Authority
Can the agent only recommend, or can it write records, send messages, change permissions, deploy code or move money?
Run an AI agent security assessment that maps what the agent can access, what can influence it, what actions it can take and what evidence supports a deployment decision.
An assistant that drafts text is different from an agent with persistent memory, MCP tools, scheduled execution, customer data, financial authority or the ability to delegate work to other agents.
Can the agent only recommend, or can it write records, send messages, change permissions, deploy code or move money?
Can users, email, files, websites, tool output or stored memory inject instructions into the workflow?
Does it act only when asked, or can it run on schedules, react to events, replan, chain goals or continue without immediate approval?
Can policy, memory, tooling, workflow and changed data be rolled back after a bad or manipulated action?
The review follows the same evidence chain used inside AgentRiskLayer. Capabilities can make controls relevant, but they do not become vulnerabilities by themselves.
Record autonomy, memory, tool discovery, delegation, trigger mode, learning or adaptation, evaluator authority and recovery scope.
Review identities, tenant scope, customer data, secrets, files, databases, networks and administrative access.
Review tool trust, dynamic discovery, external services, write authority, action validation and downstream enforcement boundaries.
Test authorised scenarios where untrusted input tries to influence tool calls, approvals, data access or protected actions.
Check whether high-impact actions are bound to the exact action, target, parameters, value and validity period before execution.
Connect observed controls, test evidence, findings, remediation ownership, exact retest and the resulting deployment decision.
AgentRiskLayer keeps each stage separate so missing information is not silently converted into a vulnerability and a declared safeguard is not treated as verified control evidence.
The owner describes the exact agent version, its access, tools, autonomy, approvals and safeguards.
Code, configuration, inspection output, authorised tests and runtime records are collected separately from declarations.
A finding requires an observed or reproducible failure. Unknown, missing or inconclusive information remains an information gap.
Remediation is recorded, the exact failure is retested and current evidence supports a proceed, hold or do-not-deploy decision.
A useful answer needs more than “human approval is enabled.” The assessment checks where approval is enforced, what exact action and value are bound to it, whether it can be replayed, what happens when parameters change and what evidence records the decision.
Capability → applicable control → test → evidence → finding only if failure is demonstrated.
The free check identifies what needs review. The £99 AI Agent Security Assessment unlocks the full report and customer-operated inspection, controlled-testing, remediation and retest workflows. It reports only work actually completed.
Describe the agent, its access and safeguards and get an initial risk view.
Start freeFull report and PDF plus evidence, controlled-testing, remediation and exact-retest workflows for one agent.
Start with the free checkOngoing projects, runtime decisions, retention and team workflows.
Compare plansNo. AgentRiskLayer Security Assessment is a proprietary assessment against the AgentRiskLayer Control Profile. It is not an accredited certification or a guarantee that a system is risk-free.
No. Unknown or unconfirmed information remains context. A finding requires an observed or reproducible control failure.
Yes. The assessment can review MCP and other tool-enabled agents, including tool trust, permissions, external dependencies, action validation, prompt injection exposure and approval boundaries.
The remediation is recorded against the changed system version and the exact original failure is retested before closure.
No. The assessment is designed around privacy-safe descriptions and evidence. Do not enter credentials or secrets into the assessment fields.
Read the assessment methodology, Trust Centre and sample report before starting.
Start free. Unknowns remain unknown. Findings require evidence.