REPEATABLE EVIDENCE. INDEPENDENT FINDINGS.

Agents act. WitnessOps reviews what yours are permitted to do.

AI agents can send, buy, write, delete and call other systems. WitnessOps reviews what yours are permitted to do and what happens when they do it — and reviews the ground they stand on, starting with what the internet can already see. Bounded scope, findings in writing, evidence attached.

Two reviews. Two fixed prices.

Agent Action Security Review

What your AI agents are permitted to do, and what happens when they do it.

€2,500 fixed · excluding VAT

Within 10 working days after evidence rules are agreed

Request the review

Early Bird — Internet Footprint Review

What your organisation exposes to the open internet, found, evidenced and written up.

€500 fixed · excluding VAT

Request the review

What you receive

Written findings with the evidence attached, for a scope agreed before work starts. A request that exceeds the bounded review is narrowed or declined. An enquiry does not authorise collection or start a review.

Clear boundaries

Useful evidence.
Explicit limits.

What the app can and cannot do.

The app can

  • Record one bounded check
  • Keep the snapshot
  • Compare saved checks
  • Read and export reports
  • Keep findings tied to their evidence

The app cannot

  • Monitor continuously
  • Certify a system
  • Replace a penetration test
  • Treat missing data as a finding
  • Make a universal verification claim

What an Agent Action Security Review records

One consequential action, taken apart.

Illustrative · shape onlyDesigned, not executed
Consequential action
refund.issue above a set amount, through a payments API — an illustrative action, not an executed one.One action per review. Chosen with you before evidence rules are agreed.
Executing identity
svc-agent-refunds@example.com — a reserved example of the identity an agent would run as, not the one that configured it.
Permission / authority boundary
The roles, scopes and approval steps that stand between an identity and an action, as configured.Read from configuration under agreed evidence rules. Not assumed; none inspected here.
Supporting evidence
Policy exports, the tool manifest, approval configuration and action logs for an agreed window — each attached to the claim it supports.Collected only after evidence handling is agreed. No evidence was collected for this illustration.
Finding
A written statement of what an identity is permitted to do relative to an action, and what happens when it does it — with the evidence beside each claim.Written after review. This specimen carries no finding.
Explicit unknowns
What the evidence did not establish — for instance whether an action was exercised in the agreed window, or whether a human step exists outside the systems inspected.Named in writing. These are example questions, not results.

Illustrative. Reserved documentation names. No customer, execution, verification, authorisation failure or result is shown. This is the shape of a record, not a record.

Ask an expert

One question.
Non-secret details only.

Tell us what needs to happen and by when. We will confirm whether the app, a named review, or neither is the right next step.

For product or access questions, visit support.

Do not send passwords, private keys, API keys, recovery codes, session tokens or customer evidence in an initial enquiry.

Next, confirm your email with a code. We’ll then review the fit and reply with the next step.

Security Verification & Evidence | WitnessOps