Independent review before a consequential launch
AI Agent Production Readiness Review
An independent security, controls, and governance review for agents that access sensitive data, call tools, or take consequential actions.
This review gives a technical and accountable team a clearer launch decision for one important workflow. It covers the architecture and the operating conditions around it, not just the model or prompt.
When to use it
- Before approving a pilot for production or broader user access.
- Before adding write tools, sensitive data, autonomous actions, or agent-to-agent delegation.
- After a near miss, unexpected action, model change, or control failure.
- When security, risk, or leadership cannot reconstruct what the agent was allowed to do.
What is reviewed
Authority and permissions
Identity, delegated authority, tool scope, approval gates, privilege changes, revocation, and confused-deputy paths.
Data and action boundaries
Retrieval sources, secrets, untrusted input, write paths, external services, and the conditions for consequential actions.
Reliability and operations
Failure handling, safe degradation, ownership, escalation, evaluation, observability, incident response, and change control.
Evidence and governance
Decision context, audit trails, policy enforcement, risk acceptance, launch criteria, and whether findings can be verified later.
Deliverables
- A scoped system model for the agreed workflow, actors, data, tools, and exclusions.
- An authority and control map showing where permissions originate and how they are constrained.
- A threat and failure register tied to evidence, affected assets, and unresolved assumptions.
- Prioritized findings with response options, dependencies, and a launch-readiness view.
- A written remediation plan and working readout with the accountable team.
Scope and commercial model
The standard review is fixed-scope and takes about two weeks once the boundary, evidence, participants, and schedule are agreed. It is not a certification or compliance attestation. Delegated Trust is an independent practice and is not affiliated with, sponsored by, or endorsed by Salesforce. Multiple workflows, major evidence gaps, implementation, penetration testing, and legal advice require separate scope.
The review can use diagrams, walkthroughs, configuration excerpts, selected logs, and representative evidence. Production access, write access, customer data, and source code are not assumed.
Founding pilot
One workflow. Ten business days. $6,500.
Two pilot slots are available for teams approaching production or expanding an agent's permissions. Each slot is one client, one AI agent or workflow, and one agreed business process.
- Fixed fee of $6,500 USD.
- Ten business days once the evidence and participants are available.
- Authority and control map, threat and failure register, prioritized findings, remediation plan, and final readout.
- No implementation, penetration test, certification, or unlimited follow-up.
Start with one workflow
Describe what the agent can access, what action concerns you most, and the decision the review needs to support.
[email protected]