Authority Gap Assessment

Your AI agents can send data, commit spend, and delete records right now, in your name. Most of it was never authorised by anyone. That holds until the day a regulator, an auditor, or a customer asks who signed off, and all you have is a log. Find the gaps before they do. One surface, one fixed fee, results in days, and the map is yours to keep.

Most teams can tell you what their agents did. Almost none can tell you what their agents were authorised to do. That gap stays invisible until the day it isn't. Then your logs meet the one question they cannot answer: who authorised that? The Authority Gap Assessment measures the gap before that day arrives: a fixed-scope engagement that tests what your agents can actually do against the authority anyone granted them.

Authority granted

Rules, named owners, delegated limits.

Capability observed

Tools, permissions, and actions the agent can actually take.

Gap register

Where action outruns authority, ranked by consequence.


Scope, Timeline, Fee

Scope
One authority surface: one autonomous workflow, or one division. Fixed by design: scoped by the surface we assess, not by how many agents run on it. Agent counts change weekly; the governed surface doesn't.
Timeline
5–10 business days from receipt of inputs.
Fee
A$15,000 fixed. Credited in full against a Design Partner Evaluation begun within 60 days of delivery.
Inputs
  • Your Delegation of Authority or approval matrix (if one exists)
  • The agent's tool and permission configuration
  • A sample of its activity logs
  • A short interview with the workflow owner
How it runs
  • A 20-minute scoping call
  • A mutual NDA
  • Your inputs, then delivery

The Four Questions

Every consequential action the agent can take answers to the same four questions.

  1. A ratified rule

    Is there a written rule that covers this action at all? Or is the agent doing something no policy ever imagined?

  2. A named authority

    Whose authority is the agent acting under? Is there a named, accountable owner for the mandate, or no owner at all?

  3. A limit

    Is there a bound on amount, data scope, or frequency? And does the agent's real capability respect it?

  4. A record

    Is the action recorded and reviewable the way a human approval would be?

Every no is a gap. Expect ten to thirty on a real register, each one an action your organisation answers for that nobody signed off on.


Who Asks For This

Whoever answers for it when the autonomous system does something nobody authorised.

Operating mandate CEO / Founder In an AI-native company, the agents act under your name. One signature approves this engagement. No committee. Walk into your customers' risk reviews already holding the authority story they're asking for.
Head of AI / CTO You and your platform or engineering leads own what the agents do in production, whether you signed off on it or not. The gap map separates what was deliberately authorised from what merely works.
Risk ownership CISO Sooner or later, you and your security architects have to explain the control. The assessment shows which consequential actions are governed, and ranks the ones that are not.
CRO Delegation limits exist for humans. The register shows which ones your autonomous systems actually respect.
CDO Agents read data. They change it. They release it. The consequence map classifies which of those actions are privacy-sensitive or externally binding, and under whose authority, if any, they happen.
Assurance CAE / Audit When you or your incident teams ask for the receipt, today the answer is a log. And a log is not a receipt. The gap register is the evidence-backed starting point for what should exist instead.

If an agent's action would land on your desk, you need the gap map before it does.


What You Receive

  1. Executive summary

    The headline number: how many consequential actions your agents can take today sit outside your authority structure, and how many of those are high-consequence.

  2. Authority map

    Your existing rules (delegation of authority, approval matrix, signing limits) mapped against the actions they actually govern.

  3. Agent capability map

    What each agent can actually do, from its tool access, permissions, and activity logs. Not what its description says.

  4. Ranked gap register

    Every action the agent can take outside your authority structure, classified by consequence, with the evidence that proves each one.

  5. Recommendations

    The register skeleton: who should own each mandate, within what limits, and how enforcement closes each gap.

  6. Forwardable one-pager

    One page, board-committee-ready. Your sponsor sends it upward without touching a word.



The assessment stands alone. You keep the gap map whether you go further or not. If the findings call for enforcement, the next step is a Design Partner Evaluation of Ambit Authority at the exact boundary the assessment exposed, and your assessment fee is credited against it in full.

Request an assessment