1. Answer with the current truth
Choose None, Ad hoc, Partial, or Ready for each control. Do not answer for the target architecture unless it is already implemented and reviewed.
Use this when you need a fast internal readout before a Microsoft AI agent pilot, customer review, or trainer-led workshop.
Choose None, Ad hoc, Partial, or Ready for each control. Do not answer for the target architecture unless it is already implemented and reviewed.
The score is a practical launch-readiness signal. It maps common agent risks to DORA, NIST CSF, and CIS language so security and platform teams can discuss evidence without turning the scanner into a legal opinion.
For most teams the first fixes are identity ownership, least-privilege tool permissions, audit logging, incident handling, and a concise evidence pack for the pilot owner.
Run the scanner