TKOResearch
Menu

Resource

List an AI agent's permissions before granting production access.

A practical launch-readiness checklist for teams preparing AI agents with tools, memory, retrieval, credentials, approvals, logs, and production access.

Overview

What this resource covers.

  • Tool and data inventory
  • Memory and retrieval checklist
  • Credential and approval-gate review prompts
  • Logging and artifact checklist
  • Launch blocker worksheet

What you receive

Checklist preview

Use this as the starting checklist before granting production access or asking for a formal assessment.

Authority inventory

List every action the agent can perform and mark it read, write, delete, send, execute, approve, retrieve, or remember.

  • Owner
  • Environment
  • Default permission
  • Human approval required

Credential review

Identify each token, session, API key, OAuth grant, and delegated account the agent can use.

  • Credential owner
  • Scope
  • Lifetime
  • Revocation path

Launch blocker test

If a bad prompt, retrieved document, or tool output can cause a real action without approval, mark the launch blocked pending containment.

01

Checklist areas

  • What can the agent read, write, delete, send, execute, approve, retrieve, and remember?
  • Which credentials, tokens, sessions, and user grants can it use?
  • Which human approvals are required for high-impact actions?
  • Which logs and records help establish what happened after an unwanted action?

Next step

Describe the system, question, and timing.

Download the PDF checklist