Authority boundary
Attempt an action outside the written purpose and permitted tool set.
A bounded rehearsal for agents that send, change, pay, delete, or publish. We test whether approval, permissions, retry protection, audit evidence, shutdown, and recovery work when the workflow is stressed.
No production credentials. Staging or a sanitised workflow first. Written delivery available.Request interpreted
ObservedHuman approval
PassedArguments changed after approval
FailedAction trace preserved
PartialNo workflow file, credentials, prompt, or customer data leaves your browser.
Generic model evaluation asks whether an answer is good. This rehearsal asks whether the agent can be induced to perform an unauthorised, duplicated, altered, or unrecoverable action.
Attempt an action outside the written purpose and permitted tool set.
Check that the reviewed action and arguments are exactly what executes.
Verify that the agent identity cannot reach unrelated records, tools, or secrets.
Replay timeout and retry paths without double-send, double-charge, or double-delete.
Introduce untrusted content that tries to alter goals, permissions, or approval rules.
Exercise the emergency stop, failure owner, recovery path, and preserved evidence.

A click is not enough. We check whether the approved destination, amount, record, and action remain bound to what actually executes—and whether the team can stop and recover when they do not.
Bind the reviewed arguments to execution.
Prevent retries from repeating the action.
Preserve a stop owner and usable evidence.
Agencies already deploy agent workflows for clients. A reusable, client-facing evidence pack helps them explain what the agent can do, which actions require approval, what happens on failure, and what was actually tested.
Add a concrete action-control workstream to a client deployment.
Find approval bypass, retry duplication, privilege, and rollback gaps before handover.
Move from one workflow rehearsal toward a white-label partner programme.
Purpose, tools, permissions, high-impact actions, approvers, exclusions, and stop authority.
Pass, partial, or fail results tied to the exact test, observed trace, and limitation.
Prioritised fixes plus one written clarification round and one bounded re-check.
5 business days after usable staging evidence · no production access by default · not a penetration test or certification
Request written pilot scope ↗Start with the self-check. If the action deserves evidence, request a scope without sharing credentials or client data.
Run the action self-check ↗