AI Agent Management
Guardrail review, authority drift detection and injection testing for agents that act rather than answer, with a monthly report an auditor could read.
| How it is bought | Monthly recurring |
| Duration | 12-month term, 30 days notice after month 3 |
| Written for | Organisations running agents that ACT rather than answer |
An agent that is wrong has already done something. Authority granted at launch tends to widen quietly, and the audit trail is only discovered to be inadequate during an incident.
What you receive
Named artifacts, not activities. If one of these is not delivered, the engagement is not complete.
- Guardrail review: the allow-list, the value ceiling, the blast-radius ceiling and the reversal path, checked against what the agent can actually reach today
- Authority drift detection, because permissions widen and nobody logs the decision
- Action audit: a sample of real actions traced end to end, with the reasoning reconstructable
- Prompt injection testing against the trust boundary, repeated as the retrieval corpus changes
- A monthly report an auditor could read, listing what it did and what it was stopped from doing
How it runs
- Month 1: map every action the agent can take, every system it can reach, and every path a human is supposed to be in.
- Monthly: audit sample, guardrail check, and an injection test against the current corpus.
What this deliberately does not include
Published with the same prominence as the deliverables. A scope with no stated exclusions is a scope that will be argued about later, and the argument always happens at the worst possible moment.
- Agents with no defined boundary. We will define one first, as a project, because there is nothing to manage otherwise.
- Accepting authority for actions we cannot reverse or evidence.
- Business decisions the agent supports. We manage the agent, not the policy it applies.
How you know it is finished
For any action in the period you can show what it did, why, who was affected and how it could have been reversed.
What you need ready
The agent's action inventory, its logs, and the name of whoever owns the authority limits.
Every engagement starts with a written scope confirmation before any invoice is raised. Nothing here is a click-to-buy: we confirm what you need, agree the scope in writing, then invoice. If the scoping conversation shows that a smaller engagement, or none at all, is the right answer, we say so before anything is signed.
Request this engagement Talk it through first See the guardrails demonstrated
We use privacy-friendly analytics by default. Optional analytics cookies load only if you accept.