Assurance sprint
Do your AI agents' controls work as approved?
An eight-week, fixed-fee assessment of two or three of your AI agents. It runs inside your environment, tests only objectives your own reviewer has confirmed, and ends with signed evidence your auditors can verify.
What you get
- A test result for every confirmed control objective: pass, fail or warning, each with the boundary cases and log evidence behind it.
- A findings register (CSV) with severity, status, the agent affected and first-seen and last-seen dates.
- A signed evidence pack (JSON, HTML and Markdown) that anyone with Lantern's public key can check offline.
- A walk-through with risk and internal audit, and a retest of fixed findings within the sprint.
Eight weeks
| Weeks | What happens | Your team |
|---|---|---|
| 1–2 | Choose two or three agents. Agree the export: approved policies, enforced rules, permissions, activity log. | Agent owner, platform engineer |
| 2–3 | Lantern shows each objective beside the interpretation it will test. A named reviewer confirms or disputes each one. | Risk or audit reviewer |
| 3–6 | Tests run on your machine with no network connection. Draft findings are discussed as they appear. | Agent owner |
| 6–8 | Signed evidence pack, findings register and walk-through. Fixed findings are retested. | Risk, internal audit |
What we test
Policy enforced as approved
Every boundary case gives the approved outcome.
No unguarded paths
Tools are reachable only through the control point.
Limits that can't be split
Totals are enforced, not just single actions.
Separation of duties
The agent can't approve its own held actions.
Concentration and fallback
Shared providers have tested fallbacks.
Unapproved AI
Prevented, not just detected.
How your data is handled
- Lantern runs as a container inside your environment, with networking switched off. Nothing is sent to Lantern.
- We work from exported files your team chooses. No access to production systems is needed.
- We never need prompts, messages or model inputs and outputs. The activity log stays with you; the pack records only how many records were read and their fingerprint.
What Lantern is not
- Not an audit opinion or a certification. Lantern provides evidence; your auditors decide.
- Not a control. Lantern never writes, changes or enforces a policy, so it stays independent of what it tests.
- Not legal advice. Regulatory references are indicative.
Next step
A 30-minute call to choose the agents and agree the export. The fee is fixed and agreed before work starts.