Agent, tool & browser authority
Tool permissions, delegated actions, browser sessions, callbacks, external writes, recovery paths, and the authority a workflow can exercise beyond the model.
Map what agents, browsers, cloud roles, credentials, pipelines, and public interfaces can actually reach. Separate consequential paths from theoretical findings, then remediate the highest-value path where access permits.
Tool permissions, delegated actions, browser sessions, callbacks, external writes, recovery paths, and the authority a workflow can exercise beyond the model.
Roles, trust policies, deployment principals, credential custody, storage exposure, public ingress, and cross-system privilege paths without breaking the operating path.
Workflow permissions, secret exposure, artifact trust, dependencies, SBOM findings, and remediation with closure evidence instead of an ever-growing findings list.
One deployed service or launch path: highest-impact reachable risk first, concrete remediation, reproducible verification, and explicit residual risk.
Bring one real system and the authorized evidence you already have. The assessment reconstructs the relevant authority path, identifies the most consequential reachable exposures, prioritizes remediation, and defines the smallest implementation boundary that would materially improve the system.
The fixed $2,500 48-hour Production Rescue is the implementation path after scope acceptance. The assessment is the default when the mechanism or highest-value correction is still uncertain.