Stage three · Detailed Agentic Readiness Assessment

How Ready Is This Process and Use Case, and for What Level of Authority?

Passing an initial screen does not mean an agent is ready to act. A defensible decision needs evidence about the process, the agent objective, the decisions, the data, the systems, the permissions, the people, the tests, the controls and the consequences involved.

IGX360 runs this as a facilitated cross-functional assessment. 55 questions across eleven dimensions produce more than an average score: capability maturity, an evidence confidence index, the status of 24 critical gates, the supported next decision, and an indicative autonomy ceiling.

55 questions · 11 dimensions · evidence required · 24 critical gates · deterministic scoring

What is assessed

The process and the agent are assessed together.

This is not a general judgement about whether the organisation uses AI. It evaluates one defined combination of process boundary, intended outcome, proposed agent role and objective, authorised actions, systems and data, human oversight, affected people, and recovery requirements.

The same process may support one agentic use case but not another. An agent that drafts a recommendation for a human gate and an agent that executes an irreversible transaction need different evidence, controls and authority.

Before this stage

Begin with a use case clear enough to assess.

Identify the process owner, the executive sponsor, the intended outcome, the proposed agent actions, the systems and information involved, the affected people, the intended autonomy, and the relevant jurisdictions.

The eleven dimensions

Readiness from purpose through production operation.

Each dimension carries a risk-informed weight. Expand a dimension for its focus and two representative questions. The full set of 55 questions is worked through in the facilitated session.

P1

Scope, Purpose and Intended Outcome

Is the process bounded, owned, and the reason for an agent established?

7% weight
  • Defined process boundary. How clearly is the selected process bounded from start to end, including material variants and participants?
  • Accountable ownership. Is accountability defined for both the end-to-end process and the proposed agent's decisions, actions and outcomes? Critical gate
P2

Process Truth and Documentation

Is the process documented as it actually runs, including exceptions and dependencies?

8% weight
  • End-to-end process documentation. How clearly is the selected process documented across activities, hand-offs, systems, data, decisions, controls and outcomes?
  • Actual versus intended work. Can actual operation be compared with the approved or intended process?
P3

Decisions, Rules, Exceptions and Variability

Are the decisions in scope known, and is judgement separated from rules?

7% weight
  • Decision inventory. Are the decisions within the proposed agent scope explicitly identified?
  • Rules and judgement. Is it clear which decisions are deterministic and which require contextual, professional, ethical or discretionary judgement?
P4

Agent Role, Authority and Autonomy

What may the agent do, and where does human authority hold?

14% weight
  • Bounded objective. Is the agent's objective bounded, testable and protected against harmful optimisation? Critical gate
  • Permitted and prohibited actions. Are permitted, conditional and prohibited agent actions explicitly defined and enforceable? Critical gate
P5

Data, Knowledge, Context and Memory

Is the information the agent uses identified, fit for purpose, traceable and lawful?

10% weight
  • Information inventory and purpose. Are the data and knowledge the agent may read, infer, create, change or retain identified with owners and permitted purposes?
  • Fitness for intended action. Are information-quality requirements defined and met for the specific decisions and actions proposed? Critical gate
P6

Systems, Tools, Identity and Permissions

Can the agent be integrated, identified and held to least privilege?

12% weight
  • Controlled integration. Can required systems and tools be accessed through reliable, controlled and supportable integration methods?
  • Unique agent identity. Does the agent have a unique managed identity attributable to a named owner, purpose and environment? Critical gate
P7

Risk, Compliance, Security and Affected Parties

Are consequence, regulation, agent-specific security and affected-person rights addressed?

12% weight
  • Consequence and reversibility. Are the severity, scale and reversibility of incorrect actions, omissions and cumulative behaviour understood? Critical gate
  • Legal and regulatory classification. Are applicable obligations and the use case's legal or regulatory classification established and approved? Critical gate
P8

Human Roles, Oversight and Workforce Readiness

Is human oversight meaningful, and are the people ready and resourced?

8% weight
  • Meaningful human oversight. Are human approval, monitoring, intervention, override and escalation points effective for the proposed consequences and scale? Critical gate
  • Role and accountability change. Are changes to human tasks, decisions, accountability, workload and controls understood and accepted?
P9

Testing, Simulation and Acceptance

Is there evidence the complete system behaves acceptably before and after release?

