48 checks to run before AI agents go live, grouped into eight areas. Each check says why it matters in one line.
Section 4 covers web access, the area most teams miss, where an AI agent allow list does the work.
Tick what is already true. Priority 1 checks should be done before any agent reaches production.
Work through it with the agent's owner, someone from security and someone from the AI platform team. Most checks need all three to answer honestly.
Many checks are solved once for the whole platform. Web access at the egress proxy is the clearest example.
Page types for 40M+ domains come from the page types database. Rules for risky URL patterns on any domain are in the egress rules library.
These six cut the most risk for the least effort. None requires new software beyond a page-type lookup.
Web checks are the fastest because they need no change to the agent itself. The decision happens at the tool, gateway or proxy.
Count your ticks. Then read the band that matches your total.
The score is a guide, not a certification. One open priority 1 check can matter more than ten closed priority 3 checks.
| Area | Usual owner | Typical tools |
|---|---|---|
| 1. Inventory | AI governance or platform team | Register, AI-SPM discovery |
| 2. Identity | Identity and access team | Identity platform, NHI tools, vault |
| 3. Tools and MCP | AI platform team | MCP gateway, tool allowlists |
| 4. Web access | Network security | Egress proxy, page-type data, host list |
| 5. Data | Data protection team | DLP, masking, data catalog |
| 6. Runtime | Application security | Runtime protection, sandboxes |
| 7. Logging | Security operations | SIEM, observability |
| 8. Governance | Risk and compliance | GRC or AI governance platform |
Area 4 is often nobody's job, because it sits between the AI team and network security. Assign it explicitly.
Network security already runs URL filtering for people. Extending it to agents with page types is usually the shortest path.
The checklist works best as a living document. These four patterns cover most organisations.
Pick one owner for the checklist itself, usually the AI governance lead, so updates and scores stay consistent across teams.
| Agent type | Heaviest areas | Checks not to skip |
|---|---|---|
| Research agent reading public sites | 4 Web, 6 Runtime | 4a to 4d, 6a |
| Browser or computer-use agent | 4 Web, 2 Identity | 4b, 4c, 4f, 2b |
| Coding agent | 3 Tools, 2 Identity | 3c, 3f, 2b, 4e |
| Customer support agent | 5 Data, 7 Logging | 5a, 5e, 7a |
| Sales or procurement agent | 4 Web, 5 Data | 4b, 4c, 5f |
| Vendor SaaS agent | 1 Inventory, 8 Governance | 1e, 8b, plus vendor answers for 4 and 5 |
Web access shows up for four of the six types. Any agent that can open a URL needs area 4.
Coding agents are the exception to watch. They mostly read documentation, but package installs and uploads are writes, so check 4d still applies.
| Area | Evidence to keep |
|---|---|
| 1. Inventory | Register export with owners and review dates |
| 2. Identity | List of agent identities with credential lifetimes |
| 3. Tools | Approved tool and MCP server list with approvers |
| 4. Web access | Policy file and a sample of allow and deny log lines |
| 5. Data | Data classes per agent and masking rules |
| 6. Runtime | Kill switch test record and fail-closed settings |
| 7. Logging | Log retention setting and one incident drill report |
| 8. Governance | Signed policy and the last monthly metrics report |
If you cannot show the evidence, leave the box unticked. An honest 30 is worth more than a hopeful 45.
Keep the evidence next to the agent's register entry, so the next reviewer finds it in one place.
The honest fine print — the same two assumptions we publish, plus two operational ones
Page types for 40M+ domains, checked before every agent request.