Back to Blog
AI Agent Exposure Assessment Checklist

AI Agent Exposure Assessment Checklist

A printable checklist for scoping and running a fourteen-day Audit Mode exposure assessment on coding agents and tool-using copilots.

The 1stProtect Team Sep 10, 2026 6 min read

AI Agent Exposure Assessment Checklist

Use this checklist to scope a fourteen-day Audit Mode engagement on a representative developer cohort. It aligns to the AI Agent Exposure Assessment offer — evidence first, enforcement second.

Before day 1 — Scope

  • Named executive sponsor (CISO, VP Engineering, or delegate)
  • Pilot cohort defined (team size, OS mix, agent tools in use: Claude Code, Cursor, Codex, etc.)
  • Endpoints in scope (laptops, VDI, selected servers if applicable)
  • Success criteria documented (e.g., credential reach map, MCP shell usage, production-adjacent commands)
  • Legal / HR aware of Audit Mode (observe, do not block initially)
  • SIEM contact for optional decision telemetry forwarding

Days 1–2 — Deploy

  • 1stProtect deployed in Audit Mode on cohort machines
  • Agent attribution validated (human vs autonomous actor visible in console)
  • Baseline week of “normal sprint” work agreed — no artificial lockdown
  • Runbook for developers: work continues; security is measuring, not blocking

Days 3–12 — Observe

  • Autonomous actors in the wild — inventory of active agents and tools
  • Sensitive surface area — repos, paths, data stores touched
  • Credential reach — SSH, cloud tokens, secret files (attempted reads)
  • Egress and MCP endpoints — destinations and tool invocations
  • Production-adjacent execution — shell, kubectl, cloud delete-class patterns
  • Weekly sync with platform + security (themes, not alert noise)

Days 13–14 — Synthesize

  • Executive summary draft (exposure themes, not raw log dumps)
  • Representative events with actor, action, resource, outcome
  • Prioritized boundary list for Prevent-mode pilot
  • Comparison to organizational policy intent (gaps explicit)
  • Decision on Phase 2: targeted Prevent vs expanded Audit

Deliverables checklist

  • Exposure map across pilot cohort
  • Illustrative blocked/would-block event narratives
  • Recommended least-privilege boundaries (human vs agent)
  • Integration notes (EDR, SIEM, IAM) for decision telemetry

Red flags that should never wait for day 14

  • Unrestricted MCP shell with production kubeconfig on same host
  • Agent read of org-wide secrets store in first 48 hours
  • Repeated egress to unapproved destinations during routine coding tasks

Request the structured assessment: /offers/ai-agent-exposure-assessment or the pilot form on the homepage.