Your agent is documented for 12 actions. Its credentials permit 47.
The two lists are never the same, and almost nobody has ever put them side by side. This is the audit that does.
Format
What this involves
- Access needed
- Read-only: config, credentials scope, traces
- Your time
- About one day of one engineer
- Runs in
- 1 to 3 weeks
- Evidence
- What the agent is permitted to do, and did
- From
- $4,500
The gap
Every agent has two capability lists.
The first is what it is documented to do — the tools in the spec, the actions in the design note, the description in the security review.
The second is what its credentials actually permit. That list is longer. It is always longer.
An OAuth token scoped for "read email" typically carries send, delete and folder access, because that is how the scope is packaged. A database tool the spec calls read-only usually holds write. An agent running under a staff member's SSO can do everything that person can do, which on most teams is a great deal.
Nobody chose the second list. It arrived as a side effect of how permissions are granted.
The report says: here are the actions nobody approved. It is usually the shortest page and the first one anyone reads.
What we read
Read-only, always. We take nothing we were not given and we change nothing.
-
Tool and MCP manifests
Every function and server the agent can call.
-
Credential scopes
The real permission set behind each token, key and role.
-
Execution traces
LangSmith, Langfuse, model-provider logs, CloudTrail, or whatever you keep.
-
Identity configuration
Whether the agent acts as itself or wears a person's credentials.
About a day of one engineer's time on your side, mostly granting read access and answering questions.
The eleven, answered
On the overview we set out the eleven categories of material sixteen State Attorneys General asked OpenAI to preserve on 3 August 2026.
This audit answers them for you. Each one gets your position, the evidence that supports it, or a plain statement that no evidence exists. That last outcome is not a failure — it is the most common result, and knowing it before someone asks is the entire value.
Three layers
What it costs
Fixed fee, agreed before anything starts. Nothing is charged until you have approved the scope in writing.
Snapshot
Configuration and the capability gap, at a point in time.
The fastest route to the one number that matters. No traces, no behavioural findings.
- Capability register
- Declared-versus-permitted gap
- Written findings
Full Assay
Configuration, thirty days of traces, and a signed report.
This is the audit. What you commission when a third party will read the result.
- Everything in Snapshot
- 30 days of execution traces
- Containment finding
- Detection finding
- The eleven answered
- Signed report
Fleet Assay
Up to five agent systems, each with its own signed report.
When agents have multiplied faster than anyone documented them.
- Full Assay on each of five systems
- Cross-system comparison
- Five signed reports
Beyond five agents, $2,500 per additional agent.
These are published fees, not estimates. Where an engagement genuinely does not fit one of the three, we will say so and quote the work rather than force it into a tier.
Stated plainly
What this is not
- Not a compliance certificate. No law requires an AI agent audit, and we will not imply one does.
- It does not make you compliant with anything. It tells you what is true.
- Not a penetration test of your wider estate.
- It does not assess whether your model's answers are correct. That is evaluation work, and a different discipline.
Accountability
Who signs it
Every report is signed by Brijesh Patel, ISO/IEC 42001 Lead Auditor, who performed the work.
Not a firm name on a template. A person, named, who read the evidence and reached the finding — and who can be asked about it afterwards.
There is no statute behind an agent audit. What makes the report worth anything is that a qualified human put their name on it and would say the same thing under questioning. That is the instrument.
Fit
Who this is for
- Agents already running in production
- Teams facing a customer security review or a vendor questionnaire that has started asking about agents
- Anyone who needs a document a third party will read — a customer, an insurer, a board, or a regulator
The three methods
If this is the wrong one
They differ by how much access you give us, and therefore by how strong the evidence is. More access, better evidence — there is no way around that trade.
Black Box
No credentials, no integration, no sight of your code. We talk to your agent the way an attacker would and write down everything it tries.
Read Only
The two lists are never the same, and almost nobody has ever put them side by side. This is the audit that does.
Proxy
Most teams find out from someone outside. This is the tier that changes that.
Not sure which? Start with the eleven questions — how many you can answer tells you which method you need.
Before you ask
Questions
How much of our engineer's time does this take?
About a day, spread over the engagement. Mostly access grants and clarifying questions.
Can you do this without touching production?
Yes, if your staging configuration genuinely mirrors production. We will tell you if it does not, and what that costs you in confidence.
Do you use AI to run the audit?
To collect evidence, yes — enumerating permissions, parsing traces, running the battery. To reach the verdict, no. An assayer uses instruments; the instruments do not sign the certificate.
What if we do not keep traces?
Then Snapshot is where you start, and the first recommendation in your report will be about what to begin recording.
Next step
Request a Read Only audit
Two minutes. No account, and no call booked automatically. We reply within two working days with a scope and a fixed fee — or with an honest reason this is not the right method for you.
Sources. Letter of 3 August 2026 from the Attorneys General of sixteen states to OpenAI, and Alabama Deceptive Trade Practices Act Subpoena Duces Tecum No. 26-0007. Both public. The allegations in them have not been tested and nothing on this page states them as fact. Primary documents last read by a human on 25 August 2026.