Merge and deploy
Agents that can modify repositories, merge pull requests, trigger CI/CD, or deploy services.
Private pilot engagement
The ANANS Agent Admissibility Review is a bounded private engagement for teams preparing AI agents that can merge code, deploy infrastructure, communicate with customers, access production data, or cause spend. The review maps the consequential action surface, tests the evidence behind the proposed controls, and returns a deployment decision with explicit residual risk.
Capability is not authority. Evidence must bind the exact action being admitted.
The pilot is aimed at teams that already have an agent or near-production workflow and need a sharper pre-execution decision boundary, not a general AI strategy workshop.
Agents that can modify repositories, merge pull requests, trigger CI/CD, or deploy services.
Agents with cloud, infrastructure, production-data, or privileged operational access.
Agents that can contact customers, issue commitments, initiate purchases, or cause other real-world effects.
The review is evidence-first. It does not assume that an approval screen, policy document, or audit log proves the underlying action boundary.
| Area | Question |
|---|---|
| Agent/action inventory | What can the system actually do, through which tools and credentials? |
| Consequential-effect map | Which actions can merge, deploy, send, spend, disclose, delete, or otherwise create external effects? |
| Authority boundary | Who or what may authorize each consequential action, and can the agent widen that authority itself? |
| Pre-execution controls | What prevents an inadmissible action before it occurs rather than merely recording it afterward? |
| Evidence quality | Do tests, logs, receipts, and approvals bind the exact action and exact runtime path? |
| Bypass and residual risk | What paths remain outside the claimed boundary, and what would falsify the deployment claim? |
Fixed fee: US$5,000 Scope: one bounded agent / workflow review Engagement begins only after scope and terms are mutually agreed.
A useful first message identifies the agent/workflow, the tools or systems it can affect, the action you want to admit, and the evidence already available.