How the decision is made

A score is not proof. The evidence behind it matters.

AgentRiskLayer keeps unresolved information, declared controls, observed evidence, findings, attack evidence and runtime behaviour separate so the customer can see exactly what is known and what still needs proof.

Assessment states

Unknown, declared, observed and failed are not the same thing.

The platform keeps them separate so uncertainty does not masquerade as a vulnerability and an unsupported claim does not masquerade as proof.

Information required

A material question is unanswered. It is not scored as a vulnerability; the next step is to clarify the system or control.

Declared control

The customer states that a protection or non-applicability condition exists. It still needs appropriate evidence.

Finding

A specific declared control weakness or separately observed/tested failure exists and needs remediation and verification.

Verified or retested

Evidence supports the control or shows that a previously identified weakness no longer reproduces for the assessed scope.

Evidence chain

Nine stages from statement to decision.

Not every customer starts with every stage. The platform shows what exists and what is still missing.

  1. 1Declared controlsWhat the customer says exists.
  2. 2Observed controlsWhat authorised inspection can see.
  3. 3FindingsSpecific material weaknesses and credible attack paths.
  4. 4Red-team evidenceWhat controlled testing reproduces.
  5. 5Runtime evidenceWhat policy allows or blocks.
  6. 6Human approvalWho authorised the exact action.
  7. 7RemediationWhat changed and who owns it.
  8. 8RetestWhether the specific weakness remains.
  9. 9Deployment decisionProceed, hold or do not deploy.
Risk model

Five questions shape the decision.

Exposure

What can the agent reach?

Data sensitivity, users, tools, identities, networks, models, memory and operational authority. Exposure is context, not a vulnerability by itself.

Weakness

Which protections are weak?

Least privilege, input separation, tool policy, approval, containment, recovery and monitoring.

Completeness

What still needs an answer?

Material unknowns are shown as information required and can produce a hold without creating a false critical finding.

Confidence

How strong is the evidence?

Customer assertion, observed configuration, repeatable test, runtime event or reviewed evidence.

Attack path

What could actually happen?

Credible chains from untrusted input through agent authority to a real business consequence.

Methods

Different questions require different evidence.

The assessment does not pretend that one questionnaire or one scanner can answer everything.

Guided assessment

Establishes exposure, declared controls and unresolved information in plain language.

Local inspection

Observes repository, configuration, model and MCP evidence under explicit customer authorisation.

Controlled red team

Tests authorised non-production behaviour under written Rules of Engagement.

Runtime enforcement

Records the policy identity and decision before prompts, outputs or tool calls proceed.

Remediation and retest

Binds a fix to accountable ownership, evidence and the exact test needed for closure.

Integrity evidence

Uses signed or hashed artifacts where appropriate so tampering and scope are visible.

What this is—and is not

Decision support with explicit boundaries.

It is

A proprietary security assessment and evidence workflow against the AgentRiskLayer Control Profile for the identified system and version.

It is not

An accredited certification, legal opinion, guarantee of security or proof about systems that were outside the assessed scope.

Rules of Engagement

Adversarial testing requires authorised targets, environment, dates, allowed methods, prohibited actions, contacts and stop conditions.

Framework basis

Recognised guidance informs the control profile.

Findings can map to applicable OWASP agentic and LLM risks, NIST AI RMF, NIST SSDF and supply-chain guidance. A mapping indicates relevance; it does not create certification or compliance on its own.