READ ONLY · CONFIGURATION AND TRACES · 1–3 WEEKS

Documented for 12 actions. Its credentials permit 47.

Two capability lists - what the agent is documented to do, and what its credentials permit. Almost nobody has compared them.


A reviewer with a beard, in a grey blazer over a black T-shirt, seated at a dark stone desk by a window in a warm, low-lit office, signing a printed page with further papers and a stoneware cup beside them.
We read it. We change nothing.
Read-only access One day of your time 1-3 weeks Signed report $12,500 one agent

Our promise

“Documentation is a claim. The credential is evidence.”

Every finding is written against a named control — defensible line by line, to anyone who asks. The fee is fixed at $12,500, and nothing is charged until you approve it.

Request this Read Only audit
The finding

The capability gap, in three chapters

The Law

Every agent in production has two capability lists. The first is what it is documented to do: the tools in the spec, the actions in the design note, the description that went into the security review. It is the list your team wrote, and the one every answer you give about the agent is based on.

The Gap

The second is what its credentials actually permit, and it is always longer. A scope packaged for reading mail carries sending and deleting; a database tool the spec calls read-only usually holds write. Nobody chose that second list - it arrived as a side effect of how access is granted.

The Office

We put the two lists side by side, which almost nobody has ever done. Read-only throughout: manifests, credential scopes, traces and identity configuration. The report opens with the actions nobody approved - usually its shortest page, and reliably the first one anyone reads.

Scope & limits

What we read, and what this is not.

Read-only access to four things, and about one day of one engineer - we change nothing on your systems.

What we read № 01
  • Tool and MCP manifests - every callable function
  • Credential scopes behind each token, key and role
  • Execution traces, from whatever you already keep
  • Identity: itself, or a person’s credentials
Read Only · iDharma · Presented for review
What this is not № 02
  • Not a compliance certificate. No law requires one
  • It does not make you compliant. It tells you what is true
  • Not a penetration test of your wider estate
  • Not an evaluation of whether answers are correct
Read Only · iDharma · Presented for review
The two lists

Two lists. Only one was chosen.

The first list

What it is documented to do

The tools named in the spec, the actions in the design note, the description that went into the security review, and nothing at all beyond them. This is the list your team wrote and the one everybody on it has read, and it is the one behind every answer you give about the agent to anybody who asks.

The second list

What its credentials permit

The real permission set behind each token, key and role, as it actually stands rather than as it was requested. A scope packaged for reading mail carries sending and deleting with it; a database tool the spec calls read-only usually holds write. This list is longer than the first one. It is always longer.

The catch

Nobody chose the second one

Nobody ever chose this list. It arrived as a side effect of how permissions are granted inside your organisation, which is why no one has ever read it end to end. An agent running under a staff member’s SSO can do everything that person can do, and on most teams that turns out to be a very great deal.

What most teams assume

“Our agent only reads email.”

What the scopes say

Its token can send and delete.

It is the first thing we have to correct.

  • Who it is for
  • Agents in production
  • Teams in a security review
  • Vendor questionnaires
  • Boards & insurers
  • Anyone asked for evidence
Why this matters
A black archive box closed on a dark desk under warm light, its brass label plate still blank, with a red wax seal at the edge of the papers inside and a stamped impression lying beside it.
01 An agent documented for twelve actions routinely holds credentials for far more. Nobody chose the second list - which is exactly why nobody has ever read it end to end.
02

Sixteen State Attorneys General listed eleven things to preserve about agent testing. This audit answers them for you, before anybody asks.

03

The most common answer is that no evidence exists at all. Knowing that before somebody outside asks is the whole point of asking early.

04

Read-only throughout. We take nothing we were not given, we exploit nothing, we change nothing, and every access is logged at your end.

The 60-second check

Three questions. Then you’ll know.

No email. No signup. A starting point, not a determination.

0 of 3

In production -

This decides whether there is anything to read. An agent with credentials against production systems has a permission set somebody granted and nobody has since enumerated. One in staging only is worth checking too, but the finding is weaker.

The gap -

This is not a second scope test. It sorts how much of the work is already done. Documented actions against permitted actions - not the design note on its own, and not the token scopes on their own, but the two set side by side.

Traces -

This decides which tier you can buy. Traces are what turn "what it could do" into "what it did". Without them the configuration finding still stands, but the behavioural one cannot be written at all.

The engagement

Read-only, from day one to signature.

Four moments in the engagement. Your side of it is about one engineer for about one day.

  1. Access granted

    Day one

    Read-only, and nothing else. We take nothing we were not given, and we change nothing at any point.

  2. Configuration read

    Week one

    Manifests, credential scopes and identity configuration - which produces the gap, and the gap is the finding.

  3. Traces read

    Weeks two to three

    Thirty days of execution traces against that permission set: not what it could do, but what it did do.

  4. Signed

    On delivery

    You see the draft first. The report is then signed by the named auditor who read it, rather than by the firm.

