← All services

Agent Action Security Review

Understand the controls around one AI action.

Review one agent action before launch or customer handover. Find gaps in approvals, permissions and execution evidence, with practical fixes for your team to prioritize.

Price
€2,500 fixed · excluding VAT
Delivery
Within 10 working days after evidence rules are agreed
Scope this review

Start with a short description. We confirm fit and scope before work begins.

See a sample review →

Synthetic example · Not customer evidence

See what a finding looks like.

Sample review excerpt: one support agent issuing refunds. All inputs and findings below are fictional; no system was tested.

Fictional example · No system tested

Finding 01 · High priority in this example

The refund tool does not enforce the approval policy.

Risk
A refund could bypass human approval.
Recommended fix
Require approval at the refund tool before execution.
View example evidence and proposed check
Fictional input A: refund policy
Refunds above €100 require a human approver before execution.
Fictional input B: tool configuration
The refund tool permits up to €1,000 per request and does not require an approval reference.
What those inputs support
The described tool configuration does not enforce the policy. This is a document-level inconsistency, not an observed unauthorized refund.
What remains unknown
No execution log or provider result is supplied. A separate downstream approval control may exist; its behavior has not been established.
Suggested owner and follow-up check
The tool owner should demonstrate in an agreed test environment that an above-limit request without approval stops, and that changing the approved order, amount or currency invalidates that approval. No fix or retest has been performed in this illustration.

Your review applies this structure to the agreed action: evidence, impact, recommended fixes and explicit unknowns.

Explore the separate key-rotation verification demo →

What you get

  • Authority map: who can approve the action.
  • Execution path: which identity, tools and systems act.
  • Permission boundary: what the agent can reach.
  • Evidence chain: what supports the outcome and what is unknown.
  • Control gaps and practical fixes: recommended changes in priority order.
  • Readout: findings and decisions for your team.

Scope and limits

One consequential agent or automation action. Read, inspect, reconstruct and report; no production changes or safety certification.

Do not send passwords, private keys, API keys, recovery codes, session tokens or other secrets.

Who it is for

AI product teams and automation agencies launching an agent or handing it over to a customer.

Company background

WitnessOps was founded by Karol Stefanski, previously an engineer at Waystone and Nostra. Professional background on LinkedIn →

Your part in the engagement

What do you need from me?

Start with a short description of one agent action and any launch or handover date. Before the paid review, we agree a named owner, the inputs and any meetings needed.

What access is required?

We agree how to inspect the action and handle evidence before you share it. The review is read-only: no platform installation, production changes or credentials through this form.

What happens after delivery?

We walk through the findings, priorities and open questions. Your team decides what to change and implements fixes; remediation and retesting require separate scope.

How the engagement works
  1. 1. Fit check

    What consequential action can the agent or automation take? A short description is enough to start. Add any deadline or customer handover if known. We clarify missing details together; do not send secrets or source material.

  2. 2. Agree scope before committing

    Confirm fit, the one action, fixed fee, required inputs, evidence handling and exclusions before work begins. We identify the responsible owner and agree how to inspect the action without installing a new platform.

  3. 3. Review the action path

    Use the Agent Workflow Reconstruction method to trace authority → identity → permissions → tools → execution → evidence and identify control gaps without exploitation or production modification.

  4. 4. Report and read out

    Within 10 working days after evidence rules are agreed, receive the action map, findings, prioritized fixes and readout. Each finding states what supports it and what remains unknown. Your team owns the launch decision and implementation of fixes.

Full scope and exclusions

Non-secret fit check first. One consequential agent or automation action.

  • One consequential agent or automation action
  • One consequential agent or automation action only. The engagement names the exact authority, executing identity, action, permission boundary, tools, evidence boundary, and verification mechanism.
  • Default operating mode: read, inspect, reconstruct, and report.
  • Production modification, destructive testing, exploitation, credential changes, persistence, and continuous monitoring are not included unless separately scoped and explicitly authorised.
  • A receipt proves only what its named verifier and referenced evidence support. It does not certify that the agent was correct, safe, compliant, or complete.
  • The Agent Workflow Reconstruction method can produce an evidence-gap analysis, proposed receipt shape, and sample pack. Extract supported receipt JSON to test through /verify; /verify does not accept the whole pack. The pack is not customer evidence or a claim that a control has been deployed in production.
  • Customer evidence is accepted only after scope and handling are agreed.

Not included

  • Platform installation
  • Production modification
  • Destructive testing
  • Exploitation
  • Credential changes
  • Persistence
  • Continuous monitoring
  • Certification that an agent is safe
  • Custom protocol development
  • Multi-workflow programmes
Example and technical details

What the result supports

WitnessOps reviews one consequential agent or automation action across authority → identity → permissions → tools → execution → evidence. The review identifies over-privileged identities, weak or implicit approval paths, tool access beyond intended scope, broken approval-to-action binding, missing execution evidence, and actions that cannot be independently demonstrated afterward.

How to inspect the result

Agent Workflow Reconstruction is the delivery method used to reconstruct the action and test the evidence chain. Where useful, the technical package includes an evidence-gap analysis, proposed receipt shape, and sample pack with supported receipt JSON. Extract that JSON to test it through /verify; /verify does not accept the whole pack. A receipt proves only what its named verifier and referenced evidence support; it does not certify compliance or agent safety.

Scope this review

Start with a short description. We confirm fit and scope before work begins.

Agent Action Security Review | WitnessOps