HHandover

Private browser assessment

AI agent governance checklist

Review identity, access, approval, evidence, verification, and offboarding controls before an agent reaches production.

Local to this tabExportable evidence record

Private self-assessment

Agent and controls

Environment
Risk tier

Inventory

0/3 marked complete

Identity and access

0/4 marked complete

Actions and approval

0/3 marked complete

Evidence and review

0/3 marked complete

Verification

0/3 marked complete

Lifecycle

0/2 marked complete

Evidence, not a badge

A completed checklist is the start of review

Every marked control needs inspectable evidence. A separate identity should test denied paths, attribution, revocation, and successor continuation before approving production use.

Direct answer

What belongs in an AI agent governance checklist?

An AI agent governance checklist should record a named owner, purpose, risk tier, distinct identity, least-privilege access, consequential-action approvals, immutable evidence, negative-path tests, revocation, incident response, and offboarding. Controls should be verified at the model host, MCP server, API, data, and publishing boundaries the agent actually uses.

Shared review

Give unresolved controls an owner

Continue the assessment as a versioned handover so people and agents can attach evidence, comment on exact files, and record the final decision.

Inspect a reviewed handover