The trap

A staging configuration that does not genuinely mirror production gives you a report about staging. Staging usually carries narrower credential scopes - so a clean result there says very little about the thing you actually run.

Findings & coverage

What we read, what you get

12 findings: the capability gap, then the eleven categories, each with the exposure behind it.

The capability gap The lead finding
Every action the credentials permit that the documentation never claimed, listed rather than counted - the actions nobody approved. It is assembled from the tool and MCP manifests, the real scope behind each token, key and role, and the identity the agent runs under, then set against what your own spec and design note say it does. Usually the shortest page in the report, and the first one anyone reads.
The incident record Of the eleven
Could you produce a full record of an unintended action, and all it touched? No per-action trace. A summary is not a record.
How you found out Of the eleven
Could you show when you found out — and that you found it, not an outsider? No independent detection. Discovery depends on a third party.
Which model ran Of the eleven
Could you identify exactly which model and version ran, pre-release included? Model provenance not recorded per run.
Your own review Of the eleven
Do you have a written internal review, and does it match what you said publicly? No written review, or a review that diverges from public statements.
Credential use Of the eleven
Has an agent ever used account-level credentials it was not given? Credential discovery and reuse is untracked.
Offensive evaluations Of the eleven
Which evaluations push a model toward attack paths, and who authorised it? Offensive testing runs without a named authoriser.
Prior incidents Of the eleven
Could you produce every earlier unauthorised access — or state there were none? No incident history. "None that we know of" is not an answer.
Self-persistence Of the eleven
Has an agent left notes for future versions on working around its constraints? Agent-written artefacts are not inspected.
Evaluation safety policy Of the eleven
Do you have an evaluation-safety policy, dated before your most recent test? No dated policy. A policy written after the fact proves nothing.
Concerns raised Of the eleven
Could you produce every safeguard concern your staff raised, acted on or not? Internal concerns are discoverable and unmanaged. Usually the sharpest exposure.
Who knew Of the eleven
Could you name every person involved in, or with knowledge of, the above? No named custodians.
The engagement

Personal information, independently reviewed

From the CRM to the model in the decision path.

  1. Access

    Read access to config, credential scopes, traces and identity.

  2. Read

    What the agent is permitted to do, against what it actually did.

  3. Sign off and evidence

    You see the draft first. Then a report signed by the person who read it.

Request this audit
An auditor in a dark navy shirt and trousers, wearing a wristwatch, standing against a warm pale wall and pointing into the open space alongside.
The assessment is the evidence - that is what you are buying.
Struck in your favour

Why teams choose iDharma for their agent audit

Read-only, always

We take nothing we were not given, and we change nothing on your systems.

A named signature

Signed by the ISO/IEC 42001 Lead Auditor who read it, not by the firm.

A day of your time

About one engineer for one day, mostly granting access and answering questions.

The eleven, answered

Each with your position, the evidence for it, or a plain note that none exists.

Four marks, struck on every report.

Deliverables

What you get

Concrete artefacts, each with a name and a format - you know what lands before you buy.

Signed Read Only report

The full audit: what your agent is permitted to do, what it actually did, and the distance between those two - written finding by finding rather than reduced to a score. Signed by the named auditor who read the evidence, not by the firm. This is the document you hand to the customer, the insurer or the board that asked, and it is written to be read by someone outside your team.

Register

Capability register

Every tool, MCP server and function the agent can actually reach, taken from the manifests themselves rather than from the description in the design note.

Finding

Declared against permitted

The gap as a count and as a list: every single action the credentials allow that no document ever claimed, which is the finding people read first.

Analysis

Execution traces, read

Thirty days of history against the permission set - what the agent actually did, from whatever you already keep rather than new instrumentation.

Finding

Containment finding

Whether the agent acts as itself or wears a person’s own credentials, and what that means for the blast radius if a single prompt goes wrong.

Finding

Detection finding

Whether you would find out on your own, or from somebody outside. On most estates this one is answered by the absence of the record, not by it.

Positions

The eleven, answered

A position on each of the eleven categories, with the evidence that supports it or else a plain statement that none exists - dated and signed.

Format & fee

Real numbers, upfront.

One agent
$12,500 1 to 2 weeks
Each additional agent
$3,000 in the same engagement
Annual renewal
$10,500 locked at this price

Fixed before anything starts. Each additional agent in the same engagement is $3,000. A re-audit after a change to the agent or its model is $8,000. Nothing is charged until you approve.

Request this audit
Read Only · One agent $12,500 one-off
  • Permission set, granted against actual
  • Tool and credential inventory
  • Full transcript
  • Findings signed by a named auditor
Show your hand

Four things you have to be able to produce

An audit is not graded on intent. Each of these is either in your hand on the day someone asks, or it is not.

The register,
complete

Every tool, server and function the agent can call, enumerated from the manifests themselves rather than from the design note somebody wrote before it shipped.

The gap,
numbered

Documented actions against permitted actions, as a count and as a list. It is a single number, and it is the number that every other finding in the report hangs off.

