Independent review before a consequential launch

AI Agent Production Readiness Review

An independent security, controls, and governance review for agents that access sensitive data, call tools, or take consequential actions.

This review gives a technical and accountable team a clearer launch decision for one important workflow. It covers the architecture and the operating conditions around it, not just the model or prompt.

When to use it

What is reviewed

Authority and permissions

Identity, delegated authority, tool scope, approval gates, privilege changes, revocation, and confused-deputy paths.

Data and action boundaries

Retrieval sources, secrets, untrusted input, write paths, external services, and the conditions for consequential actions.

Reliability and operations

Failure handling, safe degradation, ownership, escalation, evaluation, observability, incident response, and change control.

Evidence and governance

Decision context, audit trails, policy enforcement, risk acceptance, launch criteria, and whether findings can be verified later.

Deliverables

  1. A scoped system model for the agreed workflow, actors, data, tools, and exclusions.
  2. An authority and control map showing where permissions originate and how they are constrained.
  3. A threat and failure register tied to evidence, affected assets, and unresolved assumptions.
  4. Prioritized findings with response options, dependencies, and a launch-readiness view.
  5. A written remediation plan and working readout with the accountable team.

Scope and commercial model

The standard review is fixed-scope and takes about two weeks once the boundary, evidence, participants, and schedule are agreed. It is not a certification or compliance attestation. Delegated Trust is an independent practice and is not affiliated with, sponsored by, or endorsed by Salesforce. Multiple workflows, major evidence gaps, implementation, penetration testing, and legal advice require separate scope.

The review can use diagrams, walkthroughs, configuration excerpts, selected logs, and representative evidence. Production access, write access, customer data, and source code are not assumed.

Founding pilot

One workflow. Ten business days. $6,500.

Two pilot slots are available for teams approaching production or expanding an agent's permissions. Each slot is one client, one AI agent or workflow, and one agreed business process.

Start with one workflow

Describe what the agent can access, what action concerns you most, and the decision the review needs to support.

[email protected]