Agent Action Security Review

Tell us what you want to check

Describe one agent action. We’ll confirm fit and scope together. No secrets or evidence yet.

Selected offer: Agent Action Security Review

Price: €2,500 fixed · excluding VAT

Timing: Within 10 working days after evidence rules are agreed

Describe the action at a high level. Do not paste secrets, credentials, logs, screenshots, customer data, or production evidence.

An approximate date is enough. We’ll confirm delivery timing after agreeing scope.

Add context (optional)

Next, confirm your email with a code. We’ll then review the fit and reply with the next step.

Submitting this form opens only the non-secret fit check for one consequential agent or automation action. Work does not start until scope, evidence rules, and evidence handling are agreed.

Do not send passwords, private keys, API keys, recovery codes, session tokens or other secrets.

What happens next and scope
Selected situation

Review one agent action before launch or customer handover. Find gaps in approvals, permissions and execution evidence, with practical fixes for your team to prioritize.

What happens next
  1. 01What consequential action can the agent or automation take? We check the failure impact, systems, tools, and security boundaries without asking for secrets.
  2. 02If it fits, we agree the one action, authority, executing identity, permissions, tool access, evidence rules, exclusions, and evidence handling before accepting source material.
  3. 03Within 10 working days after evidence rules are agreed for the €2,500 fixed · excluding VAT engagement.
First message only

Do not submit secrets, credentials, private keys, MFA codes, source exports, full logs, screenshots, customer records, or unrelated production data. Name evidence types only; source materials are handled after scope is agreed.

Commercial scope

€2,500 fixed · excluding VAT for one consequential agent or automation action. Non-secret fit check first. Within 10 working days after evidence rules are agreed.

No work or target-facing check starts from this form.

No customer evidence is accepted until scope is agreed.

Typical bundle
  • ✓ACTION_BOUNDARY.json
  • ✓AUTHORITY_MAP.json
  • ✓EVIDENCE_MANIFEST.json
  • ✓RECEIPT.json
  • ✓VERIFY_RESULT.json
Inspect sample package
Boundary kept clear

One consequential agent or automation action only. Default operating mode: read, inspect, reconstruct, and report. No production modification, destructive testing, exploitation, credential changes, persistence, continuous monitoring, or safety certification unless separately scoped and explicitly authorised.

Need help? Support./Disclosure: Security.
What the review includes
What Agent Action Security Review includes
01
Authority map

Who can authorize the action, which identity executes it, and where production authority stops.

02
Execution path

The one consequential action, connected tools, APIs, MCP integrations, and affected systems.

03
Permission boundary

The identity’s effective access, privilege boundary, scope controls, and possible blast radius.

04
Evidence chain and control gaps

What binds authorization to execution and resulting state, what cannot be independently demonstrated, and the practical fixes.

Tell Us What You Need Reviewed | WitnessOps