence (cron, systemd, init.d) |
AGENT_TOOL_PERSISTENCE_FILE | File-level persistence (startup scripts, rc files) |
AGENT_TOOL_PERSISTENCE_WEBHOOK | Webhook/callback persistence |
| Type | Default category |
|---|
AGENT_TOOL_FILE_WRITE | UNAUTHORIZED_SYSTEM_MODIFICATION |
Default category: UNAPPROVED_EXTERNAL_COMMUNICATION
| Type | What it catches |
|---|
AGENT_TOOL_MESSAGING | Slack/email/SMS messaging tool calls |
AGENT_TOOL_WEB_FETCH | HTTP fetch operations (default ALLOW) |
AGENT_TOOL_WEB_SEARCH | Web search (default ALLOW) |
AGENT_TOOL_WEB_BROWSE | Web browsing (default ALLOW) |
Default category: AUTONOMOUS_FINANCIAL_ACTION · Data classification: FINANCIAL
| Type | What it catches |
|---|
AGENT_TOOL_FINANCIAL_REFUND | Refund issued to a customer |
AGENT_TOOL_FINANCIAL_PAYOUT | Payout to a recipient |
AGENT_TOOL_FINANCIAL_TRANSFER | Funds transfer |
AGENT_TOOL_FINANCIAL_CHARGE | Charge to a customer |
AGENT_TOOL_FINANCIAL_SUBSCRIPTION | Subscription modification |
These types pair with BEHAVIORAL_VELOCITY_FINANCIAL and BEHAVIORAL_VELOCITY_FINANCIAL_COUNT for cumulative-threshold monitoring. The FINANCIAL policy template uses RISK_ADAPTIVE actions for these — see Risk-Adaptive Policy.
| Type | Default category |
|---|
AGENT_TOOL_CALL | OPERATIONAL_ANOMALY |
AGENT_TOOL_FILE_READ | SENSITIVE_DATA_BOUNDARY_VIOLATION |
AGENT_TOOL_FILE_LIST | SENSITIVE_DATA_BOUNDARY_VIOLATION |
AGENT_TOOL_CODE_SEARCH | SENSITIVE_DATA_BOUNDARY_VIOLATION |
Behavioral
| Type | Default category | What it catches |
|---|
BEHAVIORAL_LATENCY_DRIFT | OPERATIONAL_ANOMALY | Unusual latency patterns |
BEHAVIORAL_TOKEN_DRIFT | OPERATIONAL_ANOMALY | Unusual token usage patterns |
BEHAVIORAL_RESPONSE_LENGTH_DRIFT | OPERATIONAL_ANOMALY | Response length anomalies |
BEHAVIORAL_RATE_LIMIT_EXCEEDED | OPERATIONAL_ANOMALY | Rate limit violations (behavioral) |
BEHAVIORAL_VOLUME_SPIKE | OPERATIONAL_ANOMALY | Unusual request volume |
BEHAVIORAL_ACTOR_QUARANTINED_ACCESS | OPERATIONAL_ANOMALY | Quarantined actor attempting access (behavioral) |
BEHAVIORAL_ACTOR_TERMINATED_ACCESS | OPERATIONAL_ANOMALY | Terminated actor attempting access (behavioral) |
BEHAVIORAL_ACTION_PARAMETER_ANOMALY | OPERATIONAL_ANOMALY | Unusual values for action parameters |
BEHAVIORAL_ACTION_FINANCIAL_ANOMALY | AUTONOMOUS_FINANCIAL_ACTION | Anomalous financial action parameters (e.g. unusually large refund) |
BEHAVIORAL_VELOCITY_FINANCIAL | AUTONOMOUS_FINANCIAL_ACTION | Cumulative financial amount over a window (boundary: FINANCIAL_VELOCITY) |
BEHAVIORAL_VELOCITY_FINANCIAL_COUNT | AUTONOMOUS_FINANCIAL_ACTION | Cumulative financial-action count over a window |
BEHAVIORAL_CONSTITUTION_VIOLATION | HIGH_RISK_AUTONOMOUS_DECISION | Action violates the agent's constitution (judge-based) |
BEHAVIORAL_TOOL_ABUSE | PRIVILEGED_TOOL_MISUSE | Repeated or escalating tool use |
System
Default category: OPERATIONAL_ANOMALY
| Type | What it catches |
|---|
SYSTEM_RATE_LIMIT_EXCEEDED | System-level rate limit hit |
SYSTEM_CONCURRENT_LIMIT_EXCEEDED | Concurrent request limit |
SYSTEM_PAYLOAD_SIZE_EXCEEDED | Payload too large |
SYSTEM_ACTOR_QUARANTINED_ACCESS | Quarantined actor attempting access (system) |
SYSTEM_ACTOR_TERMINATED_ACCESS | Terminated actor attempting access (system) |
SYSTEM_INVALID_KEY | Invalid detection key used |
SYSTEM_ORG_SUSPENDED | Suspended org attempting access |
Infrastructure / Shadow AI
Default category: UNREGISTERED_SHADOW_AI · Surfaced via Discovery
| Type | Data classification | What it catches |
|---|
INFRASTRUCTURE_SHADOW_AI_BOT | NONE | Unapproved AI bot/plugin in collaboration apps |
INFRASTRUCTURE_AI_BOT_EXCESSIVE_ACCESS | NONE | AI bot with excessive channel/scope access |
INFRASTRUCTURE_HARDCODED_AI_KEY | CREDENTIALS | Hardcoded AI API key in source code |
