Back to home

Structured pilot · fourteen days

AI Agent Exposure Assessment

A time-boxed engagement for teams who need clarity before they commit. Deploy 1stProtect in Audit Mode on a small, representative developer group and build a factual picture of how autonomous software behaves in your environment — then translate that picture into decisions leadership can act on.

Observation first. Enforcement follows once the evidence supports it.

Consenting assessments can opt into the anonymized State of Enterprise Agent Permissions 2026 cohort.

Six dimensions of exposure — measured, not assumed

The assessment is built from runtime telemetry on the machines where agents act. Each dimension below is populated from attributed events in Audit Mode, not from surveys or policy documents alone.

  • Autonomous actors in the wild

    Identify which agents are active in the pilot cohort — coding assistants, tool-using copilots, and automation running under real user sessions, not lab scenarios.

  • Sensitive surface area

    See which repositories, paths, data stores, and production-adjacent systems agents reach during ordinary work, before policy is tightened.

  • Credential reach

    Clarify where agent authority overlaps with human privilege — SSH material, cloud tokens, and secrets that should remain human-only.

  • Egress and tool endpoints

    Chart outbound communication and tool invocation: approved destinations, unexpected hosts, and paths that widen blast radius.

  • Production-adjacent execution

    Understand shell, MCP, API, and browser actions that could alter production if left unconstrained — normalized to what was actually attempted.

  • Policy gap analysis

    Contrast observed behavior with organizational intent in Audit Mode: which actions would fail once boundaries you care about are enforced.

Deliverable

Findings your security leadership can use

You receive a concise executive summary, an exposure map across the pilot cohort, representative events with context, and a prioritized set of boundaries worth enforcing — all tied to observed behavior during the engagement window.

Audit-mode telemetry feeds the exposure narrative and recommended next steps.

From uncertainty to evidence

Many programs stall because nobody can say, with confidence, whether agent risk is theoretical or already present in daily engineering work. A bounded assessment replaces speculation with your own data — so budget, policy, and enforcement conversations start from fact.

When the record is yours, the question is no longer whether autonomous software needs boundaries. It becomes which boundaries matter first — and how quickly you can validate them in production.

How the two weeks run

Engagement timeline

Observation runs in parallel with normal engineering work — no hard stop on developer velocity.

Days 1–2

Scope

Align with security and platform teams on a representative developer group, endpoints in scope, and the decisions the assessment must support.

Days 3–12

Observe

Run 1stProtect in Audit Mode on that cohort. Work continues uninterrupted while actions are attributed, classified, and retained as evidence.

Days 13–14

Synthesize

Consolidate findings into an executive narrative: exposure themes, illustrative events, and a practical set of boundaries to test next.

Input

Actor

Normalize

Action

Local policy

Decision

ALLOW continues
BLOCK terminates

Ready to see your environment clearly

Share your cohort, stack, and timeline through the pilot form. We will shape scope, Audit Mode deployment, and reporting with your team so the assessment answers the decisions in front of you.

Get your exposure report