ASSESSMENT PROCESS

Define the scope, test it, preserve evidence,
then verify remediation.

AI-agent assessment begins by defining scope, stop conditions, and expected results. Testing is executed through reproducible scenarios with traceable evidence.

01Initial discussionReview the AI use case, users, connected systems, authorization model, and current concerns at a high level.
02Agree scope and conditionsDocument scope, exclusions, data, accounts, stop conditions, timing, and deliverables.
03Map boundaries and scenariosDefine who may access what through which path and create normal, unauthorized, and bypass cases.
04Execute and observeRecord agent responses, tool selection, APIs, communications, and data access.
05Evaluate and analyzeAssess conditions for success, reproducibility, impact, detectability, and evidence quality.
06Report, improve, re-testExplain the result through boundary maps and business risk, prioritize remediation, and repeat the same cases when needed.
Safety controls

Dedicated least-privilege accounts, mock or anonymized data, stop conditions, and fail-closed behavior are preferred.