9% weight
  • Predefined acceptance thresholds. Are measurable acceptance thresholds agreed before testing across value, quality, safety, compliance, security, human outcomes and cost? Critical gate
  • Representative scenarios. Does testing cover representative normal, exceptional, boundary, adversarial, high-volume and dependency-failure scenarios? Critical gate
P10

Monitoring, Incident Response and Recovery

Can the agent be observed, contained, recovered and learned from?

9% weight
  • End-to-end observability. Can material inputs, context, tool calls, approvals, decisions, actions, exceptions and outcomes be reconstructed? Critical gate
  • Operational thresholds and drift. Are thresholds and alerts defined for outcome deterioration, unusual behaviour, drift, control breaches, interventions and cost?
P11

Value, Economics and Deployment Decision

Are the economics understood and is deployment a governed decision?

4% weight
  • Total lifecycle economics. Is total cost understood per successful outcome, including integration, usage, oversight, exceptions, correction, assurance and recovery?
  • Benefit attribution. Can benefits be attributed to the agentic intervention rather than unrelated process or demand changes?
Why this assessment is different

An average is not allowed to hide the reason an agent should not act.

  • Evidence is scored separately. For each answer, assessors record whether it is verified, partially evidenced, an unsupported assertion, or unknown. The evidence confidence index stays visible next to maturity.
  • Twenty-four critical gates constrain the result. Accountable ownership, bounded objectives, permitted and prohibited actions, information fitness, legal classification, agent identity, least privilege, meaningful human oversight, representative testing, end-to-end observability, containment and continuity. A missing gate cannot be offset by strong scores elsewhere.
  • Conditional risk is examined when relevant. Extra gates apply when the agent uses persistent memory, delegates to other agents, or materially affects people. Not applicable requires a recorded reason and is never scored as a high answer.
  • The result includes an autonomy ceiling. The assessment distinguishes advisory assistance, human-approved action, bounded supervised action and governed autonomy. It identifies the highest level the evidence supports. It never authorises that level.
  • The calculation is deterministic. The score is produced by published rules, weights and gates. A language model does not decide whether the use case passes. Every result records the version of the questions and scoring method used.
What the result contains

Five views of readiness.

A score is not a certificate. A ceiling is not an approval.

  1. 1

    Weighted maturity

    An overall score and eleven dimension scores show how developed the relevant capabilities are. Authority, identity, risk, testing and operations carry more weight than the rest.

  2. 2

    Evidence confidence index

    A separate score shows whether the answers are supported by current evidence or rest on assertion and unknowns. An unsupported claim stays visible.

  3. 3

    Critical gate status

    Twenty-four gates, red, amber or green. A red gate constrains the result regardless of the scores around it. Four gates are conditional and apply only where memory, delegation or effects on people are in scope.

  4. 4

    Readiness decision

    One of R0 to R5, from "insufficient basis to assess" through "candidate for a bounded supervised experiment" to "strong candidate for governed scaling review". Candidate means suitable to enter the next decision, not approved.

  5. 5

    Indicative autonomy ceiling

    A0 to A5, the highest form of agent involvement the current evidence supports, from advisory assistance through bounded supervised action to governed autonomy. An accountable body must still authorise any deployment or increase in authority.

Readiness decision

R0
Insufficient basis to assess
R1
Critical foundation work required
R2
Suitable for design and controlled validation
R3
Candidate for a bounded supervised experiment
R4
Candidate for controlled production validation
R5
Strong candidate for governed scaling review

Autonomy ceiling

A0
No agent action
A1
Advisory assistance only
A2
Human-approved action
A3
Bounded supervised action
A4
Governed autonomy within defined conditions
A5
Expanded or dynamic autonomy review
From result to roadmap

The assessment ends with owned action, not a PDF score.

Every material finding traces to a question, a gate or an evidence gap and becomes an action with an owner, a dependency, the evidence required to close it, a decision gate and a reassessment trigger. That is the Readiness Roadmap.

The Detailed Agentic Readiness Assessment provides an indicative, evidence-based decision-support baseline. It does not constitute certification, assurance, legal, regulatory, security or technical advice, or authorisation to deploy an AI system. A competent accountable body must make the deployment decision using appropriate specialist evidence for the process, use case, sector, affected people and jurisdictions involved.