INFRASTRUCTURE_PUBLIC_AI_REPO | NONE | Public repository containing AI code |
INFRASTRUCTURE_AI_KEY_IN_HISTORY | CREDENTIALS | AI API key found in git history |
INFRASTRUCTURE_MCP_NO_AUTH | NONE | MCP server without authentication |
INFRASTRUCTURE_AGENT_UNRESTRICTED_EXECUTION | NONE | AI agent configured with unrestricted execution |
Infrastructure Misconfiguration
Default category: INFRASTRUCTURE_MISCONFIGURATION · Surfaced via Discovery
| Type | What it catches |
|---|
INFRASTRUCTURE_MCP_PUBLIC_ENDPOINT | MCP server exposed on a public endpoint |
Schema-driven criterion classes. Per-schema specifics travel in Detection.runtimeAttributes (schema_id, field_path, rule_id, etc.).
| Type | Default category | What it catches |
|---|
DOCUMENT_REQUIRED_FIELD_MISSING | REGULATED_ARTIFACT_NONCONFORMANCE | Required field missing from a regulated document |
DOCUMENT_FIELD_FORMAT_VIOLATION | REGULATED_ARTIFACT_NONCONFORMANCE | Field value does not match schema format/enum |
DOCUMENT_CROSS_FIELD_INCONSISTENCY | REGULATED_ARTIFACT_NONCONFORMANCE | Two fields contradict each other |
DOCUMENT_UNSUPPORTED_ASSERTION | REGULATED_ARTIFACT_NONCONFORMANCE | Assertion lacks required evidence |
DOCUMENT_SCOPE_OVERREACH | REGULATED_ARTIFACT_NONCONFORMANCE | References a value outside the bound catalog |
DOCUMENT_UNATTESTED_FIELD_PROVENANCE | REGULATED_OUTPUT_PROVENANCE_VIOLATION | Field cannot be tied to an attested ActionRecord-backed source |
Fallback
| Type | Default category | What it catches |
|---|
CUSTOM_UNKNOWN | OPERATIONAL_ANOMALY | Unknown or unclassified detection |
Severity Levels
| Level | Meaning | Examples |
|---|
| LOW | Minor finding, informational | Email address detected, file read operation |
| MEDIUM | Notable finding, may require attention | Phone number detected, database query, web fetch |
| HIGH | Significant risk, likely needs action | SSN detected, shell execution, prompt injection |
| CRITICAL | Severe risk, immediate action needed | Credential exfiltration, jailbreak, attack chain, persistence mechanism, multi-agent coordinated exfil |
Lifecycle Stages
| Stage | When | What's scanned |
|---|
| INGRESS | Before the request is sent to the AI provider | User/agent prompts, input content |
| EGRESS | After the AI provider responds | AI responses, tool call results, agent actions |
| DEPLOYMENT | During infrastructure scanning | Cloud configs, model registrations, shadow AI |
| TRAINING | During training data pipelines | Training data, fine-tuning inputs |
Most enforcement happens at INGRESS (block bad inputs) and EGRESS (catch sensitive data and risky actions in outputs). DEPLOYMENT and TRAINING are primarily for discovery and compliance scanning.
Data Classifications
| Classification | Description | Sensitive |
|---|
| PII | Personally Identifiable Information — SSN, email, phone, name, DOB, drivers license, passport, credit card | Yes |
| PHI | Protected Health Information — medical records, insurance, prescriptions, diagnoses, treatments | Yes |
| FINANCIAL | Financial Data — bank accounts, routing numbers, investment accounts, tax IDs, plus financial action types | Yes |
| CREDENTIALS | Credentials & Secrets — API keys, passwords, SSH keys, AWS keys, auth tokens | Yes |
| INTELLECTUAL_PROPERTY | Intellectual Property — trademarks, copyrights, patents, trade secrets | Yes |
| NONE | Not data-classified — prompt injection, tool calls, infrastructure findings, document conformance | No |
Capability Surfaces and Boundary Surfaces
Some detection types map to a capability surface (an agent action, like INITIATE_PAYMENT) or a boundary surface (a defensive boundary, like INJECTION_DEFENSE). These are used by the policy engine to express controls in terms of what the agent is doing rather than just what was detected. See Policy Templates for how risk-adaptive rules use them.
Next steps