Review identity, access, approval, evidence, verification, and offboarding controls before an agent reaches production.
Local to this tabExportable evidence record
Private self-assessment
Agent and controls
Inventory
0/3 marked complete
01
Identity and access
0/4 marked complete
02
Actions and approval
0/3 marked complete
03
Evidence and review
0/3 marked complete
04
Verification
0/3 marked complete
05
Lifecycle
0/2 marked complete
06
Evidence, not a badge
A completed checklist is the start of review
Every marked control needs inspectable evidence. A separate identity should test denied paths, attribution, revocation, and successor continuation before approving production use.
Direct answer
What belongs in an AI agent governance checklist?
An AI agent governance checklist should record a named owner, purpose, risk tier, distinct identity, least-privilege access, consequential-action approvals, immutable evidence, negative-path tests, revocation, incident response, and offboarding. Controls should be verified at the model host, MCP server, API, data, and publishing boundaries the agent actually uses.
Shared review
Give unresolved controls an owner
Continue the assessment as a versioned handover so people and agents can attach evidence, comment on exact files, and record the final decision.