An Agent Trust Audit establishes what your agents can do, what you could prove afterward, and how fast you could stop them.
Six workstreams, each producing evidence rather than opinion. It ends with a remediation roadmap ordered by blast radius and a written statement of what the audit could not see.
Get an Agent Trust Gap BriefWhat the audit covers
1. Agent & tool inventory
Every agent, every tool it can reach, every credential it holds, and the named human accountable for each. Usually the first time the true count is visible.
2. Permission mapping
What each agent may do versus what it actually can do. The gap between those two is where most findings live.
3. MCP & tool-exposure assessment
Per server and per tool: read, write, spend. Plus readiness for the 2026-07-28 specification before the twelve-month window closes.
4. Evidence & replay assessment
Could you reconstruct a consequential action end to end today? Tested against real actions, not against the documentation.
5. Revocation & kill-switch test
Measured time-to-effect on a live path. Not whether the code exists — whether it works, and how fast.
6. Remediation roadmap
Ordered by blast radius, not by ease. With the honest note where a fix is expensive and the trade-off is yours to make.
The BLOCK / APPROVE / TAMPER test
Every audit includes the three cases that separate a governed estate from an instrumented one. If your system cannot demonstrate all three, that is the finding.
- BLOCK — an out-of-scope action refused before execution, emitting a signed refusal receipt.
- APPROVE — an approval bound to one exact payload and window; modify either and it must refuse.
- TAMPER — alter a stored receipt; chain verification must fail and name where integrity broke.
See the demonstration and the ApexClaw Receipts schema.
What you receive
Findings with evidence
Each names what was observed, how, and on what date. What could not be verified is marked UNKNOWN rather than inferred.
Standards mapping
Gaps mapped to OWASP ASI01–10, NIST AI RMF, ISO/IEC 42001 and the obligations that apply in your jurisdiction — as interpretation, not determination.
Stated limitations
What the audit could not see, in writing. An assessment claiming completeness is not a trust artifact.
Claims boundary This is an assessment, not a certification. No SOC 2, ISO 27001 or EU AI Act conformity is issued or implied. Scope and pricing are set after discovery and remain labelled as targets until formally fixed.
Not sure you need the full audit? Start with the Agent Trust Gap Brief — it is designed to tell you whether the rest is warranted.
Common questions
What does the audit cover?
Agent inventory, the action surface of each agent, identity and credential scoping, policy enforcement points, evidence quality, revocation, and retention against obligation.
What is the deliverable?
A prioritised remediation plan with each finding tied to observed evidence, ordered by the irreversibility of what is currently ungoverned.
Is it framework-mapped?
Yes — findings map to OWASP ASI01–ASI10 and to NIST AI RMF functions, so the output is usable in existing risk processes.
Do you need production access?
Read-only wherever possible. Some findings require observing an action path, which is scoped and agreed in advance.
What if we have no agents in production yet?
Then the audit is cheaper and far more valuable, because controls designed before deployment cost a fraction of controls retrofitted after.