Skip to content

Per-agent assessment workflow

Confirm the agent name, identifier, owner, purpose, version, environment, tools and current authority. The assessment is cleared or changed when another agent is selected.

Document:

  • Trigger and intended outcome.
  • Inputs, memory and retrieval.
  • Models and dependent agents.
  • Tools, APIs and reachable systems.
  • Read, write, execute and administrative capability.
  • Human approvals and escalation.
  • Users and affected people.
  • Data sensitivity and jurisdictions.
  • Maximum single and cumulative impact.
  • Failure, misuse and incident scenarios.

Record the presently approved operating level and the proposed target. If the current authority does not match the documented level, raise a finding immediately.

Assess every canonical requirement. The target-level matrix tells you whether the requirement is a MUST, SHOULD or MAY, but it does not replace contextual judgement.

For each requirement, choose:

  • Fully met
  • Partially met
  • Not addressed

Then record depth:

ResultDepth labels
Fully met1 Ad hoc, 2 Defined, 3 Embedded
Partially met or Not addressed1 Not started, 2 In progress, 3 Near complete

Partially met and Near complete remain blockers for a target-level MUST. Use the normative level matrix and documented exception governance for SHOULD or MAY treatment.

Use the on-screen playbook to:

  • Understand the control objective.
  • Identify minimum, production and advanced practices.
  • Ask agent-specific questions.
  • Inspect suitable evidence.
  • Design a safe test.
  • Recognise common false assurance.

Technology examples are options, not mandatory products.

Prefer evidence that proves both design and operation: identity records, policy decisions, traces, denials, approvals, monitoring, incident exercises and configuration-change records.

Test the negative path. Attempt an unauthorised resource, action, volume or transaction within an approved non-destructive environment and verify that enforcement, logging and response all occur.

Reflect failed tests, stale evidence, operating exceptions and incident history in the requirement result. Do not retain a favourable result that is contradicted by current adverse evidence.

For promotion, work through Performance, Security Validation, Business Value, Incident Record and Governance Sign-off. Attach evidence to each gate rather than relying on a single approval statement.

Record:

  • Maintain current level.
  • Hold promotion.
  • Approve promotion.
  • Demote.
  • Suspend or contain pending investigation.

Include decision owner, conditions, residual risk and next review.

Reassess after material change, incident, drift, failed test, new tool or privilege, changed purpose, new affected population, or expiry of evidence.

  • Correct registered agent selected.
  • Identity and capability manifest are current.
  • Current authority matches current ATF level.
  • All 25 requirements considered.
  • Requirement result and depth labels are consistent.
  • MUST requirements supported for the target.
  • SHOULD exceptions are justified.
  • Evidence is agent-, version- and environment-specific.
  • Boundaries and containment have been tested.
  • Incidents and adverse findings are reflected.
  • All applicable promotion gates are complete.
  • Human decision, conditions and reassessment triggers are recorded.