Identity & Ownership
AI agents have explicit identities rather than sharing human or service credentials.
Every production-capable agent has a named owner and lifecycle.
Agent permissions can be scoped independently by environment and capability.
Interactive Assessment
Assess whether your engineering platform has the foundations to support AI agents safely and consistently alongside human developers.
21 questions · 7 dimensions · runs entirely in your browser. This is decision support, not certification.
Your platform
Choose “In place” only when the capability is usable in normal engineering workflows, not merely planned.
AI agents have explicit identities rather than sharing human or service credentials.
Every production-capable agent has a named owner and lifecycle.
Agent permissions can be scoped independently by environment and capability.
Core platform capabilities are available through stable machine-readable APIs, CLIs, or tool contracts.
Golden paths are encoded as reusable workflows or templates rather than documentation alone.
Tool contracts expose constraints and expected outcomes clearly enough for automated consumers.
High-impact actions are evaluated by policy outside model reasoning.
Approval requirements are based on action risk and scope rather than whether the caller is human or AI.
Production execution can be revoked or constrained without changing the model or prompt.
Agent workflows have repeatable evaluation scenarios before production use.
Model or prompt changes can be compared against a stable evaluation baseline.
Failures and unsafe proposals are retained as regression cases.
The organization can trace a consequential action from request through decision to execution.
Agent, model, tool, policy, and approval context are available in operational telemetry.
Operators can distinguish model failure from policy, platform, or tool failure.
Model and agent costs can be attributed to teams, products, or workflows.
Budgets or usage boundaries exist for expensive automated workflows.
The platform can identify latency or capacity bottlenecks across model and non-model dependencies.
Secrets and privileged credentials are not exposed directly to model context.
Untrusted retrieved content is treated as data rather than authority.
The platform has a tested way to stop, isolate, or roll back harmful automated behavior.
Readiness Profile
Complete all 21 questions to generate your readiness profile.