We assess one agent workflow, then hand your engineers the control files that bind it. It runs on questions your own staff answer. We never touch your systems.
One domain below threshold decides the verdict, whatever the weighted total says. Figures illustrate the instrument, not a customer result.
Ask what a given agent is permitted to do, and up to what limit. Usually the answer lives in someone's head.
One verdict, traced end to end. The agent reaches an MCP server, which authenticates as a non-human identity, which carries a scope, which permits a refund, which needs a control, which produces the evidence an auditor asks for. Grey edges are relationships the assessment records but this verdict does not turn on.
Which actions, under whose identity, up to what limit. In most estates that has never been written down, and the answer sits with whoever built it.
An auditor can only test a boundary that was declared somewhere. Your second line has the same problem.
The agent does something nobody decided it could do. The model behaved. The permissions did not exist.
We take one workflow at a time. Three things come back, and all three are yours to keep.
Bounded or not, as of today, scored on a fixed instrument. Run it again next quarter and the number is comparable.
What is missing, in the order it matters. Written plainly enough to be uncomfortable.
Machine-readable control files for your gateways and pipelines. Your engineers deploy them. You own them outright.
Nothing to integrate and nothing to install. It runs on answers your own people give.
Not during the assessment, not afterwards. We built it this way so your risk function can approve the engagement on its normal path, without raising an exception for third-party access.
Two things cross the line, in opposite directions. Everything on the bottom row stays on your side of it, for the whole engagement.
One agent workflow: what it is allowed to do, and what stops it. Whoever runs that workflow can answer without preparing.
The same instrument every time, so this quarter's score can be set against last quarter's. Where you cannot show evidence, the score records it as unevidenced. We do not give credit for intent.
Control files, the score and the gap list. Deployment is your engineers' work, through your own change process.
Scopes widen. Someone adds a tool. The re-score says what moved since the last one.
Every control we specify carries the clause it answers to. Your compliance team can check the mapping before anyone signs anything.
One workflow, assessed and handed back as a configuration pack. The first one costs nothing. If it turns out your estate is in good order, we will say so and leave you alone.
We will not ask for credentials or system access at any stage, and the first assessment costs nothing.