Watchlight AI
Assessment

The AI Agent Blast-Radius Assessment

Find out exactly what your AI agents can do, who authorized it, and what breaks if one is compromised. A fixed-fee, senior-led assessment that inventories your agent estate, maps its blast radius against the 12 Principles, and hands you a prioritized roadmap and a board-ready report. In weeks, not quarters.

What You Cannot See Today

Three questions most enterprises with agents in production cannot answer.

Agents Are Already in Production

Business teams have shipped AI agents with valid credentials and broad access. Most security teams cannot enumerate them, let alone say what each one is permitted to do.

Standing Access Is a Standing Blast Radius

Agents run on static, over-scoped service accounts. A prompt-injected or malfunctioning agent inherits everything that credential permits, at machine speed, on a path no human reviewed.

You Cannot Answer the Auditor

"Which agent did this, under whose authority, against what policy?" Today that answer lives in scattered logs, if it exists at all. Boards and regulators are starting to ask.

What We Assess

Six dimensions, measured against the framework we authored.

Agent & MCP Inventory

We find every AI agent and MCP server in scope, including the ones built without security in the loop, and record owner, purpose, and trust state.

Standing Privilege & Blast Radius

For each agent, we map what its credentials can actually reach and quantify the damage a single compromise could do.

Delegation & Authority Chains

We trace how authority propagates when agents delegate to other agents and where it silently widens beyond what anyone intended.

Runtime Authorization Gaps

We evaluate every control against the 12 Principles for Agent Runtime Governance and pinpoint where nothing authorizes an action before it runs.

Auditability & Evidence

We test whether you can reconstruct what any agent did and prove it, then flag where the evidence trail breaks.

Maturity Score & Roadmap

We score your posture on our 0 to 3 governance maturity model and hand you a prioritized, sequenced path to close the gaps.

Engagement

Two to Four Weeks, Fixed Scope

A defined engagement with a defined price and a defined set of deliverables. No open-ended consulting.

Week 1
Discovery & Inventory
Kickoff + data collection
We scope the environment, connect to your identity, cloud, and agent tooling, and build the inventory of agents, credentials, and access.
Weeks 2–3
Analysis & Blast-Radius Mapping
The core work
We map standing privilege and delegation, model compromise scenarios, and score your posture against the 12 Principles.
Weeks 3–4
Readout & Roadmap
Executive + technical
We deliver a board-ready report and a technical remediation plan, and walk your security team through the findings live.
Deliverables

What You Walk Away With

Complete agent and MCP inventory with ownership and purpose
Standing-privilege and blast-radius map for every agent in scope
Delegation-chain and authority-expansion analysis
Governance maturity score against the 12 Principles (0 to 3)
Prioritized 30/60/90 remediation roadmap
Board-ready executive report and a detailed technical plan

Inside the Executive Report

The board-ready deliverable your leadership actually reads.

  1. 01Executive summary and overall risk posture
  2. 02Agent inventory and shadow-AI findings
  3. 03Standing-privilege and blast-radius exposure
  4. 04Delegation and authority-expansion risks
  5. 05Auditability and evidence gaps
  6. 06Maturity score and peer benchmark
  7. 07Prioritized 30/60/90 remediation roadmap
  8. 08Appendix: methodology and evidence

Fixed Scope, Fixed Price

Choose the depth that fits. Every tier ends with a clear picture and a plan.

Rapid Scan

from $15,000
1 week

One business unit or one agent framework. A fast read on your biggest exposure.

  • Agent and MCP inventory for one team
  • Top standing-privilege and blast-radius findings
  • Maturity snapshot and executive summary
Book a Scoping Call
Most popular

Standard Assessment

from $40,000
2–3 weeks

Organization-wide across your primary frameworks. The full picture and a plan.

  • Full inventory, blast-radius, and delegation analysis
  • Maturity score against the 12 Principles
  • Board-ready report and technical remediation plan
  • Live readout with your security team
Book a Scoping Call

Enterprise

Custom
4+ weeks

Multiple business units and frameworks, with a hands-on path to enforcement.

  • Everything in Standard, at enterprise scope
  • Compromised-agent tabletop exercise
  • Executive workshop and board readout
  • Path to a Watchlight AI Beacon design-partner engagement
Book a Scoping Call

Pricing is indicative and scoped per environment. The assessment credits toward a Watchlight AI Beacon design-partner engagement.

We Wrote the Framework

Authors of the 12 Principles for Agent Runtime Governance.

23+ Years in the Trenches

Enterprise identity and security for the largest, most regulated organizations.

A Method, Not an Opinion

The same maturity model and controls that define the discipline.

Know Your Blast Radius Before an Attacker Does

Start with a 30-minute scoping call. We will size the engagement, confirm the fee, and tell you straight what we expect to find.

We value your privacy

We use cookies to enhance your browsing experience, analyze site traffic, and personalize content. You can choose to accept all cookies or customize your preferences. Learn more