Workflow module
The vendor and model review
Document the model, provider, and terms behind the agent — because a brand name is never a substitute for evidence.
Document the model, provider, and terms behind the agent — because a brand name is never a substitute for evidence.
Why it matters
Every agent inherits the behaviour, data handling, and limits of the model and provider underneath it. A familiar brand name tells you nothing about the version in use, the terms it runs under, or the dependencies it carries.
What good looks like
A dedicated record captures the model, provider, version, terms, data handling, and dependencies — each with what is known and what is still to verify. An assessment status reads Not assessed, In progress, Insufficient evidence, or Assessed, alongside a confidence level of High, Medium, Low, or Unknown. Blank fields read as honestly unknown rather than quietly satisfied.
What can go wrong
The dependency is 'it uses a big-name model' and nothing more. Version, terms, and dependencies are never written down. 'Assessed' is claimed with no evidence, so 'Insufficient evidence' is never distinguished from a real assessment. A model change slips in unnoticed and the record no longer matches reality.
What AgentProof checks
AgentProof structures the six vendor and model fields, counts what is known versus blank, and holds the four-state assessment machine plus a confidence key that keeps Insufficient evidence distinct from Assessed. It links vendor docs and model cards from the evidence register. It documents the dependency — it does not endorse, certify, or approve any vendor or model.
Key terms
The exact vocabulary this part of the record uses — grounded in the shipped product model.
- Vendor fields
- model, provider, version, terms, data_handling, dependencies.
- Assessment status
- not_assessed, in_progress, insufficient_evidence, assessed — insufficient evidence stays distinct from assessed.
- Confidence
- high, medium, low, unknown.
- Evidence types
- model_card, vendor_doc, data_sheet — linked from the evidence register.
Keep reading
Build this record for your own agents
AgentProof turns each part of this into one documented, evidence-backed record — before your compliance review.
Ready to build a compliance-readiness record for your own agent?
Request a compliance readiness pilot to apply this guidance to a real agent.
AgentProof builds a compliance-readiness record, not an official audit, and it does not speak on behalf of any vendor.