Scan methodology
How we score your Agent Trust Readiness
The Agent Trust Readiness Score is a quick, opinionated assessment of how well your organisation can answer three questions about every autonomous AI agent it operates: who is this agent, what is it allowed to do, and what did it actually do? We call those three questions Tokenise, Enforce, and Audit. The composite score is a weighted average of the three pillars on a zero to one hundred scale.
The three pillars
Tokenise covers identity and lifecycle. Does each agent have a unique, verifiable identity that is bound to a named human or organisational principal? Can you revoke a single agent without taking the parent system down? Is there a documented path for provisioning, updating, deprecating, and retiring an agent?
Enforce covers runtime policy. Can the system block an out-of-policy action before it lands, or are policies only enforced in retrospect? Are decisions made through a centralised policy engine, and are policy changes themselves audited and version-controlled?
Audit covers accountability. For any agent action in the last ninety days, can you reconstruct the full chain: who authorised, what policy applied, what the agent decided, what it did, and what the outcome was? Is the log tamper-evident, and is there a single named accountable party?
How questions are scored
Each pillar question maps to an ordinal value from zero to four, where four is the best answer (a clean “yes” or its equivalent), two is partial credit, zero is the worst answer, and one is “unsure”: not knowing is itself a signal, but not as damaging as an explicit no. We sum each pillar’s ordinals, normalise to a zero to one hundred scale, and that is the pillar score.
Composite weighting
By default we weight the three pillars at thirty, thirty-five, and thirty-five percent for Tokenise, Enforce, and Audit respectively. If your answers indicate that you operate agents that transact or move money, run consequential decisioning systems, or mutate systems of record, we shift to a higher-risk weighting of twenty-five, forty, and thirty-five. The same shift applies to organisations in Financial Services, Healthcare, or Government, regardless of the agent inventory.
Score caps
No organisation scores above eighty-five on this scanner. The gap between eighty-five and one hundred is the part of the problem we believe requires a dedicated agent governance platform; we do not pretend the scanner can resolve it. If you operate money-moving agents and any of the Enforce questions return a “no” or “unsure”, the composite is capped at fifty regardless of the rest of your answers. The cap reflects a judgement: you cannot have meaningful trust in an agent that touches money without runtime enforcement.
Bands
Scores from zero to thirty-nine fall into the red band: material exposure. Scores from forty to sixty-nine sit in amber: gaps in critical controls. Scores from seventy to eighty-five land in green: on track.
Framework matrix
The PDF report cross-references your answers against eight frameworks: the EU AI Act, NIST AI Risk Management Framework, ISO 42001, the UK AI Bill, the Colorado AI Act, NYC Local Law 144, GDPR Article 22, and the AGAP® Protocol. For each framework we list the obligations that your answers indicate are at risk. The matrix is intentionally conservative: a triggered obligation means there is enough signal to investigate, not that you are necessarily out of compliance.
Top actions
The report ranks five prioritised actions by regulatory exposure first, implementation effort second. The actions are framework-neutral, but each one closes one or more of the obligations flagged in the matrix.
What we do with your data
Submissions are stored on Vortalis infrastructure and used only to send you the report and to follow up if you ask us to. We never share your answers, your email, or your organisation name with third parties. You can ask us to delete your submission at any time by replying to the report email.
Ready to score? Start the scan.