Every agent in production has two capability lists. The first is what it is documented to do: the tools in the spec, the actions in the design note, the description that went into the security review. It is the list your team wrote, and the one every answer you give about the agent is based on.
Documented for 12 actions. Its credentials permit 47.
Two capability lists - what the agent is documented to do, and what its credentials permit. Almost nobody has compared them.
Our promise
“Documentation is a claim. The credential is evidence.”
Every finding is written against a named control — defensible line by line, to anyone who asks. The fee is fixed at $12,500, and nothing is charged until you approve it.
Request this Read Only auditThe capability gap, in three chapters
The second is what its credentials actually permit, and it is always longer. A scope packaged for reading mail carries sending and deleting; a database tool the spec calls read-only usually holds write. Nobody chose that second list - it arrived as a side effect of how access is granted.
We put the two lists side by side, which almost nobody has ever done. Read-only throughout: manifests, credential scopes, traces and identity configuration. The report opens with the actions nobody approved - usually its shortest page, and reliably the first one anyone reads.
What we read, and what this is not.
Read-only access to four things, and about one day of one engineer - we change nothing on your systems.
- Tool and MCP manifests - every callable function
- Credential scopes behind each token, key and role
- Execution traces, from whatever you already keep
- Identity: itself, or a person’s credentials
- Not a compliance certificate. No law requires one
- It does not make you compliant. It tells you what is true
- Not a penetration test of your wider estate
- Not an evaluation of whether answers are correct
Two lists. Only one was chosen.
What it is documented to do
The tools named in the spec, the actions in the design note, the description that went into the security review, and nothing at all beyond them. This is the list your team wrote and the one everybody on it has read, and it is the one behind every answer you give about the agent to anybody who asks.
What its credentials permit
The real permission set behind each token, key and role, as it actually stands rather than as it was requested. A scope packaged for reading mail carries sending and deleting with it; a database tool the spec calls read-only usually holds write. This list is longer than the first one. It is always longer.
Nobody chose the second one
Nobody ever chose this list. It arrived as a side effect of how permissions are granted inside your organisation, which is why no one has ever read it end to end. An agent running under a staff member’s SSO can do everything that person can do, and on most teams that turns out to be a very great deal.
“Our agent only reads email.”
Its token can send and delete.
It is the first thing we have to correct.
- Who it is for
- Agents in production
- Teams in a security review
- Vendor questionnaires
- Boards & insurers
- Anyone asked for evidence
Sixteen State Attorneys General listed eleven things to preserve about agent testing. This audit answers them for you, before anybody asks.
The most common answer is that no evidence exists at all. Knowing that before somebody outside asks is the whole point of asking early.
Read-only throughout. We take nothing we were not given, we exploit nothing, we change nothing, and every access is logged at your end.
Three questions. Then you’ll know.
No email. No signup. A starting point, not a determination.
Your scope check
Read-only, from day one to signature.
Four moments in the engagement. Your side of it is about one engineer for about one day.
-
Access granted
Day oneRead-only, and nothing else. We take nothing we were not given, and we change nothing at any point.
-
Configuration read
Week oneManifests, credential scopes and identity configuration - which produces the gap, and the gap is the finding.
-
Traces read
Weeks two to threeThirty days of execution traces against that permission set: not what it could do, but what it did do.
-
Signed
On deliveryYou see the draft first. The report is then signed by the named auditor who read it, rather than by the firm.
A staging configuration that does not genuinely mirror production gives you a report about staging. Staging usually carries narrower credential scopes - so a clean result there says very little about the thing you actually run.
What we read, what you get
12 findings: the capability gap, then the eleven categories, each with the exposure behind it.
- The capability gap The lead finding
- Every action the credentials permit that the documentation never claimed, listed rather than counted - the actions nobody approved. It is assembled from the tool and MCP manifests, the real scope behind each token, key and role, and the identity the agent runs under, then set against what your own spec and design note say it does. Usually the shortest page in the report, and the first one anyone reads.
- The incident record Of the eleven
- Could you produce a full record of an unintended action, and all it touched? No per-action trace. A summary is not a record.
