Agent Permissions Audit

Find Out What Your AI Agents Are Allowed To Do

Most teams cannot answer that question. We give you the answer in writing: every action your agents can take on their own, every key that never expires, every spend limit nobody set. Then we hand you the fix list.

01

The keys never expire

An agent gets an API key so it can do its job. The key has no end date, no spend cap and no list of what it may touch. A year later nobody remembers making it, and it still works.

02

Agents hand power to other agents

One agent starts another to finish a job. In most systems the second one inherits everything the first could do. Nothing narrows it, and nothing writes down that it happened.

03

Nobody wrote down what “allowed” means

A buyer asks what your agents are permitted to do without a human. If the honest answer is a shrug and a look through the code, you do not have a governance problem later. You have one now.

The Check

Six Things We Look At

We go through your agents one at a time and answer six questions about each. The right hand column is what these checks usually turn up.

What the agent permissions audit checks, and what it commonly finds
What we look at The question we answer What usually turns up
Keys and tokens What credentials do your agents hold, and when do they stop working? Long-lived keys with no end date, still valid, nobody sure who made them
Reach What can each agent actually touch? An agent with access to a whole database when its job needs four fields
Handoffs When one agent starts another, what does the second one inherit? Everything the first one had, with nothing narrowing it on the way down
Money What can an agent spend or commit before a person sees it? No hard ceiling anywhere — only the limit on the underlying account
The stop button How do you switch one agent off without taking the rest down? No way to do it, so the real answer is a deploy or a support ticket
The record Can you show who authorised an action, and when? Application logs that show the action but not the authority behind it

The right hand column describes the patterns this check is designed to surface. It is not a claim about what we will find in your system. Your report says what is actually there.

You Keep It

What Lands On Your Desk

Everything below is yours. Not a login to our portal — files, in your hands, that you can hand to a buyer, an auditor or the engineer who joins next year.

  • A written list of every action your agents can take without a person
  • Each one marked fine, tighten or fix now, with the reason
  • A fix list in order, with the rough effort against each item
  • A scope and expiry written out for every agent, ready to implement
  • How each finding lines up with the EU AI Act, SOC 2 and ISO 42001
  • A 60 minute call to walk your engineers through all of it
# A line from the agent inventory, simplified agent: refund-handler started_by: support-triage-agent can_do: issue_refund, read_order, email_customer spend_limit: none set expires: never revocable: no — requires redeploy logged_as: "system" # Verdict: fix now # Inherits full parent scope. Can refund without a # ceiling, and the log cannot tell you which agent did it.

An illustration of the format, not a real client system. Your report has one of these for every agent you run.

Two Weeks

How It Runs

Days 1–2

You show us what you run

One call with whoever built the agents. Read-only access if you are comfortable giving it, documentation and config files if you are not. We agree the list of agents in scope before any money changes hands.

Days 3–7

We do the check

Quiet work on our side. We trace every credential, every permission and every handoff between agents. We do not touch your live system. If we find something that needs your attention this week rather than next, you hear about it the same day.

Days 8–10

You get the report and the call

The written report, the fix list in priority order, and 60 minutes with your engineers to go through it. Then it is yours. You can hand the fixes to your own team, and plenty of clients do.

The Rule Books

Why A Checker Cares

None of these rule books uses the word “agent” much yet. All of them already ask the question this audit answers: what can this system do on its own, and who said it could.

EU AI Act

The Act expects a person to be able to oversee an AI system and step in. An agent nobody can switch off, with authority nobody wrote down, is hard to describe as overseen. Your report gives you the written record that question needs.

SOC 2

Access control does not stop at people. An auditor who has started asking about non-human accounts will ask who approved this agent's access, what it is limited to, and how it gets taken away. Most teams answer the first and stall on the other two.

ISO/IEC 42001

The standard wants roles and responsibilities written down for your AI systems. When some of those systems act by themselves, an inventory of what each one may do is the plainest form that evidence can take.

We are not lawyers and this is not legal advice. No audit makes anyone compliant. What it does is put the evidence in your hands so your lawyer, your auditor or your buyer can judge for themselves.

One Price

What It Costs

We count your agents with you first, then fix the price in writing. It does not move after that. No hourly bills, no monthly fee.

On its own

Agent Permissions Audit

$6,500

2 weeks · Up to 5 agents or autonomous workflows

  • The full inventory and the fix list
  • A scope and expiry drafted for every agent
  • Findings mapped to your rule books
  • A 60 minute walkthrough call
Plan My Job
Best Value
Bolted on

Added To A Full Safety Check

+$4,000

Runs alongside the $8k–15k audit · No second kickoff

  • Everything in the standalone audit
  • One report covering agents and everything else
  • Your engineers sit through one walkthrough, not two
  • One fix list, ordered across the whole estate
Plan My Job
Bigger estates

More Than 5 Agents

Quoted

We price per agent, not per company

  • We count the agents with you, free
  • A fixed number back within two working days
  • Repeat agents of the same shape cost less
  • Same deliverables, same fixed-price promise
Get A Number

Counting the agents costs nothing and does not commit you. If we think it is too early for you to buy this, we will say so on the call. See our other prices →

Straight Answers

Questions People Ask

What counts as one agent?

One agent is one thing that can act on its own, without a person pressing the button each time. A chatbot that only writes text does not count. A chatbot that can issue a refund, send an email or call an API does. If you are not sure, tell us what you run and we will count it with you before you pay anything.

Do you need access to our source code?

No. Read-only access helps and makes the work faster, but we can do the whole audit from your documentation, your configuration files and a walkthrough call with your engineers. You choose which of those you are comfortable giving us.

Do you change anything in our system?

No. This audit only looks and reports. We never touch a live system during it. If you want us to make the fixes afterwards, that is separate work and separately priced — and you are free to have your own team do it instead. Plenty do.

How is this different from a penetration test?

A penetration test asks whether an outsider can break in. This asks a different question: what can your own agents legitimately do, right now, if nobody attacks anything at all. Most of what we find is not a break-in. It is an agent that was handed more power than its job needs, and a key that was never given an expiry date.

We only have one agent. Is this worth it?

Often yes, because the first agent is where the habits get set. It is far cheaper to give that one a scope and an expiry now than to retrofit it across thirty agents in two years. Tell us what you have and we will say honestly if it is too early.

Does this make us compliant with the EU AI Act?

No single audit makes anyone compliant, and we are not lawyers. What this gives you is the written evidence the human oversight and risk management parts of the Act expect you to be able to produce: a record of what your autonomous systems can do, who authorised it, and how it can be stopped.

Start with the count

Fifteen minutes. Tell us what your agents do and we will tell you how many are in scope, what it would cost, and whether it is worth doing yet.