# AI agent entitlement review checklist

Version: 1.0

Reviewed: 28 July 2026

Owner: ____________________

Review period: ____________________

Next review or trigger: ____________________

Use this worksheet to compare approved, configured, effective, and observed authority. Record the
review criteria, complete population, evidence period, exceptions, and limitations before reaching
a conclusion.

## 1. Scope and population

- [ ] State the organization, tenants, environments, business Processes, tools, and review period.
- [ ] Reconcile the agent registry with the identity provider and workload identity system.
- [ ] Reconcile cloud IAM, Kubernetes service accounts, CI identities, vaults, and secret managers.
- [ ] Reconcile API gateways, MCP servers, connectors, target-system accounts, and network egress.
- [ ] Include active, dormant, disabled, emergency, shared, delegated, and ephemeral identities.
- [ ] Record unmatched identities and systems as findings or stated scope limitations.

Population evidence:

| Source | Query or export | Records | Unmatched | Evidence reference |
| --- | --- | ---: | ---: | --- |
| Agent registry |  |  |  |  |
| Identity provider |  |  |  |  |
| Workload platform |  |  |  |  |
| Secrets and vaults |  |  |  |  |
| Gateways, MCP, connectors |  |  |  |  |
| Target systems and runtime logs |  |  |  |  |

## 2. Identity and ownership

For every identity:

- [ ] Record tenant, agent, workload, service, delegated subject, issuer, and audience.
- [ ] Confirm a named accountable owner and current approved business purpose.
- [ ] Confirm the environment, risk class, effective date, expiry, and review date.
- [ ] Flag shared credentials and document the mandatory attribution gateway.
- [ ] Flag ownerless, dormant, expired, duplicate, or cross-environment identities.

## 3. Effective entitlement

Compare requested, approved, configured, effective, and observed values.

| Boundary | Approved value | Configured value | Observed value | Owner | Verdict |
| --- | --- | --- | --- | --- | --- |
| Tool or connector |  |  |  |  |  |
| Tenant, resource, record, field |  |  |  |  |  |
| Action |  |  |  |  |  |
| Amount or risk threshold |  |  |  |  |  |
| Purpose |  |  |  |  |  |
| Environment and destination |  |  |  |  |  |
| Effective time and expiry |  |  |  |  |  |

- [ ] Inspect direct grants, roles, groups, attributes, capabilities, and delegated access.
- [ ] Inspect wildcard scopes, administrative roles, emergency access, and inherited privileges.
- [ ] Confirm separate permission for propose, approve, and execute operations.
- [ ] Confirm approval thresholds remain below the authorization ceiling.
- [ ] Confirm tokens or capabilities bind the intended audience, resource, action, and expiry.

## 4. Runtime sample

For each sampled request:

- [ ] Reconstruct agent, workload, delegated subject, tenant, authentication event, and token audience.
- [ ] Reconstruct effective roles, attributes, capabilities, and all seven access boundaries.
- [ ] Recalculate the expected `allow`, `warn`, `require_approval`, or `block` outcome.
- [ ] Verify policy identity, version, matched rules, evaluated fields, and reason codes.
- [ ] Verify an eligible independent reviewer decided the same bound request before expiry.
- [ ] Verify policy and authority were re-evaluated before release.
- [ ] Join the execution receipt, before and after state, and downstream effect.
- [ ] Include deny, expiry, changed-request, reviewer-ineligible, and dependency-failure samples.

## 5. Emergency revocation test

- [ ] Name the incident commander and identity, platform, network, tool, and business responders.
- [ ] Cancel active and queued executions and hold pending approvals.
- [ ] Revoke identities, tokens, secrets, sessions, delegated grants, and capabilities.
- [ ] Isolate network, connector, or target-system paths that remain reachable.
- [ ] Verify later authentication, authorization, and execution attempts fail.
- [ ] Reconcile completed and partial effects and record authorized compensation.
- [ ] Repair the cause, issue fresh authority, test the safe state, and approve recovery.

Last test: ____________________

Test scope: ____________________

Residual access found: ____________________

Evidence references: ____________________

## 6. Exceptions and conclusion

| Finding or exception | Risk | Owner | Compensating control | Due or expiry | Retest |
| --- | --- | --- | --- | --- | --- |
|  |  |  |  |  |  |

Conclusion:

- Criteria:
- Population and evidence period:
- Sample and negative tests:
- Findings and expired exceptions:
- Unsupported assertions or limitations:
- Reviewer:
- Decision and date:
- Internal certification boundary:
- Next review date and change triggers:

This worksheet supports an internal control review. The conclusion applies only to the stated
criteria, population, environment, period, evidence, samples, and limitations.
