Tell us what you want to check
Describe one agent action. We’ll confirm fit and scope together. No secrets or evidence yet.
Selected offer: Agent Action Security Review
Price: €2,500 fixed · excluding VAT
Timing: Within 10 working days after evidence rules are agreed
What happens next and scope
Review one agent action before launch or customer handover. Find gaps in approvals, permissions and execution evidence, with practical fixes for your team to prioritize.
- 01What consequential action can the agent or automation take? We check the failure impact, systems, tools, and security boundaries without asking for secrets.
- 02If it fits, we agree the one action, authority, executing identity, permissions, tool access, evidence rules, exclusions, and evidence handling before accepting source material.
- 03Within 10 working days after evidence rules are agreed for the €2,500 fixed · excluding VAT engagement.
Do not submit secrets, credentials, private keys, MFA codes, source exports, full logs, screenshots, customer records, or unrelated production data. Name evidence types only; source materials are handled after scope is agreed.
€2,500 fixed · excluding VAT for one consequential agent or automation action. Non-secret fit check first. Within 10 working days after evidence rules are agreed.
No work or target-facing check starts from this form.
No customer evidence is accepted until scope is agreed.
- ✓ACTION_BOUNDARY.json
- ✓AUTHORITY_MAP.json
- ✓EVIDENCE_MANIFEST.json
- ✓RECEIPT.json
- ✓VERIFY_RESULT.json
One consequential agent or automation action only. Default operating mode: read, inspect, reconstruct, and report. No production modification, destructive testing, exploitation, credential changes, persistence, continuous monitoring, or safety certification unless separately scoped and explicitly authorised.
What the review includes
Who can authorize the action, which identity executes it, and where production authority stops.
The one consequential action, connected tools, APIs, MCP integrations, and affected systems.
The identity’s effective access, privilege boundary, scope controls, and possible blast radius.
What binds authorization to execution and resulting state, what cannot be independently demonstrated, and the practical fixes.