Score any AI agent in ten questions. The tool shows a risk band and the controls that band needs before launch.
Below the tool: the method, how to run it with a team, and how web controls from an AI agent allow list lower the score.
Run it once per agent. The result panel lists the controls that would lower the score most, starting with the highest-scoring answers.
Pick the answer that is true today, not the one you plan. Scores update as you click.
The score is a guide for prioritising work, not a certification or legal opinion.
Each question is short on purpose, so a team can answer it in a minute.
Agent risk is roughly how much the agent can do, times how little stops it. The questions cover both sides.
Questions one to six describe capability: what the agent could do on a bad day. Questions seven to ten describe containment: what would stop it or reveal it.
A capable agent with strong containment can score lower than a weak agent with none.
How many steps the agent takes without a person deciding.
Whether it can open pages on the public internet.
Whether it can reach signup, checkout, upload or posting pages.
How much access its keys and tokens carry.
How sensitive the data it reads and handles is.
Whether it uses tool servers nobody on your team reviewed.
Whether people approve risky steps.
Whether you can see what it did and where it went.
Whether code it runs is sandboxed.
Whether it acts in public, in your name.
The same scoring the tool uses, written out so you can run it on paper or in a spreadsheet. The total is scaled to 100.
| Question | Lowest risk answer | Highest risk answer | Max points |
|---|---|---|---|
| 1. Autonomy | Answers only (0) | Acts on its own (12) | 12 |
| 2. Web reach | No web access (0) | Any website (12) | 12 |
| 3. Action pages | Denied by a control (0) | Reachable (14) | 14 |
| 4. Credentials | None (0) | Broad, or a person's own login (12) | 12 |
| 5. Data | Public only (0) | Personal or regulated (10) | 10 |
| 6. Outside tools | None (0) | Unreviewed third-party servers (9) | 9 |
| 7. Oversight | Every risky step approved (0) | Never (9) | 9 |
| 8. Logging | Every request with agent ID (0) | No logs (8) | 8 |
| 9. Isolation | Runs no code (0) | No sandbox (7) | 7 |
| 10. Public exposure | Never acts in public (0) | Posts or reviews in your name (7) | 7 |
Question three carries the most weight on purpose. Reaching an action page is the step where a mistake turns into a real-world consequence.
Note the middle answer on question three: a prompt that forbids purchases still scores 10 of 14. Instructions are not controls.
Answers questions from internal documents. No web, read-only access, full logs.
Typical score: around 20, low.
Plans its own steps, opens any site, no page controls, text-only logs.
Typical score: around 60, high.
Runs code, installs packages, broad repository access, weak isolation.
Typical score: around 70, high.
These are illustrations of common setups, not measurements of any product. Score your own agent with its real settings.
Four bands keep the conversation simple. The number matters less than the band and the controls it calls for.
| Band | Score | Meaning | Before launch |
|---|---|---|---|
| Low | 0 to 24 | Little the agent can do goes wrong in a costly way | Register it, name an owner |
| Moderate | 25 to 49 | Mistakes are possible but limited | Logging and a web policy |
| High | 50 to 74 | The agent can act in ways that cost money or reputation | Deny action pages, scoped credentials, owner approvals |
| Critical | 75 to 100 | A single bad step could cause a serious incident | Every control above, plus default-deny egress and a red-team test |
Most real agents with web tools start in the high band. Two or three controls usually bring them down a band.
Set a target band per agent before scoring. Agents that face customers or handle regulated data usually target moderate or lower.
Each control lowers one or two answers. Pick the ones that move the highest answers first.
| Question | Control that lowers it | Effort |
|---|---|---|
| Action pages | Deny action page types before each request | Hours |
| Web reach | Allow only the read page types the purpose needs | Hours |
| Oversight | Route denied action pages to the owner | A day |
| Logging | Log every URL decision with the agent ID | A day |
| Outside tools | Approve tool servers one by one | Days |
| Credentials | Own identity, task-scoped, short-lived | Weeks |
| Isolation | Run code in a sandbox with default-deny egress | Days to weeks |
Web controls are the fastest wins. They need no change to the agent, only a check where its requests leave.
Identity and isolation take longer, but they protect against more than web mistakes. Plan them in parallel, and do not wait for them before switching on web controls.
The same agent, scored twice, two weeks apart.
Four changes, about two weeks of work. The agent still does its job, and the worst outcome is now a request waiting for approval.
This is an illustration of a typical before and after, not a measurement of any particular deployment.
The tool takes five minutes alone. With the right three people in the room, thirty minutes produces a score everyone trusts.
The owner explains what the agent does and which tools it has.
Answer all ten together. Disagreements are the useful part.
Pick the two controls that lower the score most for least effort.
Write the score, the chosen controls and the next review date in the agent register.
The agent owner, someone from security, and someone from the AI platform team.
The agent's tool list, its credentials and a week of its logs if they exist.
Scoring the agent you plan to build. Score the one that runs today.
A score is only true for the agent as it runs today. Any of these events means the old score no longer describes it.
Especially browsing, code execution or anything that writes.
Behaviour changes with the model, even with the same prompt.
Access to a more sensitive data class raises question five.
Any unexpected action, even a harmless one.
Every 90 days for high and critical agents, yearly for low.
Removing an approval step is a tier change.
Each question traces to published guidance, so the score fits into an existing risk programme.
| Question | OWASP agentic threats | NIST AI RMF |
|---|---|---|
| Autonomy | Excessive agency, rogue agents | Map |
| Web reach and action pages | Tool misuse, identity spoofing | Manage |
| Credentials | Privilege compromise | Manage |
| Data | Memory poisoning, data exposure | Map, Measure |
| Outside tools | Tool misuse | Manage |
| Oversight and logging | Overwhelming human review, repudiation | Govern, Measure |
| Isolation | Unexpected code execution | Manage |
More detail in our framework comparison.
The tool is simple on purpose. Most failures come from how it is used, not from the questions themselves.
The design has approvals. The running agent skips them.
"The prompt forbids purchases" does not lower question three.
A platform score hides the one risky agent built on it.
Agents gain tools quietly. The score becomes fiction.
Agents inside SaaS products act for your staff too.
A score with no follow-up changes nothing.
Agents inside SaaS products act for your staff. You cannot see their code, but you can still answer most of the ten questions.
Questions 1 to 4 and 8 can be answered from the vendor's documentation or a short questionnaire.
Many vendor agents can have browsing or actions switched off per tenant.
Agents running in your staff's browsers pass your proxy, where page policy applies.
If the vendor cannot answer a question, score the highest risk answer.
Every agreed control needs an owner and a date. Otherwise the assessment is only a number.
A page where the agent can sign up, reset a password, buy, subscribe, upload, post or comment.
How many steps the agent takes without a person deciding.
Something that stops or limits an action every time, not an instruction.
The score after agreed controls are in place.
A named person's written decision to run an agent above target.
An event, such as a new tool, that requires scoring again.
Once every agent has a score, the numbers tell you where to spend effort across the whole company.
Work on critical agents first, whatever team owns them.
If ten agents all score high on question three, one proxy policy fixes all ten.
Report the average and the highest score each quarter.
Owners whose agents never get rescored need a conversation, not a lecture.
The honest fine print — the same two assumptions we publish, plus two operational ones
Deny action pages with page types for 40M+ domains, checked before every request.