AI Agent Allowlist
Home Page-Types Database Agent Guardrails 2026 Incidents API Docs Pricing
Resources
Use Cases (15) Industries & Buyers (12) Learn: Core Concepts (12) Implementation Guides (15) Comparisons (8) Agent Security Guides (22) Market & Frameworks (9) Schema & Data Reference (6) FAQ Glossary
Why It Matters
2026 Agent Incidents Category Targeting Database Refreshes Contact Customer Login
Download Free Sample
free scoring tool, answers stay in your browser

AI Agent Risk Assessment

Score any AI agent in ten questions. The tool shows a risk band and the controls that band needs before launch.

Below the tool: the method, how to run it with a team, and how web controls from an AI agent allow list lower the score.

10Questions
4Risk bands
100Point scale
5 minPer agent
The tool

Score one agent

Run it once per agent. The result panel lists the controls that would lower the score most, starting with the highest-scoring answers.

Pick the answer that is true today, not the one you plan. Scores update as you click.

Risk score

0
Low

    The score is a guide for prioritising work, not a certification or legal opinion.

    The method

    What the ten questions measure

    Each question is short on purpose, so a team can answer it in a minute.

    Agent risk is roughly how much the agent can do, times how little stops it. The questions cover both sides.

    Questions one to six describe capability: what the agent could do on a bad day. Questions seven to ten describe containment: what would stop it or reveal it.

    A capable agent with strong containment can score lower than a weak agent with none.

    1

    Autonomy

    How many steps the agent takes without a person deciding.

    2

    Web reach

    Whether it can open pages on the public internet.

    3

    Action pages

    Whether it can reach signup, checkout, upload or posting pages.

    4

    Credentials

    How much access its keys and tokens carry.

    5

    Data

    How sensitive the data it reads and handles is.

    6

    Outside tools

    Whether it uses tool servers nobody on your team reviewed.

    7

    Oversight

    Whether people approve risky steps.

    8

    Logging

    Whether you can see what it did and where it went.

    9

    Isolation

    Whether code it runs is sandboxed.

    10

    Exposure

    Whether it acts in public, in your name.

    The questions in full

    Every question, every answer, every point value

    The same scoring the tool uses, written out so you can run it on paper or in a spreadsheet. The total is scaled to 100.

    QuestionLowest risk answerHighest risk answerMax points
    1. AutonomyAnswers only (0)Acts on its own (12)12
    2. Web reachNo web access (0)Any website (12)12
    3. Action pagesDenied by a control (0)Reachable (14)14
    4. CredentialsNone (0)Broad, or a person's own login (12)12
    5. DataPublic only (0)Personal or regulated (10)10
    6. Outside toolsNone (0)Unreviewed third-party servers (9)9
    7. OversightEvery risky step approved (0)Never (9)9
    8. LoggingEvery request with agent ID (0)No logs (8)8
    9. IsolationRuns no code (0)No sandbox (7)7
    10. Public exposureNever acts in public (0)Posts or reviews in your name (7)7

    Question three carries the most weight on purpose. Reaching an action page is the step where a mistake turns into a real-world consequence.

    Note the middle answer on question three: a prompt that forbids purchases still scores 10 of 14. Instructions are not controls.

    Three agents scored

    What typical agents score on day one

    Internal knowledge assistant

    Answers questions from internal documents. No web, read-only access, full logs.

    Typical score: around 20, low.

    Research agent with browsing

    Plans its own steps, opens any site, no page controls, text-only logs.

    Typical score: around 60, high.

    Autonomous coding agent

    Runs code, installs packages, broad repository access, weak isolation.

    Typical score: around 70, high.

    These are illustrations of common setups, not measurements of any product. Score your own agent with its real settings.

    Bands

    What each band means

    Four bands keep the conversation simple. The number matters less than the band and the controls it calls for.

    BandScoreMeaningBefore launch
    Low0 to 24Little the agent can do goes wrong in a costly wayRegister it, name an owner
    Moderate25 to 49Mistakes are possible but limitedLogging and a web policy
    High50 to 74The agent can act in ways that cost money or reputationDeny action pages, scoped credentials, owner approvals
    Critical75 to 100A single bad step could cause a serious incidentEvery control above, plus default-deny egress and a red-team test

    Most real agents with web tools start in the high band. Two or three controls usually bring them down a band.

    Set a target band per agent before scoring. Agents that face customers or handle regulated data usually target moderate or lower.

