Advisory · AI Agent Security · Built in Norway & the UK

AI Agent Audit

Do you know what your AI agents can actually do?

Agents act as well as answer. They read your data, take in content you don't control, and send things on your behalf. We find every agent you run, audit each one against the same six checks, and show you which are one prompt injection away from leaking data.

1The risk we look for — the lethal trifecta

Simon Willison's lethal trifecta names the combination that turns a helpful agent into a way to steal data. Any one of these is fine. All three in the same agent means an attacker only has to get some text in front of it.

Leg 1

Private data

The agent can read files, mailboxes, customer records or source code.

SharePoint sites, Microsoft Graph, CRM, knowledge sources

Leg 2

Untrusted content

The agent takes in text that someone outside your organisation can write.

Inbound email, shared documents, web pages, external chats

Leg 3

A way out

The agent can send information beyond your boundary.

Webhooks, custom connectors, outbound mail, HTTP tools

The fix is rarely to switch the agent off. It is to cut one leg: narrow what it reads, stop it ingesting outside content, or remove the route out. The audit tells you which leg is cheapest to cut for each agent.

2What we audit — six checks per agent

Inventory & ownership

Every agent found and listed, from Copilot Studio and Power Platform to custom builds and MCP tools, each with a named owner and a stated purpose.

Identity & permissions

What each agent runs as, whether it borrows a person's credentials, and whether its scopes are wider than the job needs.

Lethal-trifecta exposure

Which agents combine private data, untrusted content and a way out, and which single leg to cut to make each one safe.

Human oversight

Which actions an agent can take on its own, which need approval, and whether that approval is a real check or a rubber stamp.

Logging & evidence

Whether you can reconstruct what an agent read, decided and did, and how long that record is kept.

Lifecycle & kill switch

How agents are approved, changed and retired, who can stop one quickly, and what happens to orphaned agents when their maker leaves.

3Where we look — and what you get back
Microsoft Copilot agents
Copilot Studio agents, declarative agents, Power Automate flows, custom connectors and consented Entra apps.
Vendor & SaaS agents
Agents that arrived inside tools you already pay for, often switched on by default and owned by nobody.
Custom-built agents
Agents your developers built on model APIs and frameworks, including MCP servers and the tools they expose.
What you receive
Complete agent inventory with owners
Lethal-trifecta map, agent by agent
Permission & identity findings
Oversight and logging gaps
Prioritised fixes, one per finding
Board-ready summary
4How it runs — four steps
Step 1

Discover

We find every agent, connector and tool in use, including the ones nobody registered.

Step 2

Map

Each agent is mapped to the data it reads, the content it ingests and the routes out.

Step 3

Audit

Every agent is scored against the six checks, with evidence for each finding.

Step 4

Report

You receive the inventory, trifecta map and fix list, walked through with your team.

Working towards the AI agent standard? See AIUC-1 readiness

Find out which agents hold all three.

Book a 30-minute call. We'll walk through the six checks and what an audit of your agents would cover. How many agents are you actually running?

Book an agent audit call

OWASP LLM Top 10 · AIUC-1 · EU AI Act · NIST AI RMF · ISO 42001