Guides
AI Agent Security Review Readiness Checklist
Gather scope, controls and evidence before a buyer or internal review.
System and ownership
- Identify the system version, deployment, business owner and risk owner.
- Inventory agents, tools, identities, credentials and data flows.
- Identify high-impact actions and the requirements governing them.
- Record supplier dependencies and change notification arrangements.
Controls and tests
- Define permitted actions, resource boundaries and approval conditions.
- Record where permissions and argument checks are enforced.
- Test denied and allowed actions in an authorised environment.
- Test approval expiry, altered requests, unavailable dependencies and rollback.
- State test counts, observed results and coverage exclusions.
Evidence and decisions
- Index configuration, test and approval records against requirements.
- Assign each finding a remediation owner and acceptance test.
- Separate implemented, missing, failed and untested controls.
- Record unresolved risks and who can accept them.
- Set change triggers and the next review date.
This is a preparation checklist, not a certification or risk score.
Turn the checklist into a review record
Use one row for each requirement or consequential action. Record the owner, affected system version, enforcement point, evidence location, observed result and next decision. A reader should be able to follow a row from the requirement to the artefact without guessing which deployment was tested.
| Review field | What to record |
|---|---|
| Action and impact | The operation, target and potential consequence, such as exporting customer records. |
| Authority | Caller identity, service identity, tool permissions and required approval. |
| Control location | Where the downstream permission or argument restriction is enforced. |
| Test and result | Authorised scenario, configuration, attempt count and observed outcome. |
| Evidence | Reference to the configuration, test output or decision record. |
| Status and owner | Implemented, failed, missing or untested; remediation owner and next step. |
Work through one consequential action
For a customer-data export, identify the requesting user, the agent identity, the export tool, permitted records and approved destinations. Use synthetic data to test a permitted export, a denied dataset and an unapproved destination. If approval is required, test whether changing the dataset or destination invalidates it.
Record whether the tool enforced the restriction and whether the event record identifies the decision. If the environment cannot exercise a path, mark it untested and explain why. Do not convert missing evidence into an assumed pass.
Decide what is ready and what needs work
A review-ready pack is internally consistent: architecture, inventory, configuration and tests refer to the same deployment. Findings have owners and acceptance criteria. The responsible risk owner can see unresolved gaps and coverage limits.
Use the sample assessment report as a fictional format example. A scoped AI agent security assessment can help validate the boundaries; guardrail engineering can address agreed implementation gaps.
Keep evidence in an access-controlled workspace. An initial enquiry should describe the problem without attaching credentials, customer data or confidential findings.
Turn security challenges into a clear plan
Tell us what you need to protect, improve or achieve. We will help you identify the control gaps, prioritise the work and define practical steps towards your goal.