Most AI agent incidents aren't model failures. They're permission failures: an agent that could read the production database, a grant that never expired, a credential that lived in a prompt. If you're putting agents near production, run this audit first. Twelve questions, each with what "good" looks like.
1. Can you list every integration each agent can touch?¶
If the answer is "roughly," you don't have an inventory — you have a hope. Good looks like a registry: one row per agent, one row per integration, with the exact scopes granted. This is the cheapest control you own and the one most teams skip.
2. Are grants time-boxed, or permanent?¶
Permanent grants are how a forgotten prototype becomes a breach six months later. Good: every grant carries an expiry date, and expiry is enforced by the system, not by someone remembering to clean up.
3. Who approved each grant — and where is the record?¶
"The team decided" is not an approval record. Good: each grant names an approver, a date, and a reason, stored somewhere an auditor can read without asking you.
4. Can agents see credentials, or only use them?¶
An agent that can read an API key can exfiltrate it. Good: credentials live in a vault or broker; the agent receives short-lived tokens scoped to the task, never the raw secret.
5. Is there a spend ceiling per agent, per workload?¶
Agents don't get tired, and metered APIs don't get cheaper at 3 a.m. Good: every agent workload has a spend ceiling, and hitting it fails closed — the agent stops, it doesn't keep going on vibes.
6. What happens when an agent hits a limit?¶
The wrong answer is "it retries." Good: limits trigger a defined block response — stop, log, notify a human. The runbook for a blocked agent should exist before the first block, not after.
7. Are high-risk actions hard-gated on human approval?¶
Money movement, external messages, permission changes, production writes: these should never be "bounded auto." Good: a hard-gated list exists, it's short, and bypassing it requires a recorded exception, not a config tweak.
8. Do denied actions produce evidence?¶
A blocked action nobody logged is a near-miss nobody learned from. Good: every denial writes a structured log row — who, what, when, why denied — that your audit trail can show an auditor.
9. Can you reconstruct what an agent did last Tuesday?¶
"It probably didn't run" is not an audit trail. Good: every agent action appends to a tamper-evident log with timestamps, inputs, and outcomes. If you can't replay the day, you can't prove anything about it.
10. Is there a quarantine path for a misbehaving agent?¶
Agents will misbehave — that's not pessimism, it's operations. Good: a one-page runbook exists for isolating an agent in the first hour without taking down the rest of the fleet.
11. When did you last re-tier your agents?¶
Risk tiers drift: new integrations arrive, scopes widen, prototypes become load-bearing. Good: a quarterly access review re-tiers every agent against what it can actually touch today, not what the original design doc said.
12. Who owns decommissioning?¶
Retired agents with live credentials are the most common zombie in the stack. Good: decommissioning is a checklist with an owner — revoke grants, rotate shared secrets, archive logs — run the day the agent retires, not "eventually."
How to run the audit¶
Block ninety minutes. Pull your agent inventory, your grant list, and one recent incident (or near-miss). Score each question red/yellow/green. Anything red gets an owner and a date. Repeat quarterly — the first audit finds the gaps; the second one proves they're closing.