Assess
Review the agent’s purpose, architecture, models, prompts, memory, tools, data, permissions, workflows, users, vendors and operating environment. Inputs include design documents, configurations, demonstrations, logs, policies, test evidence and stakeholder interviews. The output is a documented risk baseline and evidence-gap register. Client teams provide access, context and accountable owners.