AgentGuard, by ScreenComply

Security

AI agent security audit.

Agents are already inside your company, connected by your own people, holding permissions nobody reviewed. A security audit for AI agents asks five questions. Here they are, with a checklist you can run this week and the parts worth automating.

Google Workspace available now.

A penetration test asks how someone could get in.
An agent audit asks who is already in, and what they're allowed to do.

The five questions a proper audit answers

01

What is connected?

Every AI app and agent with access to company accounts, including the ones employees connected without asking.

02

What can it do?

Read mail, send mail, edit files, share files, see calendars, administer the Workspace. Per app, per person.

03

What does it reach?

Which people and which kinds of data each permission exposes. One app, one inbox is different from one app, every inbox.

04

What did it do?

Actual activity, not theoretical access. What each agent opened, downloaded, shared and sent, with the record behind it.

05

What did we do about it?

Findings, decisions and actions, kept together with their evidence. The part auditors and insurers ask for.

A checklist you can run this week

If you want to start by hand, this is the audit. Each step is possible from Google Admin. Each step is also tedious, which is why most companies do it once and never again.

  1. Export the list of connected apps. In Google Admin, review third-party app access and the apps each user has authorized. Expect more than you think.
  2. Translate the permissions. Each app lists technical permission names. Work out, for each one, whether it can read mail, send mail, edit files, share files, or manage the Workspace.
  3. Match apps to people. Note how many people each app can act for, and whether any of them are in finance, HR, legal or leadership.
  4. Check who granted it and whether they're still here. Any app connected by someone who has left is a finding on its own.
  5. Look for unused access. If an app hasn't acted in a month, its access is all risk and no benefit.
  6. Read the activity. In the audit log, look at what the riskiest apps actually did: external shares, downloads, mail sent.
  7. Decide and record. Revoke what shouldn't exist, write down what you kept and why, and set a date for the next review.

Steps 2, 3, 5 and 6 are where the hours go, and where mistakes happen. They are also exactly what the audit automates.

Where AuditMyAgent helps

The tedious steps, done for you

  • ✓Inventory kept currentConnected apps refreshed daily, new connections flagged as they appear.
  • ✓Permissions in plain language"Can send email as 14 people" instead of a permission string.
  • ✓People and exposureWhich employees each app covers, and who connected it.
  • ✓Activity with evidenceWhat each agent did, week by week, with the original record.
  • ✓Orphaned and unused accessFlagged automatically from the directory and the activity log.
  • ✓Findings and actions on recordEvery revocation and policy finding kept with who, when and why.

Who runs this audit

IT and security leads

Before the question is asked

The board, a customer or an insurer will eventually ask what AI tools have access to company data. This is the answer, kept current.

Compliance

Evidence, not assurances

Access reviews are a standing requirement in most frameworks. An agent audit extends them to the apps acting on behalf of people, with records you can hand over.

Founders and operators

Without a security team

Small companies adopt AI tools fastest and have nobody watching. Two minutes to connect, and the audit does the watching.

Questions

What does an AI agent security audit cover?

Five things: an inventory of every AI app and agent connected to company accounts, the permissions each one holds, the people and data those permissions expose, what the agents actually did with that access, and a record of findings and the actions taken.

Is this the same as a penetration test?

No. A penetration test looks for ways in. An agent audit looks at who is already in: the apps your own people connected, with the access they were given. Most companies need the audit first, because the agents are already there.

How long does an AI agent security audit take?

By hand, days: exporting app lists, decoding permission names, matching them to people, and reading activity logs. With AuditMyAgent, connecting takes two minutes and the first findings arrive within the hour, with the inventory kept current from then on.

Does the audit cover agents we build ourselves?

If your agent connects to Google Workspace the way any other app does, it shows up like any other app, with its permissions and activity. For agents you run yourself and want to hold back from risky actions until a human approves, ask us about the separate approval gateway.

Know who is already in.
Then decide who stays.

Connect Google Workspace as an administrator. The five questions are answered within the hour.

Audit My Workspace

From $5 per employee per month. Pricing and the 3-day free trial.