What we examine
- Identity and authentication paths for each agent
- Tool permissions, delegated access, and resource boundaries
- Owner, sponsor, approvals, monitoring, and retirement
Engagement
Specify what each AI agent can read or change, where approval is required, and how its access is reviewed and revoked.
The starting point
An agent that can retrieve data or take actions becomes part of the operating environment. Its authority must be explicit, reviewable, and removable.
Delivery depends on your systems, access, licensing, and agreed scope. Findings are not a certification of compliance, and a service description is not a guarantee of a particular outcome.
Agent governance defines the authority under which an agent operates. It connects an identity to approved actions, resources, owners, review gates, and a retirement process. A policy states the requirement; implementation identifies which permission, configuration, interface, and operating procedure enforce it.
Bring a general description of the systems, the decision you need to resolve, the current stage of work, and the owners who can agree on access and scope. Establish a secure exchange process before sharing detailed architecture or sensitive records.
The agreed scope defines what will be delivered. For this engagement, the starting deliverables are:
Verification evidence, operating responsibilities, and unresolved dependencies should be clear before the work is handed over.