Services · Gate Readiness Assessment
Find the control gaps before your security review.
A scoped assessment of AI agent actions, permissions and review evidence. Production access is optional; active testing needs separate authorisation.

What the engagement covers
Agent and tool inventory
In-scope agents, identities, models, prompts, tools, MCP servers and data flows, with explicit coverage limits.
Control mapping
A requirement-by-requirement record of implemented, missing and untested controls against your agreed review criteria.
Authorised test results
Reproducible scenarios for the high-risk actions in scope, with system version, attempt counts and observed outcomes.
Prioritised findings
Impact, evidence, a named remediation owner and suggested acceptance tests. The report belongs to the client.
Scope and responsibilities
Supply architecture and configuration exports, an agreed requirements list, and a technical contact. We prefer a test environment with synthetic data. Inventory collection is read-only; active tests are explicitly authorised with allowed actions, time windows, stop conditions and a recovery plan.
A production test requires additional written approval. Workload, dependencies and access determine the delivery schedule; a small scope may fit one to three weeks, confirmed in the proposal.
A practical example
A customer-care agent can read account data and issue refunds. The assessment checks who can invoke its tools, whether exports are bounded, whether refund limits are enforced outside the model, and whether decisions can be reconstructed.
The resulting report records observed failures and untested paths. It does not predict certification from a single attack-success percentage.
Inspect a sample report
View a fictional control review with test counts, evidence and open findings. It shows the format, rather than a client outcome.
Request a scoping conversation
Please email us to discuss your requirements. Online enquiry submission is currently unavailable.
Include a brief description of the agents, actions or review requirements you have in mind. Company details are optional.
Do not include credentials, customer data or confidential security findings. Read our privacy notice for how we handle your enquiry.
When an AI agent security assessment helps
An assessment is useful before an enterprise buyer review, before an agent gains access to sensitive data or consequential tools, and after a material change to its permissions or integrations. Start with the business action that could cause harm, then identify the controls and evidence needed to evaluate it.
For example, an assistant that drafts a refund and an agent that executes the refund have different authority. Reviewing the model response alone does not establish whether the payment tool enforces a transaction limit or verifies the approver.
How the assessment moves from scope to findings
- Define the deployment. Agree the agent version, environments, owners, review requirements and excluded paths.
- Map the authority. Trace identities, credentials, tools, MCP servers, data destinations and approval decisions.
- Test the boundaries. Exercise agreed allowed and denied actions using synthetic data, with written authorisation and stop conditions.
- Make findings actionable. Record the observed result, supporting artefact, impact, remediation owner and acceptance test.
- Agree the next decision. Separate fixes ready for retesting from unresolved risks and areas that remain untested.
Use the security review readiness checklist to prepare the initial information. The sample assessment report shows how evidence and findings can be organised.
Assessment questions
How is this different from a penetration test?
The engagement focuses on the agent's action and data boundaries, including identity scope, tool arguments, approvals and inspectable decision records. It can complement application or infrastructure testing; it does not automatically replace those tests. The proposal states the methods and coverage.
Can you review an agent before production deployment?
Yes. Architecture, configuration and a representative test environment can establish a useful starting point. Findings state where missing access, unavailable integrations or differences from production limit the conclusions.
What happens after findings are delivered?
Your team can own remediation, or scope guardrail engineering separately. Each agreed fix should have a named owner and a reproducible acceptance test. Ongoing regression testing is a separate engagement.
Turn security challenges into a clear plan
Tell us what you need to protect, improve or achieve. We will help you identify the control gaps, prioritise the work and define practical steps towards your goal.