How Ready Is This Process and Use Case, and for What Level of Authority?
Passing an initial screen does not mean an agent is ready to act. A defensible decision needs evidence about the process, the agent objective, the decisions, the data, the systems, the permissions, the people, the tests, the controls and the consequences involved.
IGX360 runs this as a facilitated cross-functional assessment. 55 questions across eleven dimensions produce more than an average score: capability maturity, an evidence confidence index, the status of 24 critical gates, the supported next decision, and an indicative autonomy ceiling.
55 questions · 11 dimensions · evidence required · 24 critical gates · deterministic scoring
The process and the agent are assessed together.
This is not a general judgement about whether the organisation uses AI. It evaluates one defined combination of process boundary, intended outcome, proposed agent role and objective, authorised actions, systems and data, human oversight, affected people, and recovery requirements.
The same process may support one agentic use case but not another. An agent that drafts a recommendation for a human gate and an agent that executes an irreversible transaction need different evidence, controls and authority.
Begin with a use case clear enough to assess.
Identify the process owner, the executive sponsor, the intended outcome, the proposed agent actions, the systems and information involved, the affected people, the intended autonomy, and the relevant jurisdictions.
Not sure it should progress?
Run the free Process and Use-Case Screening first. It directs the next step in about 10 minutes.
Screen a use caseOwnership or governance unresolved?
Run the Organisational Readiness Discovery with a multidisciplinary team to establish the wider context.
Start discoveryReadiness from purpose through production operation.
Each dimension carries a risk-informed weight. Expand a dimension for its focus and two representative questions. The full set of 55 questions is worked through in the facilitated session.
P1 Scope, Purpose and Intended Outcome
Is the process bounded, owned, and the reason for an agent established?
7% weight
Scope, Purpose and Intended Outcome
Is the process bounded, owned, and the reason for an agent established?
- Defined process boundary. How clearly is the selected process bounded from start to end, including material variants and participants?
- Accountable ownership. Is accountability defined for both the end-to-end process and the proposed agent's decisions, actions and outcomes? Critical gate
P2 Process Truth and Documentation
Is the process documented as it actually runs, including exceptions and dependencies?
8% weight
Process Truth and Documentation
Is the process documented as it actually runs, including exceptions and dependencies?
- End-to-end process documentation. How clearly is the selected process documented across activities, hand-offs, systems, data, decisions, controls and outcomes?
- Actual versus intended work. Can actual operation be compared with the approved or intended process?
P3 Decisions, Rules, Exceptions and Variability
Are the decisions in scope known, and is judgement separated from rules?
7% weight
Decisions, Rules, Exceptions and Variability
Are the decisions in scope known, and is judgement separated from rules?
- Decision inventory. Are the decisions within the proposed agent scope explicitly identified?
- Rules and judgement. Is it clear which decisions are deterministic and which require contextual, professional, ethical or discretionary judgement?
P4 Agent Role, Authority and Autonomy
What may the agent do, and where does human authority hold?
14% weight
Agent Role, Authority and Autonomy
What may the agent do, and where does human authority hold?
- Bounded objective. Is the agent's objective bounded, testable and protected against harmful optimisation? Critical gate
- Permitted and prohibited actions. Are permitted, conditional and prohibited agent actions explicitly defined and enforceable? Critical gate
P5 Data, Knowledge, Context and Memory
Is the information the agent uses identified, fit for purpose, traceable and lawful?
10% weight
Data, Knowledge, Context and Memory
Is the information the agent uses identified, fit for purpose, traceable and lawful?
- Information inventory and purpose. Are the data and knowledge the agent may read, infer, create, change or retain identified with owners and permitted purposes?
- Fitness for intended action. Are information-quality requirements defined and met for the specific decisions and actions proposed? Critical gate
P6 Systems, Tools, Identity and Permissions
Can the agent be integrated, identified and held to least privilege?
12% weight
Systems, Tools, Identity and Permissions
Can the agent be integrated, identified and held to least privilege?
- Controlled integration. Can required systems and tools be accessed through reliable, controlled and supportable integration methods?
- Unique agent identity. Does the agent have a unique managed identity attributable to a named owner, purpose and environment? Critical gate
P7 Risk, Compliance, Security and Affected Parties
Are consequence, regulation, agent-specific security and affected-person rights addressed?
12% weight
Risk, Compliance, Security and Affected Parties
Are consequence, regulation, agent-specific security and affected-person rights addressed?
- Consequence and reversibility. Are the severity, scale and reversibility of incorrect actions, omissions and cumulative behaviour understood? Critical gate
- Legal and regulatory classification. Are applicable obligations and the use case's legal or regulatory classification established and approved? Critical gate
P8 Human Roles, Oversight and Workforce Readiness
Is human oversight meaningful, and are the people ready and resourced?
8% weight
Human Roles, Oversight and Workforce Readiness
Is human oversight meaningful, and are the people ready and resourced?
