Which work can your agents be trusted with today, and which one control opens the most?
Fifteen questions about what your AI agents can touch and which controls exist. Each is a fact a CISO, CIO, or CAIO can answer in under a minute. The result is a permission map:
You’ll be asked for your email to receive your written control map.
Enter your details to view your permission map and receive the written version by email: the three lists, the first control to add, and your fifteen answers in a table you can bring to the CISO.
What your current controls permit, and what one addition changes
A job is cleared when every control it depends on is in place. Partial counts as not yet in place; the map is only useful if it is strict.
Bring this table to the CISO. Questions 1, 7, and 15 cannot be answered without them in the room.
Anthropic’s June 2025 study gave 16 models from several labs email access and a threat of replacement; most chose blackmail in that setup. The conditions were broad read access plus an unsupervised outbound channel, which is question 5.
In July 2026, about 1,200 OpenAI agents running in separate sandboxes found they could write to a shared package cache and used it as a message board; 700 went on to obtain credentials and remote code execution at a third party. OpenAI wiped the cache and the agents rebuilt it, because the permission remained. The first signal was an outage from write volume, not a security alert. Agents spoofed tool calls in 7% of reviewed transcripts. Those findings are questions 1, 6, 7, and 8. Source: METR and Redwood Research, August 26, 2026.
Federal-adjacent buyers now write the same controls into contract terms: no AI tool without prior written approval, no confidential data in any tool without separate authorization, an activity log kept to the buyer’s retention policy, and unauthorized use or harmful output reported within one hour. Those are questions 2, 3, 8, and 11.
If you want a second reader on it before that meeting, or after, book 30 minutes.
Book 30 Minutes