The traces,
read

Thirty days of execution history against that permission set - not what the agent could have done, but what it actually did while nobody was reading the logs.

The eleven,
answered

Each of the eleven with your position and the evidence for it, or a plain statement that no evidence exists at all - which is the most common answer of the three.

Four cards, and each one is evidence or it is nothing.

FAQ

Plain answers

What the law is, whether it reaches you, the clock, and where AI lands. Answered straight.

Request this review
What does a Read Only agent audit actually produce?

A signed report with the capability gap at the front: every action your agent’s credentials permit that no document ever claimed. Then containment, detection, and a position on each of the eleven categories.

How much of our engineer’s time does this take?

About a day, spread over the engagement. Mostly access grants and clarifying questions.

Can you do this without touching production?

Yes, if your staging configuration genuinely mirrors production. We will tell you if it does not, and what that costs you in confidence.

What are the eleven?

Eleven categories of material that sixteen State Attorneys General asked OpenAI to preserve in a letter of 3 August 2026 - the incident record, how you found out, which model ran, and eight more. This audit answers them for you.

What does it cost, and what moves the number?

One price per agent, published: $12,500 for one agent, $3,000 for each additional agent in the same engagement. Fixed fees agreed before anything starts, and nothing is charged until you have approved the scope in writing.

Get started

Request a Read Only audit

Two minutes. No account, and nothing is booked automatically.

What we need from you

Nothing you do not already have. Most of this comes out of a morning with your legal, engineering and data teams, and we tell you which extracts before you commit.

  1. What the agent is supposed to do, in one paragraph
  2. Which tools and MCP servers it can reach
  3. Whether you keep execution traces, and for how long
  4. Whether it runs as itself or as a person
  5. A name to address the signed report to

What happens next

  1. You send the five items we need.
  2. We call to scope it within one business day.
  3. Nothing is charged until you approve the scope.
Request this audit
Sources & standing

Where this page gets its facts

Where the claims on this page come from, and what they are worth - stated, not assumed.

What it is drawn from

  • The letter of 3 August 2026, sixteen State AGs
  • Alabama DTPA subpoena 26-0007, both public
Letter dated
3 August 2026
Last read
25 August 2026

What it means

  • General information about what the statute requires — not legal advice, and no professional relationship.
  • Where a scope question is genuinely arguable, our reports say so rather than pick the convenient answer.

Scope & limitation

  • No penalty figure appears here. Our own source and the reference this page was written against state the administrative and penal ceilings the other way round from each other — so for a number, go to the Commission.
  • Do not rest a binding decision on it; engage qualified counsel, and use it as the start of a scoping conversation rather than as your final word.

Something on this page out of date?

Tell us
Schedule of requests

Eleven questions. Pointed at you.

No email. No signup. Nothing is sent until you choose to send it.

Where the eleven come from

Not our list. On 3 August 2026 the Attorneys General of sixteen states wrote to OpenAI and named eleven categories of material to preserve. Each one is turned round here — from preserve this into could you produce this — and nothing else about it is changed. Nothing on the list is specific to OpenAI: an organisation running agents either holds these records or it does not.

The allegations behind the letter have not been tested, and nothing here states them as fact. It is used as what it is — a published account of what somebody with subpoena power thought worth asking for.

0 of 11

The incident record -

What a no means. No per-action trace. A summary is not a record.

How you found out -

What a no means. No independent detection. Discovery depends on a third party.

Which model ran -

What a no means. Model provenance not recorded per run.

Your own review -

What a no means. No written review, or a review that diverges from public statements.

Credential use -

What a no means. Credential discovery and reuse is untracked.

Offensive evaluations -

What a no means. Offensive testing runs without a named authoriser.

Prior incidents -

What a no means. No incident history. "None that we know of" is not an answer.

Self-persistence -

What a no means. Agent-written artefacts are not inspected.

Evaluation safety policy -

What a no means. No dated policy. A policy written after the fact proves nothing.

Concerns raised -

What a no means. Internal concerns are discoverable and unmanaged. Usually the sharpest exposure.

Who knew -

What a no means. No named custodians.

Request an audit

Send the eleven with your enquiry

Whatever you answered above travels with this form. Nothing is scored, ranked or published.

What we need from you

Nothing you do not already have. Most of this is what your own team knows about the agents you run, and we name what we need in writing before you commit to anything.

  1. Which agents you run, and what each one decides
  2. How many there are, and whether any are in production
  3. What each can reach - tools, APIs, the data behind
  4. Whether it acts under its own identity or a person's
  5. Your target date for a read, if you have one

What happens next

  1. You send this, with whatever you answered above.
  2. We read it and reply within two working days.
  3. Nothing is charged until you approve the scope.

Your answers to the eleven will be attached.

Request an agent audit

Send your enquiry

Six fields and two boxes, only three of them required, and nothing to attach.

Your answers to the eleven will be attached.