Independent architecture assessment
AI Agent Production Readiness Review
This detailed scope describes the Agentic Trust Review method: a fixed-scope architecture review of how an AI agent receives authority, uses tools and data, delegates work, fails, and leaves evidence. It turns trust assumptions and plausible failure paths into concrete engineering decisions before they become production surprises.
Who it is for
The review is for engineering, security, architecture, product, and risk leaders responsible for an AI system that can retrieve protected information, call tools, change records, initiate business processes, or delegate work to other agents.
It works best when the system has a named technical owner and enough design evidence to trace at least one important workflow end to end. It can cover a design, pilot, or operating system; the strength of each conclusion depends on the evidence available.
When to run it
- Before a pilot is approved for production or broader user access.
- Before adding higher-impact tools, sensitive data, autonomous actions, or agent-to-agent delegation.
- After changing the model, orchestration layer, identity design, approval path, or trust boundary.
- When security or risk reviewers cannot reconstruct what an agent was allowed to do at decision time.
- After an incident, near miss, unexpected action, or control failure exposes uncertainty in the architecture.
What is reviewed
The exact boundary is agreed before kickoff. A typical review examines:
Authority and identity
Agent identities, human and service principals, authentication, authorization policy, token scope, delegation chains, approval gates, and privilege changes.
Tools and data
Tool definitions, API permissions, data sources, secrets, session state, retrieval boundaries, write paths, and handling of untrusted input or generated output.
Decisions and evidence
Policy enforcement points, human oversight, logs, decision context, traceability, evidence gaps, and whether important actions can be reconstructed later.
Failure and recovery
Prompt injection paths, confused-deputy behavior, excessive agency, delegation loops, partial failure, revocation, containment, rollback, and safe degradation.
Concrete deliverables
- Scope and system model. The reviewed workflows, components, actors, data stores, external services, and explicit exclusions.
- Trust and authority map. Where authority originates, how it is constrained or delegated, which controls enforce it, and where the model relies on assumptions.
- Threat and failure register. Plausible misuse and failure paths tied to affected assets, existing controls, supporting evidence, and unresolved questions.
- Prioritized findings. Each material finding states the condition observed, why it matters, the evidence reviewed, limits on the conclusion, and a recommended response.
- Remediation plan and readout. Sequenced actions, decision points, dependencies, and a working session with the accountable team. Deliverables are provided in portable document formats agreed during scoping.
What it is not
The Agentic Trust Review is not a certification, legal opinion, compliance attestation, privacy assessment, penetration test, exhaustive source-code audit, or guarantee that a system is secure. It does not certify a vendor, product, model, or control framework. Those activities may require separate specialists, testing methods, and contractual scope.
Data handling, access, and retention
The review starts with minimum necessary access. Architecture diagrams, workflow descriptions, policy and configuration excerpts, selected logs, and guided walkthroughs are preferred before direct system access. Production access, write access, customer data, and source code are not assumed.
Before kickoff, the written scope records the approved evidence, systems, participants, transfer method, storage location, access level, sensitive-data restrictions, and retention or deletion date. The client provisions and revokes any account access. Credentials and secrets should not be shared; redacted or representative evidence is preferred where it can answer the review question.
Working material is retained only for the engagement and delivery window stated in the agreement, not indefinitely. Any need for additional access, a different storage environment, subprocessors, or a longer retention period must be agreed before that handling occurs. Client policy or legal requirements take precedence when they are included in the engagement terms.
Scope, schedule, and pricing
A typical Agentic Trust Review is structured as a fixed-scope, two-week engagement once the required people and evidence are available. Systems with multiple business-critical workflows, environments, agent tiers, or significant evidence gaps may be divided into phases or separately scoped.
Two founding pilot slots are open now at a fixed $6,500 for one workflow and ten business days — see the production readiness review page for the pilot scope. There is no universal list price outside the pilot. A fixed fee is quoted in writing after the review boundary, number of workflows and integrations, evidence needs, access constraints, workshops, deliverables, and schedule are agreed. Work starts only after scope, fee, assumptions, and exclusions are documented; material changes require written rescoping.
Frequently asked questions
Can the review happen before production?
Yes. A design-stage review can work from architecture diagrams, intended tool and data flows, policy decisions, and representative configurations. Findings will distinguish observed behavior from assumptions that still need validation once the system is running.
Do you need source code or production access?
Not by default. The review starts with the minimum evidence needed for the agreed questions. Read-only configuration, selected code, logs, or a controlled environment may be requested when documents and walkthroughs cannot support a conclusion. Any additional access is agreed before it is provisioned.
Does the review certify that a system is secure or compliant?
No. It is an independent architecture assessment, not a certification, compliance attestation, legal opinion, or guarantee of security. Findings can support internal security, risk, and governance work, but they do not replace those functions.
Is this a penetration test or a full code audit?
No. The core engagement reviews trust boundaries, authority, delegation, evidence, and failure handling. Exploit testing, exhaustive source review, model-quality evaluation, privacy impact assessment, and formal compliance mapping require separate scope and qualified owners.
Is this service affiliated with Salesforce?
No. Delegated Trust is an independent practice. The Agentic Trust Review is not offered, sponsored, or endorsed by Salesforce.
What happens after the readout?
The review stands on its own. Your team receives the agreed artifacts and can implement the plan internally. If deeper design or remediation support would help, that is a separate decision and a separate scope.
Start with scope
Bring one important agent workflow.
Describe what the agent can access, what action concerns you most, and the decision the review needs to support.
[email protected]