How to Assess Your Organization's AI Agent Governance Readiness in 5 Minutes
AI Agent Governance Readiness Assessment
12 questions. 5 minutes. No email required to see your results.
How many AI agents are running in your organization right now? Who owns them? What are they authorized to do? Can you reconstruct what any of them did in the last hour and explain why it was permitted?
Most organizations cannot answer these questions. Not because the information does not exist, but because the governance infrastructure to collect, evaluate, and present it was never built.
We created a free self-assessment tool that helps security leaders answer these questions in 5 minutes. No email required. You get your maturity level, specific gaps, and a recommended next step.
What the Assessment Covers
The assessment evaluates your organization across four categories, each mapped to the 12 Principles for Agent Runtime Governance:
Agent Inventory and Identity
Do you know what agents are running? Do they have individual, verifiable identities? Can you identify who owns each one and what its purpose is? These are the foundational questions. Without a complete inventory and proper identity, everything else is built on incomplete information.
Authorization and Delegation
Are agent permissions scoped to specific tasks, or do they hold broad, long-lived access? When agents delegate to other agents, is the delegation chain tracked? Is authority narrowed at each hop? These questions determine whether your agents are operating within defined boundaries or with unchecked access.
Observability and Auditability
Can you reconstruct an agent's actions from a single identifier? Do your logs capture the governance context (intent, authority, policy decision), not just the access event? Do you have real-time awareness of what agents are doing right now? These questions determine whether you can answer the questions auditors and regulators will ask.
Data Governance and Controls
Is agent memory classified and retention-managed? Do agents hold short-lived credentials or long-lived API keys? Do you have the ability to stop an agent immediately if something goes wrong? These questions determine your operational control posture.
How Scoring Works
Each question has four possible answers:
- Yes, fully implemented (3 points)
- Partially, in progress (2 points)
- Planned but not started (1 point)
- No (0 points)
Your total score maps to a maturity level:
| Score | Level | What It Means |
|---|---|---|
| 0–9 | Level 0: Unmanaged | Agents operating without formal governance |
| 10–18 | Level 1: Identified | Basic awareness exists, significant gaps remain |
| 19–27 | Level 2: Controlled | Foundations in place, runtime enforcement gaps |
| 28–36 | Level 3: Governed | Strong governance across most categories |
The assessment also identifies your specific gaps: the questions where you scored 0 or 1. These are the areas with the highest risk and the most immediate opportunity for improvement.
What You Get
After completing the 12 questions, you see:
- Your overall maturity level with a numeric score
- A per-category breakdown showing where you are strong and where you have gaps
- A list of specific governance gaps identified in your responses
- A recommended workshop tailored to your maturity level
No email required to see the results. If you want a copy sent to you with full gap details, you can optionally provide your contact information.
Why This Matters
The gap between "our agents are authenticated" and "our agents are governed" is where risk accumulates. Most organizations have invested in IAM for their agents. Few have invested in the runtime governance layer that evaluates agent behavior in context, on every action.
This assessment gives you a baseline. It shows you where you stand relative to the governance maturity model and what the path forward looks like.
5 minutes. 12 questions. A clear picture.
Based on the 12 Non-Negotiable Principles for Agent Runtime Governance. The full framework is available in our whitepaper.
Need help acting on the results? Our advisory workshops help enterprise teams close the governance gaps the assessment identifies. Book a workshop.
Subscribe to Watchlight Insights
Get new writing on Agent Runtime Governance, AI agent security, agent identity, and delegated authorization, delivered when we publish. No noise, just the new posts.
Unsubscribe anytime. We never share your email.
Put runtime governance in front of every agent action
Watchlight AI Beacon is available now, fully on-premises and air-gapped. Request a demo to see it in your environment.
Agent Governance Readiness Assessment
Evaluate your governance posture against the 12 principles. Get a maturity score and roadmap.
2-3 days · Download one-pager (PDF)