- Meaningful human oversight. Are human approval, monitoring, intervention, override and escalation points effective for the proposed consequences and scale? Critical gate
- Role and accountability change. Are changes to human tasks, decisions, accountability, workload and controls understood and accepted?
P9 Testing, Simulation and Acceptance
Is there evidence the complete system behaves acceptably before and after release?
9% weight
Testing, Simulation and Acceptance
Is there evidence the complete system behaves acceptably before and after release?
- Predefined acceptance thresholds. Are measurable acceptance thresholds agreed before testing across value, quality, safety, compliance, security, human outcomes and cost? Critical gate
- Representative scenarios. Does testing cover representative normal, exceptional, boundary, adversarial, high-volume and dependency-failure scenarios? Critical gate
P10 Monitoring, Incident Response and Recovery
Can the agent be observed, contained, recovered and learned from?
9% weight
Monitoring, Incident Response and Recovery
Can the agent be observed, contained, recovered and learned from?
- End-to-end observability. Can material inputs, context, tool calls, approvals, decisions, actions, exceptions and outcomes be reconstructed? Critical gate
- Operational thresholds and drift. Are thresholds and alerts defined for outcome deterioration, unusual behaviour, drift, control breaches, interventions and cost?
P11 Value, Economics and Deployment Decision
Are the economics understood and is deployment a governed decision?
4% weight
Value, Economics and Deployment Decision
Are the economics understood and is deployment a governed decision?
- Total lifecycle economics. Is total cost understood per successful outcome, including integration, usage, oversight, exceptions, correction, assurance and recovery?
- Benefit attribution. Can benefits be attributed to the agentic intervention rather than unrelated process or demand changes?
An average is not allowed to hide the reason an agent should not act.
- Evidence is scored separately. For each answer, assessors record whether it is verified, partially evidenced, an unsupported assertion, or unknown. The evidence confidence index stays visible next to maturity.
- Twenty-four critical gates constrain the result. Accountable ownership, bounded objectives, permitted and prohibited actions, information fitness, legal classification, agent identity, least privilege, meaningful human oversight, representative testing, end-to-end observability, containment and continuity. A missing gate cannot be offset by strong scores elsewhere.
- Conditional risk is examined when relevant. Extra gates apply when the agent uses persistent memory, delegates to other agents, or materially affects people. Not applicable requires a recorded reason and is never scored as a high answer.
- The result includes an autonomy ceiling. The assessment distinguishes advisory assistance, human-approved action, bounded supervised action and governed autonomy. It identifies the highest level the evidence supports. It never authorises that level.
- The calculation is deterministic. The score is produced by published rules, weights and gates. A language model does not decide whether the use case passes. Every result records the version of the questions and scoring method used.
Five views of readiness.
A score is not a certificate. A ceiling is not an approval.
- 1
Weighted maturity
An overall score and eleven dimension scores show how developed the relevant capabilities are. Authority, identity, risk, testing and operations carry more weight than the rest.
- 2
Evidence confidence index
A separate score shows whether the answers are supported by current evidence or rest on assertion and unknowns. An unsupported claim stays visible.
- 3
Critical gate status
Twenty-four gates, red, amber or green. A red gate constrains the result regardless of the scores around it. Four gates are conditional and apply only where memory, delegation or effects on people are in scope.
- 4
Readiness decision
One of R0 to R5, from "insufficient basis to assess" through "candidate for a bounded supervised experiment" to "strong candidate for governed scaling review". Candidate means suitable to enter the next decision, not approved.
- 5
Indicative autonomy ceiling
A0 to A5, the highest form of agent involvement the current evidence supports, from advisory assistance through bounded supervised action to governed autonomy. An accountable body must still authorise any deployment or increase in authority.
Readiness decision
- R0
- Insufficient basis to assess
- R1
- Critical foundation work required
- R2
- Suitable for design and controlled validation
- R3
- Candidate for a bounded supervised experiment
- R4
- Candidate for controlled production validation
- R5
- Strong candidate for governed scaling review
Autonomy ceiling
- A0
- No agent action
- A1
- Advisory assistance only
- A2
- Human-approved action
- A3
- Bounded supervised action
- A4
- Governed autonomy within defined conditions
- A5
- Expanded or dynamic autonomy review
The assessment ends with owned action, not a PDF score.
Every material finding traces to a question, a gate or an evidence gap and becomes an action with an owner, a dependency, the evidence required to close it, a decision gate and a reassessment trigger. That is the Readiness Roadmap.
The Detailed Agentic Readiness Assessment provides an indicative, evidence-based decision-support baseline. It does not constitute certification, assurance, legal, regulatory, security or technical advice, or authorisation to deploy an AI system. A competent accountable body must make the deployment decision using appropriate specialist evidence for the process, use case, sector, affected people and jurisdictions involved.