Skip to main content

Assess (Phase 1)

The Assess phase establishes baseline trust by evaluating the agent's inherent risk. This is primarily configured at agent creation and can be updated as capabilities change.

Access via Agent Detail → Assess tab.

AIVSS Configuration

AIVSS (AI Vulnerability Scoring System) evaluates risk across 14 dimensions grouped into categories:

Access & Connectivity

DimensionDescriptionLow RiskHigh Risk
Data SensitivityWhat data can the agent access?Public data onlyPII, financial, health
System PrivilegesWhat permissions does it have?Read-onlyAdmin/root access
External ConnectivityCan it reach external systems?Internal onlyPublic internet, APIs
Network ScopeNetwork access breadthSingle serviceCross-network

Capability & Autonomy

DimensionDescriptionLow RiskHigh Risk
Autonomy LevelHow independently does it act?Human-initiated onlyFully autonomous
Decision ScopeWhat can it decide?Recommendations onlyBinding decisions
Action ReversibilityCan actions be undone?All reversiblePermanent actions
Execution SpeedHow fast can it act?Batched/slowReal-time

Impact & Criticality

DimensionDescriptionLow RiskHigh Risk
Business CriticalityImportance to operationsNice-to-haveMission critical
User ExposureWho is affected?Internal teamsExternal customers
Financial ImpactPotential monetary effectNoneSignificant
Compliance RequirementsRegulatory obligationsNoneHIPAA, GDPR, SOC2
Reputation RiskBrand impact potentialMinimalSignificant
Cascading EffectsDownstream dependenciesIsolatedTriggers other systems

Risk Profiles

Pre-configured profiles simplify AIVSS setup:

ProfileTypical AIVSS ScoreUse Cases
Level 1: Minimal90-100Read-only tools, internal dashboards
Level 2: Low75-89Standard automation, limited writes
Level 3: Medium50-74Customer-facing, data processing
Level 4: High25-49Financial, healthcare, critical ops

Viewing Current Assessment

The Assess tab shows:

Risk Profile Summary

  • Current profile level
  • AIVSS score breakdown by category
  • Last assessment date

Trust Score Impact

AIVSS Score: 72
├── Access & Connectivity: 65
├── Capability & Autonomy: 78
└── Impact & Criticality: 73

AIVSS Contribution: 72 × 40% = 28.8 points

Assessment History

Timeline of AIVSS changes with:

  • Change date
  • Previous vs. new values
  • Change reason
  • User who made the change

Re-Assessment

Trigger a re-assessment when:

  • Agent capabilities change (new data sources, APIs)
  • Business context shifts (more critical role)
  • Compliance requirements change
  • After significant incidents

Click Re-assess Risk to update AIVSS parameters.

Next Phase

Once you've assessed your agent's risk profile:

Authorize - Configure guardrails, policies, and behavioral rules to control what your agent can do