Enterprise Services

AI Agent Management

Guardrail review, authority drift detection and injection testing for agents that act rather than answer, with a monthly report an auditor could read.

AI Agent Management
How it is boughtMonthly recurring
Duration12-month term, 30 days notice after month 3
Written forOrganisations running agents that ACT rather than answer

An agent that is wrong has already done something. Authority granted at launch tends to widen quietly, and the audit trail is only discovered to be inadequate during an incident.

What you receive

Named artifacts, not activities. If one of these is not delivered, the engagement is not complete.

  • Guardrail review: the allow-list, the value ceiling, the blast-radius ceiling and the reversal path, checked against what the agent can actually reach today
  • Authority drift detection, because permissions widen and nobody logs the decision
  • Action audit: a sample of real actions traced end to end, with the reasoning reconstructable
  • Prompt injection testing against the trust boundary, repeated as the retrieval corpus changes
  • A monthly report an auditor could read, listing what it did and what it was stopped from doing

How it runs

  • Month 1: map every action the agent can take, every system it can reach, and every path a human is supposed to be in.
  • Monthly: audit sample, guardrail check, and an injection test against the current corpus.

What this deliberately does not include

Published with the same prominence as the deliverables. A scope with no stated exclusions is a scope that will be argued about later, and the argument always happens at the worst possible moment.

  • Agents with no defined boundary. We will define one first, as a project, because there is nothing to manage otherwise.
  • Accepting authority for actions we cannot reverse or evidence.
  • Business decisions the agent supports. We manage the agent, not the policy it applies.

How you know it is finished

For any action in the period you can show what it did, why, who was affected and how it could have been reversed.

What you need ready

The agent's action inventory, its logs, and the name of whoever owns the authority limits.

Start this engagement

Every engagement starts with a written scope confirmation before any invoice is raised. Nothing here is a click-to-buy: we confirm what you need, agree the scope in writing, then invoice. If the scoping conversation shows that a smaller engagement, or none at all, is the right answer, we say so before anything is signed.

Request this engagement Talk it through first See the guardrails demonstrated

Browse enterprise services