- How you found out Of the eleven
- Could you show when you found out — and that you found it, not an outsider? No independent detection. Discovery depends on a third party.
- Which model ran Of the eleven
- Could you identify exactly which model and version ran, pre-release included? Model provenance not recorded per run.
- Your own review Of the eleven
- Do you have a written internal review, and does it match what you said publicly? No written review, or a review that diverges from public statements.
- Credential use Of the eleven
- Has an agent ever used account-level credentials it was not given? Credential discovery and reuse is untracked.
- Offensive evaluations Of the eleven
- Which evaluations push a model toward attack paths, and who authorised it? Offensive testing runs without a named authoriser.
- Prior incidents Of the eleven
- Could you produce every earlier unauthorised access — or state there were none? No incident history. "None that we know of" is not an answer.
- Self-persistence Of the eleven
- Has an agent left notes for future versions on working around its constraints? Agent-written artefacts are not inspected.
- Evaluation safety policy Of the eleven
- Do you have an evaluation-safety policy, dated before your most recent test? No dated policy. A policy written after the fact proves nothing.
- Concerns raised Of the eleven
- Could you produce every safeguard concern your staff raised, acted on or not? Internal concerns are discoverable and unmanaged. Usually the sharpest exposure.
- Who knew Of the eleven
- Could you name every person involved in, or with knowledge of, the above? No named custodians.
Personal information, independently reviewed
From the CRM to the model in the decision path.
-
Access
Read access to config, credential scopes, traces and identity.
-
Read
What the agent is permitted to do, against what it actually did.
-
Sign off and evidence
You see the draft first. Then a report signed by the person who read it.
Why teams choose iDharma for their agent audit
Read-only, always
We take nothing we were not given, and we change nothing on your systems.
A named signature
Signed by the ISO/IEC 42001 Lead Auditor who read it, not by the firm.
A day of your time
About one engineer for one day, mostly granting access and answering questions.
The eleven, answered
Each with your position, the evidence for it, or a plain note that none exists.
Four marks, struck on every report.
What you get
Concrete artefacts, each with a name and a format - you know what lands before you buy.
Signed Read Only report
The full audit: what your agent is permitted to do, what it actually did, and the distance between those two - written finding by finding rather than reduced to a score. Signed by the named auditor who read the evidence, not by the firm. This is the document you hand to the customer, the insurer or the board that asked, and it is written to be read by someone outside your team.
Capability register
Every tool, MCP server and function the agent can actually reach, taken from the manifests themselves rather than from the description in the design note.
Declared against permitted
The gap as a count and as a list: every single action the credentials allow that no document ever claimed, which is the finding people read first.
Execution traces, read
Thirty days of history against the permission set - what the agent actually did, from whatever you already keep rather than new instrumentation.
Containment finding
Whether the agent acts as itself or wears a person’s own credentials, and what that means for the blast radius if a single prompt goes wrong.
Detection finding
Whether you would find out on your own, or from somebody outside. On most estates this one is answered by the absence of the record, not by it.
The eleven, answered
A position on each of the eleven categories, with the evidence that supports it or else a plain statement that none exists - dated and signed.
Real numbers, upfront.
- One agent
- $12,500 1 to 2 weeks
- Each additional agent
- $3,000 in the same engagement
- Annual renewal
- $10,500 locked at this price
Fixed before anything starts. Each additional agent in the same engagement is $3,000. A re-audit after a change to the agent or its model is $8,000. Nothing is charged until you approve.
Request this audit- Permission set, granted against actual
- Tool and credential inventory
- Full transcript
- Findings signed by a named auditor
Four things you have to be able to produce
An audit is not graded on intent. Each of these is either in your hand on the day someone asks, or it is not.
The register,
complete
Every tool, server and function the agent can call, enumerated from the manifests themselves rather than from the design note somebody wrote before it shipped.
The gap,
numbered
Documented actions against permitted actions, as a count and as a list. It is a single number, and it is the number that every other finding in the report hangs off.
The traces,
read
Thirty days of execution history against that permission set - not what the agent could have done, but what it actually did while nobody was reading the logs.
