READ ONLY · CONFIGURATION AND TRACES · 1–3 WEEKS

Your agent is documented for 12 actions. Its credentials permit 47.

The two lists are never the same, and almost nobody has ever put them side by side. This is the audit that does.


Snapshot Full Assay Fleet Assay
Read-only access, always Signed by a named ISO/IEC 42001 Lead Auditor About one day of your engineer's time

Format

What this involves

Access needed
Read-only: config, credentials scope, traces
Your time
About one day of one engineer
Runs in
1 to 3 weeks
Evidence
What the agent is permitted to do, and did
From
$4,500
01
The finding

The gap

Every agent has two capability lists.

The first is what it is documented to do — the tools in the spec, the actions in the design note, the description in the security review.

The second is what its credentials actually permit. That list is longer. It is always longer.

An OAuth token scoped for "read email" typically carries send, delete and folder access, because that is how the scope is packaged. A database tool the spec calls read-only usually holds write. An agent running under a staff member's SSO can do everything that person can do, which on most teams is a great deal.

Nobody chose the second list. It arrived as a side effect of how permissions are granted.

The report says: here are the actions nobody approved. It is usually the shortest page and the first one anyone reads.

02
The method

What we read

Read-only, always. We take nothing we were not given and we change nothing.

  • Tool and MCP manifests

    Every function and server the agent can call.

  • Credential scopes

    The real permission set behind each token, key and role.

  • Execution traces

    LangSmith, Langfuse, model-provider logs, CloudTrail, or whatever you keep.

  • Identity configuration

    Whether the agent acts as itself or wears a person's credentials.

About a day of one engineer's time on your side, mostly granting read access and answering questions.

03
The deliverable

The eleven, answered

On the overview we set out the eleven categories of material sixteen State Attorneys General asked OpenAI to preserve on 3 August 2026.

This audit answers them for you. Each one gets your position, the evidence that supports it, or a plain statement that no evidence exists. That last outcome is not a failure — it is the most common result, and knowing it before someone asks is the entire value.

Three layers

What it costs

Fixed fee, agreed before anything starts. Nothing is charged until you have approved the scope in writing.

Snapshot

$4,500
one-off
1 week

Configuration and the capability gap, at a point in time.

The fastest route to the one number that matters. No traces, no behavioural findings.

  • Capability register
  • Declared-versus-permitted gap
  • Written findings

Fleet Assay

$19,500
one-off
4–6 weeks

Up to five agent systems, each with its own signed report.

When agents have multiplied faster than anyone documented them.

  • Full Assay on each of five systems
  • Cross-system comparison
  • Five signed reports

Beyond five agents, $2,500 per additional agent.

These are published fees, not estimates. Where an engagement genuinely does not fit one of the three, we will say so and quote the work rather than force it into a tier.

Stated plainly

What this is not

  • Not a compliance certificate. No law requires an AI agent audit, and we will not imply one does.
  • It does not make you compliant with anything. It tells you what is true.
  • Not a penetration test of your wider estate.
  • It does not assess whether your model's answers are correct. That is evaluation work, and a different discipline.

Accountability

Who signs it

Every report is signed by Brijesh Patel, ISO/IEC 42001 Lead Auditor, who performed the work.

Not a firm name on a template. A person, named, who read the evidence and reached the finding — and who can be asked about it afterwards.

There is no statute behind an agent audit. What makes the report worth anything is that a qualified human put their name on it and would say the same thing under questioning. That is the instrument.

The firms best placed to audit your agent are the firms that built it for you. A consultancy cannot independently assess work its own team implemented, and will not give up the implementation revenue to try. We do not build agents. That is the only reason this report is worth anything.

Fit

Who this is for

  • Agents already running in production
  • Teams facing a customer security review or a vendor questionnaire that has started asking about agents
  • Anyone who needs a document a third party will read — a customer, an insurer, a board, or a regulator

The three methods

If this is the wrong one

They differ by how much access you give us, and therefore by how strong the evidence is. More access, better evidence — there is no way around that trade.

Not sure which? Start with the eleven questions — how many you can answer tells you which method you need.

Before you ask

Questions

How much of our engineer's time does this take?

About a day, spread over the engagement. Mostly access grants and clarifying questions.

Can you do this without touching production?

Yes, if your staging configuration genuinely mirrors production. We will tell you if it does not, and what that costs you in confidence.

Do you use AI to run the audit?

To collect evidence, yes — enumerating permissions, parsing traces, running the battery. To reach the verdict, no. An assayer uses instruments; the instruments do not sign the certificate.

What if we do not keep traces?

Then Snapshot is where you start, and the first recommendation in your report will be about what to begin recording.

Next step

Request a Read Only audit

Two minutes. No account, and no call booked automatically. We reply within two working days with a scope and a fixed fee — or with an honest reason this is not the right method for you.

Start the request

Sources. Letter of 3 August 2026 from the Attorneys General of sixteen states to OpenAI, and Alabama Deceptive Trade Practices Act Subpoena Duces Tecum No. 26-0007. Both public. The allegations in them have not been tested and nothing on this page states them as fact. Primary documents last read by a human on 25 August 2026.