Find Out What Your AI Agents Are Allowed To Do
Most teams cannot answer that question. We give you the answer in writing: every action your agents can take on their own, every key that never expires, every spend limit nobody set. Then we hand you the fix list.
The keys never expire
An agent gets an API key so it can do its job. The key has no end date, no spend cap and no list of what it may touch. A year later nobody remembers making it, and it still works.
Agents hand power to other agents
One agent starts another to finish a job. In most systems the second one inherits everything the first could do. Nothing narrows it, and nothing writes down that it happened.
Nobody wrote down what “allowed” means
A buyer asks what your agents are permitted to do without a human. If the honest answer is a shrug and a look through the code, you do not have a governance problem later. You have one now.
Six Things We Look At
We go through your agents one at a time and answer six questions about each. The right hand column is what these checks usually turn up.
| What we look at | The question we answer | What usually turns up |
|---|---|---|
| Keys and tokens | What credentials do your agents hold, and when do they stop working? | Long-lived keys with no end date, still valid, nobody sure who made them |
| Reach | What can each agent actually touch? | An agent with access to a whole database when its job needs four fields |
| Handoffs | When one agent starts another, what does the second one inherit? | Everything the first one had, with nothing narrowing it on the way down |
| Money | What can an agent spend or commit before a person sees it? | No hard ceiling anywhere — only the limit on the underlying account |
| The stop button | How do you switch one agent off without taking the rest down? | No way to do it, so the real answer is a deploy or a support ticket |
| The record | Can you show who authorised an action, and when? | Application logs that show the action but not the authority behind it |
The right hand column describes the patterns this check is designed to surface. It is not a claim about what we will find in your system. Your report says what is actually there.
What Lands On Your Desk
Everything below is yours. Not a login to our portal — files, in your hands, that you can hand to a buyer, an auditor or the engineer who joins next year.
- ✓ A written list of every action your agents can take without a person
- ✓ Each one marked fine, tighten or fix now, with the reason
- ✓ A fix list in order, with the rough effort against each item
- ✓ A scope and expiry written out for every agent, ready to implement
- ✓ How each finding lines up with the EU AI Act, SOC 2 and ISO 42001
- ✓ A 60 minute call to walk your engineers through all of it
An illustration of the format, not a real client system. Your report has one of these for every agent you run.
How It Runs
You show us what you run
One call with whoever built the agents. Read-only access if you are comfortable giving it, documentation and config files if you are not. We agree the list of agents in scope before any money changes hands.
We do the check
Quiet work on our side. We trace every credential, every permission and every handoff between agents. We do not touch your live system. If we find something that needs your attention this week rather than next, you hear about it the same day.
You get the report and the call
The written report, the fix list in priority order, and 60 minutes with your engineers to go through it. Then it is yours. You can hand the fixes to your own team, and plenty of clients do.
Why A Checker Cares
None of these rule books uses the word “agent” much yet. All of them already ask the question this audit answers: what can this system do on its own, and who said it could.
EU AI Act
The Act expects a person to be able to oversee an AI system and step in. An agent nobody can switch off, with authority nobody wrote down, is hard to describe as overseen. Your report gives you the written record that question needs.
SOC 2
Access control does not stop at people. An auditor who has started asking about non-human accounts will ask who approved this agent's access, what it is limited to, and how it gets taken away. Most teams answer the first and stall on the other two.
ISO/IEC 42001
The standard wants roles and responsibilities written down for your AI systems. When some of those systems act by themselves, an inventory of what each one may do is the plainest form that evidence can take.
We are not lawyers and this is not legal advice. No audit makes anyone compliant. What it does is put the evidence in your hands so your lawyer, your auditor or your buyer can judge for themselves.
What It Costs
We count your agents with you first, then fix the price in writing. It does not move after that. No hourly bills, no monthly fee.
Agent Permissions Audit
2 weeks · Up to 5 agents or autonomous workflows
- ✓ The full inventory and the fix list
- ✓ A scope and expiry drafted for every agent
- ✓ Findings mapped to your rule books
- ✓ A 60 minute walkthrough call
Added To A Full Safety Check
Runs alongside the $8k–15k audit · No second kickoff
- ✓ Everything in the standalone audit
- ✓ One report covering agents and everything else
- ✓ Your engineers sit through one walkthrough, not two
- ✓ One fix list, ordered across the whole estate
More Than 5 Agents
We price per agent, not per company
- ✓ We count the agents with you, free
- ✓ A fixed number back within two working days
- ✓ Repeat agents of the same shape cost less
- ✓ Same deliverables, same fixed-price promise
Counting the agents costs nothing and does not commit you. If we think it is too early for you to buy this, we will say so on the call. See our other prices →
Questions People Ask
What counts as one agent?
One agent is one thing that can act on its own, without a person pressing the button each time. A chatbot that only writes text does not count. A chatbot that can issue a refund, send an email or call an API does. If you are not sure, tell us what you run and we will count it with you before you pay anything.
Do you need access to our source code?
No. Read-only access helps and makes the work faster, but we can do the whole audit from your documentation, your configuration files and a walkthrough call with your engineers. You choose which of those you are comfortable giving us.
Do you change anything in our system?
No. This audit only looks and reports. We never touch a live system during it. If you want us to make the fixes afterwards, that is separate work and separately priced — and you are free to have your own team do it instead. Plenty do.
How is this different from a penetration test?
A penetration test asks whether an outsider can break in. This asks a different question: what can your own agents legitimately do, right now, if nobody attacks anything at all. Most of what we find is not a break-in. It is an agent that was handed more power than its job needs, and a key that was never given an expiry date.
We only have one agent. Is this worth it?
Often yes, because the first agent is where the habits get set. It is far cheaper to give that one a scope and an expiry now than to retrofit it across thirty agents in two years. Tell us what you have and we will say honestly if it is too early.
Does this make us compliant with the EU AI Act?
No single audit makes anyone compliant, and we are not lawyers. What this gives you is the written evidence the human oversight and risk management parts of the Act expect you to be able to produce: a record of what your autonomous systems can do, who authorised it, and how it can be stopped.
Start with the count
Fifteen minutes. Tell us what your agents do and we will tell you how many are in scope, what it would cost, and whether it is worth doing yet.