All posts
Field Notes4 min read

What a 30 Day Shadow Audit Is Built to Catch

A diagnostic engagement observes agent activity without enforcing anything. Here's what the engine is built to catch.

A Shadow Compliance Audit is a fixed-fee, 30-day diagnostic engagement. Gateplex observes agent activity inside your environment and enforces nothing. At the end you get a report describing what your agents actually did.

What the engine is built to catch

Undocumented agents. Inventory teams hold rarely matches the agents actually calling production systems.

Prompt content reaching third parties. Customer identifiers and internal document text can end up in prompts sent to model providers without anyone deciding that should happen.

Missing boundaries between read and write. Agents built to summarize or retrieve are often handed write-scoped credentials simply because that's what was available.

Gaps in action-level records. Knowing which model was called is not the same as knowing what the agent did with the answer.

These aren't exotic failure modes. They're the predictable result of agents shipping faster than the controls around them.

What the engagement needs from you

One integration point, a named contact, and roughly one hour to confirm scope. The 30-day observation period runs after that, and the report follows once it concludes.

Details and request form on the Shadow Audit page.

More reading