The gap

Your agent can read everything. Is it ready to write?

Enterprise teams do not block agents on intelligence. They block them at the write-access door, with questions about evidence, policy, approval, and traces. Use this scorecard on the workflow where a wrong write would create customer, financial, or operational damage.

Interactive scorecard

Score your agent in 10 questions

Answer for the agent whose write access your enterprise customer has to approve. The score updates immediately.

01Surface

Tool inventory

Do you have a complete inventory of every tool your agent can call (manifest, MCP export, OpenAPI schema), classified read versus write?

02Surface

Surface drift

Would you notice a new write-capable tool appearing in the agent surface before your users or your customer does?

03Risk

Risk ranking

Are the agent write-actions ranked by business risk: financial, customer-facing, workflow-state-changing, destructive?

04Risk

Riskiest action

Can you name, today, the single riskiest write-action and its worst-case business outcome?

05Evidence

Required evidence

Is the evidence each risky write requires (linked records, thresholds, customer tier, environment) explicit and checked, rather than implied by the prompt?

06Evidence

Missing evidence

When required evidence is missing, does the risky write reliably stop or escalate instead of proceeding anyway?

07Approvals

Approval rules

Are approval thresholds explicit (amount, priority, environment, customer tier) with a named approver, defined outside the prompt?

08Approvals

Escalation path

Do risky writes route to a human with the full context needed to decide, rather than a notification after the fact?

09Traces

Decision trace

For any past write, can you show in one artifact which evidence was present and which rule produced the decision?

10Traces

Security review

Could you hand an enterprise security team a review-ready dossier for this agent, covering its write-actions, today?

How to read the score

Write-ready starts at 80

Below 80, the agent may be useful, but at least one control an enterprise security review will ask about is still ad hoc. Rippletide helps teams cross that gap with Safety Cases, unsafe scenario tests, and review-ready evidence.

0-49

Read-Only Agent

Keep writes disabled for now.

50-69

Shadow-Ready Agent

Observable, not yet provable.

70-84

Review-Ready Agent

Close, with evidence gaps left.

85-100

Write-Ready Candidate

Package the proof for review.