    Lowering the score

    Which controls move which answers

    Each control lowers one or two answers. Pick the ones that move the highest answers first.

    QuestionControl that lowers itEffort
    Action pagesDeny action page types before each requestHours
    Web reachAllow only the read page types the purpose needsHours
    OversightRoute denied action pages to the ownerA day
    LoggingLog every URL decision with the agent IDA day
    Outside toolsApprove tool servers one by oneDays
    CredentialsOwn identity, task-scoped, short-livedWeeks
    IsolationRun code in a sandbox with default-deny egressDays to weeks

    Web controls are the fastest wins. They need no change to the agent, only a check where its requests leave.

    Identity and isolation take longer, but they protect against more than web mistakes. Plan them in parallel, and do not wait for them before switching on web controls.

    Worked example

    A procurement agent, before and after

    The same agent, scored twice, two weeks apart.

    Before: score 78, critical

    • Plans on its own, browses freely
    • Can reach checkout and signup pages
    • Uses a buyer's own login
    • Logs model text only

    After: score 38, moderate

    • Action pages denied, one supplier exception with approval
    • Own identity with hourly credentials
    • Every URL decision logged
    • Unknown sites denied

    Four changes, about two weeks of work. The agent still does its job, and the worst outcome is now a request waiting for approval.

    This is an illustration of a typical before and after, not a measurement of any particular deployment.

    Running it as a team

    A 30-minute assessment meeting

    The tool takes five minutes alone. With the right three people in the room, thirty minutes produces a score everyone trusts.

    1

    Five minutes: purpose

    The owner explains what the agent does and which tools it has.

    2

    Ten minutes: the questions

    Answer all ten together. Disagreements are the useful part.

    3

    Ten minutes: controls

    Pick the two controls that lower the score most for least effort.

    4

    Five minutes: record

    Write the score, the chosen controls and the next review date in the agent register.

    Who attends

    The agent owner, someone from security, and someone from the AI platform team.

    What to bring

    The agent's tool list, its credentials and a week of its logs if they exist.

    What to avoid

    Scoring the agent you plan to build. Score the one that runs today.

    When to repeat

    Triggers for a new assessment

    A score is only true for the agent as it runs today. Any of these events means the old score no longer describes it.

    A new tool

    Especially browsing, code execution or anything that writes.

    A new model

    Behaviour changes with the model, even with the same prompt.

    New data

    Access to a more sensitive data class raises question five.

    An incident

    Any unexpected action, even a harmless one.

    The review date

    Every 90 days for high and critical agents, yearly for low.

    More autonomy

    Removing an approval step is a tier change.

    Mapping

    How the questions line up with known frameworks

    Each question traces to published guidance, so the score fits into an existing risk programme.

    QuestionOWASP agentic threatsNIST AI RMF
    AutonomyExcessive agency, rogue agentsMap
    Web reach and action pagesTool misuse, identity spoofingManage
    CredentialsPrivilege compromiseManage
    DataMemory poisoning, data exposureMap, Measure
    Outside toolsTool misuseManage
    Oversight and loggingOverwhelming human review, repudiationGovern, Measure
    IsolationUnexpected code executionManage

    More detail in our framework comparison.

    Common mistakes

    How risk assessments go wrong

    The tool is simple on purpose. Most failures come from how it is used, not from the questions themselves.

    Scoring the design

    The design has approvals. The running agent skips them.

    Trusting the prompt

    "The prompt forbids purchases" does not lower question three.

    One score for all agents

    A platform score hides the one risky agent built on it.

    Never rescoring

    Agents gain tools quietly. The score becomes fiction.

    Ignoring vendor agents

    Agents inside SaaS products act for your staff too.

    No owner of the result

    A score with no follow-up changes nothing.

    Vendor agents

    Assessing agents you do not host

    Agents inside SaaS products act for your staff. You cannot see their code, but you can still answer most of the ten questions.

    Ask the vendor

    Questions 1 to 4 and 8 can be answered from the vendor's documentation or a short questionnaire.

    Check your settings

    Many vendor agents can have browsing or actions switched off per tenant.

    Check your network

    Agents running in your staff's browsers pass your proxy, where page policy applies.

    Unknown means high

    If the vendor cannot answer a question, score the highest risk answer.

    Recording it

    What to write in the agent register

    agent: vendor-research assessed: 2026-10-01 by: owner, security, AI platform score: 62 (high) target: below 45 controls_agreed: - deny action page types before each request # owner: security, due 2026-10-08 - log every URL decision with the agent ID # owner: platform, due 2026-10-15 accepted_risks: unknown reads allowed for documentation sites next_assessment: 2026-12-31

    Every agreed control needs an owner and a date. Otherwise the assessment is only a number.

