How it works
One workflow, from the whole estate to a frozen compliance-readiness record.
AgentProof documents an AI agent and assembles the compliance-readiness record your review needs, a review-ready record, not a compliance verdict. The workflow runs in five beats; the eleven practitioner steps sit beneath the beat they belong to.
Request a compliance readiness pilotBeat 1
See the whole AI-agent estate
Start from one estate across manual, discovered, connected, and hybrid environments, with every agent and its source in one place.
- 1
Identify the agent
Start from one AI estate inventory. Pull agents in from a connected source such as Microsoft Power Platform and Copilot Studio, add manual and hybrid environments, and enter agents by hand, including proposed, piloted, and shadow agents. Discovered and manually added agents live together, each showing its source, owner, and status, so nothing that could reach real work is missing from the record.
Beat 2
Know the agent
Capture what each agent actually is and how much scrutiny it needs, then view it through the governance and regulatory lenses you select.
- 2
Confirm the minimum unresolved facts
Confirm only the unresolved facts needed to determine what happens next: the agent's purpose, its owner, the users and people it affects, the data it can reach, the tools and actions it can take, and the model and vendor behind it. Existing confirmed answers are shown immediately and remain editable; workspace, environment, and prior-answer facts are inherited rather than re-entered. Unknowns are recorded as unknowns, not guessed, because a captured gap is more useful than a confident guess.
- 3
Run a quick triage
A fast, structured triage flags the risk-relevant signals that matter and sets an assessment depth, from light to standard, enhanced, or strict. An agent that only reads and drafts is a different proposition to one that can send, pay, or change records, and high-impact signals route to a deeper review straight away.
- 4
Apply governance and regulatory lenses
View the same agent through the jurisdiction-aware lenses you select, drawn from EU, UK, US, NIST, ISO 42001, and OWASP. Each lens is a documentation and evidence coverage map: what may apply, what evidence supports review, and what is missing. Coverage of expectations, never a scored verdict, and missing information stays visible rather than hidden.
Beat 3
Evidence the record
Back every claim with real evidence: the evidence register, the control checklist, the test pack, and the vendor and model review.
- 5
Register the evidence
Attach the real artefacts the applicable follow-ups call for into the evidence register, permissions and scopes, prompts and configuration, data-flow notes, sign-offs, and screenshots, and track each through its lifecycle. Received is not the same as accepted, and the register keeps that distinction visible, so from here every claim is backed by something a reviewer can inspect.
- 6
Work the control checklist
Move through the control checklist to record which of the applicable controls exist and their state, from not started through implemented or not applicable. Fuzzy is this safe enough worry becomes a concrete, inspectable list of guardrails, and the real gaps stop hiding behind a score.
- 7
Run the test pack and review the vendor and model
Record how the agent held up against the applicable checks in the test pack, hallucination, injection, jailbreak, leakage, tool-boundary and unapproved-action checks, and bias, and complete the vendor and model review of terms, data handling, model details, and support. Behaviour and dependencies become documented evidence, not assumptions, because a brand name is never a substitute for evidence.
Beat 4
Decide
Record the decision to trust the agent, with who decided and on what basis, then freeze a versioned compliance-readiness record in your workspace.
- 8
Record the decision
Capture the approval and decision record: who reviewed the agent, what they saw, the conditions they attached, and the call itself, from draft, blocked, approved for pilot, approved with restrictions, approved for production, to retired. Who approved what, and with what limits, becomes part of the record, without ever implying a legal or regulatory conclusion.
- 9
Freeze the compliance-readiness record
When you need to stand behind a decision, freeze a versioned, review-ready compliance-readiness record per agent, the profile versions, evidence, controls, tests, and decisions as they stood. Stakeholders, technical, business, security, and legal, review one stable record instead of chasing scattered artefacts.
Beat 5
Keep current
Keep the record alive after go-live, and let Radar recommend reassessment for the specific agents a tracked change may affect.
- 10
Monitor and log incidents after go-live
Once an agent is in real use, record how it is monitored and log incidents when its behaviour drifts. The record stays alive and honest, reflecting the agent as it runs rather than freezing at the approval and quietly going out of date.
- 11
Reassess with Radar when the landscape moves
Radar tracks governance, regulatory, model, and failure-mode sources and flags when a tracked change may affect an agent, recommending reassessment for the specific agents involved. Previously frozen records stand exactly as they were; a new assessment produces a new version. You decide what to revisit and when, so the record was current when you signed off and stays that way on purpose.
Where capability zones fit
Each agent's capability zone, Knowledge / Retrieval, Task / Tool-Assisted, or Autonomous Action, describes what it can do on its own. Quick triage captures those facts and sets a proportionate review posture, light, standard, enhanced, or strict, so an agent that can call tools or update systems is held to stronger evidence expectations than one that only answers questions.
Read about capability zonesCompliance Readiness Pilot: €1,500 fixed, up to 5 AI agents (one-time). It walks up to five of your AI agents through this full workflow and builds a versioned compliance-readiness record in your workspace for each, its inventory, assessment, evidence, controls, and gaps.