Service

Starter Audit Package

The starter audit package is intentionally narrow: one scoped workflow, one forbidden condition, a small model, a bounded check, and a Bounded Replay Verification Report that preserves assumptions.

Approval gates only protect against composed misuse if the workflow definition actually forces the agent through them.

Starter Package

Bounded Replay-Risk Audit — Starter Package

  • one workflow
  • one forbidden condition
  • small Boolean model
  • bounded verifier run
  • Bounded Replay Verification Report
  • remediation note
  • optional guarded retest

What you provide vs. what the audit models

You do not need to arrive with a formal Boolean model. Typical starting materials are an agent prompt, tool/function schema, MCP/server tool list, approval rule, workflow diagram, runbook, policy description, or product spec. The audit step translates that material into a small explicit workflow model: state variables, actions, preconditions, effects, forbidden condition, bound, assumptions, and exclusions. The customer-facing review point is the model boundary: what is included, what is excluded, and what the result can support.

Acceptable starting materials

  • agent prompt or system message
  • tool / function schema
  • MCP or server tool list
  • approval, confirmation, or escalation rule
  • workflow diagram or runbook
  • policy description or product spec

What the audit produces from that

  • state variables
  • actions with preconditions and effects
  • forbidden condition
  • configured bound
  • assumptions and exclusions
  • Bounded Replay Verification Report

Best-Fit Buyers

  • AI-agent builders
  • SaaS workflow owners
  • support-ops teams
  • product/security managers
  • compliance/security reviewers

Best-Fit Risks

  • workflow approval bypass
  • confirmation bypass
  • external disclosure before review
  • destructive action before confirmation
  • permission escalation before authorization
  • sensitive data export before authorization
  • composed action ordering across agent tool-use

Request a starter audit

To start, provide one workflow, one dangerous outcome, and the approval/confirmation rule that should block it. Use the customer input template as the intake format, or send equivalent workflow/tool documentation for modeling. Plain-language input is acceptable; the audit step translates it into the formal model.

Open a GitHub issue or share the completed template through your normal contact channel.

Not Included

  • unrestricted system safety determination
  • full IAM/cloud graph review
  • penetration testing replacement
  • probabilistic LLM behavior analysis
  • legal/compliance certification
  • third-party independent benchmark validation