AAgentProof

Workflow module

The control checklist

Map the guardrails an agent should have to the evidence that proves them — so no control passes on assertion alone.

Five-key statesDerived needs-evidenceFramework-mappedCoverage-not-compliance

Map the guardrails an agent should have to the evidence that proves them — so no control passes on assertion alone.

Why it matters

The fuzzy question 'is this agent safe enough?' only becomes manageable when it is a concrete, inspectable list of guardrails with states, owners, and evidence. A checklist makes the gaps visible instead of leaving them to a gut feeling.

What good looks like

Each control carries an owner, an applies-when condition, a review frequency, a test method, and one of five honest states — Not started, In progress, Implemented, Needs evidence, or Not applicable. An Implemented control with no linked accepted, non-stale evidence is shown as Needs evidence automatically — the effective state is derived, not taken on trust. Controls map to the governance lenses they support, so the same list answers several framework questions at once.

What can go wrong

Controls are a slide deck rather than real behaviour and evidence. Everything reads 'Implemented' because someone ticked a box. 'Not applicable' is used to make gaps disappear. Ownership is unclear, so when a control needs attention no one is on the hook for it.

What AgentProof checks

AgentProof runs the five-key control-status machine, applies the derived rule (implemented without accepted evidence becomes Needs evidence) and flags when that rule fired, records the owner, frequency, and test method, and maps each control to the framework profiles it supports. It reports coverage of guardrails and evidence — not a pass or fail verdict.

Key terms

The exact vocabulary this part of the record uses — grounded in the shipped product model.

Control status
not_started, in_progress, implemented, needs_evidence, not_applicable.
Derived needs-evidence rule
An implemented control with no accepted, non-stale evidence is shown as Needs evidence automatically.
Owner class
The role accountable for the control.
Review frequency
How often the control is expected to be re-checked.
Test method
How the control is verified in practice.
Mapped profiles
The framework lenses a control supports — EU, UK, US, NIST, ISO 42001, OWASP.

Keep reading

Build this record for your own agents

AgentProof turns each part of this into one documented, evidence-backed record — before your compliance review.

Ready to build a compliance-readiness record for your own agent?

Request a compliance readiness pilot to apply this guidance to a real agent.

AgentProof builds a compliance-readiness record, not an official audit, and it does not speak on behalf of any vendor.