The eleven,
answered
Each of the eleven with your position and the evidence for it, or a plain statement that no evidence exists at all - which is the most common answer of the three.
Four cards, and each one is evidence or it is nothing.
Plain answers
What the law is, whether it reaches you, the clock, and where AI lands. Answered straight.
Request this reviewWhat does a Read Only agent audit actually produce?
A signed report with the capability gap at the front: every action your agent’s credentials permit that no document ever claimed. Then containment, detection, and a position on each of the eleven categories.
How much of our engineer’s time does this take?
About a day, spread over the engagement. Mostly access grants and clarifying questions.
Can you do this without touching production?
Yes, if your staging configuration genuinely mirrors production. We will tell you if it does not, and what that costs you in confidence.
What are the eleven?
Eleven categories of material that sixteen State Attorneys General asked OpenAI to preserve in a letter of 3 August 2026 - the incident record, how you found out, which model ran, and eight more. This audit answers them for you.
What does it cost, and what moves the number?
One price per agent, published: $12,500 for one agent, $3,000 for each additional agent in the same engagement. Fixed fees agreed before anything starts, and nothing is charged until you have approved the scope in writing.
Request a Read Only audit
Two minutes. No account, and nothing is booked automatically.
What we need from you
Nothing you do not already have. Most of this comes out of a morning with your legal, engineering and data teams, and we tell you which extracts before you commit.
- What the agent is supposed to do, in one paragraph
- Which tools and MCP servers it can reach
- Whether you keep execution traces, and for how long
- Whether it runs as itself or as a person
- A name to address the signed report to
What happens next
- You send the five items we need.
- We call to scope it within one business day.
- Nothing is charged until you approve the scope.
Where this page gets its facts
Where the claims on this page come from, and what they are worth - stated, not assumed.
What it is drawn from
- The letter of 3 August 2026, sixteen State AGs
- Alabama DTPA subpoena 26-0007, both public
- Letter dated
- 3 August 2026
- Last read
- 25 August 2026
What it means
- General information about what the statute requires — not legal advice, and no professional relationship.
- Where a scope question is genuinely arguable, our reports say so rather than pick the convenient answer.
Scope & limitation
- No penalty figure appears here. Our own source and the reference this page was written against state the administrative and penal ceilings the other way round from each other — so for a number, go to the Commission.
- Do not rest a binding decision on it; engage qualified counsel, and use it as the start of a scoping conversation rather than as your final word.
Something on this page out of date?
Tell usFrom Insights
Before you commission one
How to Prepare for an AI Audit: The Readiness Checklist
Six things to have ready before the engagement starts. Assembling them takes a fortnight off the clock — and tends to find the first two findings before an auditor does.
What Is an AI Audit? Scope, Standards, and What You Get
An independent review of what your AI actually does, measured against a named standard — not a certificate, and not a review of what the documentation says it does.
What an AI Governance Framework Actually Contains
Five working parts, not a policy document. What each one has to do, how to tell whether yours is real, and why a framework is not the same thing as compliance.
Startups, Meet Your AI Stack: Budget‑Friendly Tools That Scale
For early-stage founders, building an AI-powered toolkit doesn’t have to break the bank. From ideation to growth mode, here’s how startups can tap into affordable, effective AI tools to autom
Eleven questions. Pointed at you.
No email. No signup. Nothing is sent until you choose to send it.
Not our list. On 3 August 2026 the Attorneys General of sixteen states wrote to OpenAI and named eleven categories of material to preserve. Each one is turned round here — from preserve this into could you produce this — and nothing else about it is changed. Nothing on the list is specific to OpenAI: an organisation running agents either holds these records or it does not.
The allegations behind the letter have not been tested, and nothing here states them as fact. It is used as what it is — a published account of what somebody with subpoena power thought worth asking for.
0 of 11
Send the eleven with your enquiry
Whatever you answered above travels with this form. Nothing is scored, ranked or published.
Your evidence check
Eleven questions
Nothing is saved and nothing is sent. No account, no login — answer as many as you like and close it.
Request an agent audit
Any of the eleven you answered travel with this. Nothing is sent until you press send.