adventureonthewave

consulting / agentic-readiness-audit

Agentic Readiness Audit — Scope & Deliverables

The front-door engagement: a structured audit of everything agents will touch, before they touch it.

The topical background — what the discipline covers and why — is at AI Production Readiness Audit. This page is the engagement.

Best fit

Scope — what is reviewed

AreaThe question answered
ArchitectureWhat are the agents, boundaries, and blast radii?
Agent permissionsWhat may each agent read, write, call, and spend?
Tool & MCP accessWhat happens when each tool misbehaves?
SecretsWhat could an agent — or a prompt injection — exfiltrate?
CI/CDHow does AI-written code reach production, and who stops it?
Model dependenciesWhat breaks on a provider change?
Context & memoryWhat do agents remember, and who can read it?
ObservabilityCan anyone answer "what did the agents do last night"?
RollbackAn agent broke it — now what?
Human approvalWhich actions require a human, enforced by what?
Cost controlsWhere are the ceilings, and what hits them first?
Failure modesRetry storms, silent loops, context poisoning — contained how?

Deliverables

How it runs

Read access to the repos, configs, and pipeline in question; a kickoff session; then the audit itself, then a findings walk-through with your engineers and (usually) a separate leadership read-out of the same findings in different words. Remediation can follow under the stabilization engagement when wanted.

Engagements are scoped by quote after a short call — the shape above is the shape, the size depends on your system. Start with a deep dive or email directly.