    Accepting risk

    When a high score is acceptable

    Acceptable with a record

    • A short pilot with a fixed end date
    • An isolated test environment with fake data
    • A named person accepts it in writing

    Not acceptable

    • Critical agents with personal or regulated data
    • Open action pages in production with no end date
    • Nobody willing to sign for the risk
    Terms

    Words used in the assessment

    Action page

    A page where the agent can sign up, reset a password, buy, subscribe, upload, post or comment.

    Autonomy

    How many steps the agent takes without a person deciding.

    Control

    Something that stops or limits an action every time, not an instruction.

    Residual risk

    The score after agreed controls are in place.

    Risk acceptance

    A named person's written decision to run an agent above target.

    Reassessment trigger

    An event, such as a new tool, that requires scoring again.

    Many agents

    From one score to a portfolio view

    Once every agent has a score, the numbers tell you where to spend effort across the whole company.

    Sort by score

    Work on critical agents first, whatever team owns them.

    Group by control

    If ten agents all score high on question three, one proxy policy fixes all ten.

    Track the trend

    Report the average and the highest score each quarter.

    Compare owners

    Owners whose agents never get rescored need a conversation, not a lecture.

    Controls by band

    The minimum set for each band

    Low

    • Register entry with owner
    • Review once a year

    Moderate

    • Everything in low
    • Per-agent web policy
    • Request logging with agent ID

    High

    • Everything in moderate
    • Action pages denied
    • Own short-lived identity
    • Owner approval on denials

    Critical

    • Everything in high
    • Default-deny for unknown sites
    • Sandbox for any code
    • Red-team test before launch

    The 2026 incidents would have scored critical

    • Autonomous agents, open web reach, reachable action pages and weak isolation.
    • Denying action pages and unknown writes alone would have moved them down a band.
    • In our replay, page data plus egress rules would have stopped almost all of them.
    Would your agents have been stopped? Check the incident analysis The sandbox escape case

    The honest fine print — the same two assumptions we publish, plus two operational ones

    1. The policy engine must see every request — an agent with raw socket access or a second network path bypasses everything; enforcement belongs at the egress proxy/network layer, not only in an SDK hook.
    2. Default-deny must be on. In flag-only mode these become alerts within minutes rather than prevention — still a large improvement on a timeline measured in weeks (the DseWiki edits ran from late May to late June 2026, per the researchers), but not a block.
    3. For full URL+method matching on HTTPS you need to be the proxy or in-process hook — SNI alone shows only the host, which still catches the entire host-list layer.
    4. Policy can’t read intent inside a legitimately allowed action: an agent whose job is publishing packages keeps registry access. In our replay of the 2026 incidents, no crossing fits any plausible allowlist for the agents’ documented tasks.
    Related

    Keep reading

    FAQ

    Risk assessment questions

    How do you assess the risk of an AI agent?
    Look at what the agent can do (autonomy, web reach, action pages, credentials, data, tools) and what stops it (oversight, logging, isolation). The tool on this page scores both in ten questions.
    Is my data sent anywhere?
    No. The tool runs entirely in your browser and stores nothing.
    What is a good score?
    Below 50 for agents that act on their own, and below 25 for agents that face the public. The right target depends on what the agent does.
    Which control lowers the score fastest?
    Denying action page types before each request. It usually takes hours and changes nothing about the agent itself.
    How often should agents be reassessed?
    Every 90 days for high and critical agents, and after any new tool, model, data access or incident.
    Can I assess agents inside SaaS products?
    Yes. Answer what you can from the vendor and your own settings, and score any unanswered question at its highest risk value.
    Who should sign off a high score?
    A named person who owns the business outcome, usually the agent owner's manager, with security consulted. Record the decision and its end date.
    Why does question three carry the most points?
    Reaching a signup, checkout, upload or posting page is the moment an agent mistake becomes a real-world action. Controlling it removes the largest single source of risk.
    Can I change the point values?
    Yes. The table on this page shows every value, so you can copy it into a spreadsheet and weight questions to match your own risk appetite.
    Does this replace a formal risk assessment?
    No. It is a fast, repeatable first pass. Regulated uses still need your formal risk process and legal review.

    Lower your agent's score this week

    Deny action pages with page types for 40M+ domains, checked before every request.

    Download the sample