Authority Gap Assessment
Your AI agents can send data, commit spend, and delete records right now, in your name. Most of it was never authorised by anyone. That holds until the day a regulator, an auditor, or a customer asks who signed off, and all you have is a log. Find the gaps before they do. One surface, one fixed fee, results in days, and the map is yours to keep.
Most teams can tell you what their agents did. Almost none can tell you what their agents were authorised to do. That gap stays invisible until the day it isn't. Then your logs meet the one question they cannot answer: who authorised that? The Authority Gap Assessment measures the gap before that day arrives: a fixed-scope engagement that tests what your agents can actually do against the authority anyone granted them.
Rules, named owners, delegated limits.
Tools, permissions, and actions the agent can actually take.
Where action outruns authority, ranked by consequence.
Scope, Timeline, Fee
- Scope
- One authority surface: one autonomous workflow, or one division. Fixed by design: scoped by the surface we assess, not by how many agents run on it. Agent counts change weekly; the governed surface doesn't.
- Timeline
- 5–10 business days from receipt of inputs.
- Fee
- A$15,000 fixed. Credited in full against a Design Partner Evaluation begun within 60 days of delivery.
- Inputs
-
- Your Delegation of Authority or approval matrix (if one exists)
- The agent's tool and permission configuration
- A sample of its activity logs
- A short interview with the workflow owner
- How it runs
-
- A 20-minute scoping call
- A mutual NDA
- Your inputs, then delivery
The Four Questions
Every consequential action the agent can take answers to the same four questions.
-
A ratified rule
Is there a written rule that covers this action at all? Or is the agent doing something no policy ever imagined?
-
A named authority
Whose authority is the agent acting under? Is there a named, accountable owner for the mandate, or no owner at all?
-
A limit
Is there a bound on amount, data scope, or frequency? And does the agent's real capability respect it?
-
A record
Is the action recorded and reviewable the way a human approval would be?
Every no is a gap. Expect ten to thirty on a real register, each one an action your organisation answers for that nobody signed off on.
Who Asks For This
Whoever answers for it when the autonomous system does something nobody authorised.
If an agent's action would land on your desk, you need the gap map before it does.
What You Receive
-
Executive summary
The headline number: how many consequential actions your agents can take today sit outside your authority structure, and how many of those are high-consequence.
-
Authority map
Your existing rules (delegation of authority, approval matrix, signing limits) mapped against the actions they actually govern.
-
Agent capability map
What each agent can actually do, from its tool access, permissions, and activity logs. Not what its description says.
-
Ranked gap register
Every action the agent can take outside your authority structure, classified by consequence, with the evidence that proves each one.
-
Recommendations
The register skeleton: who should own each mandate, within what limits, and how enforcement closes each gap.
-
Forwardable one-pager
One page, board-committee-ready. Your sponsor sends it upward without touching a word.
The assessment stands alone. You keep the gap map whether you go further or not. If the findings call for enforcement, the next step is a Design Partner Evaluation of Ambit Authority at the exact boundary the assessment exposed, and your assessment fee is credited against it in full.
Request an assessment