AI Agent Security Audit — who sends emails, changes systems, and exposes data in your company
An AI agent connected to email, CRM, file storage, or an API can send a message, change a record, or expose data before the team notices. The audit reviews identities, tokens, data flows, and approval controls — within an agreed scope and with written authorisation.
What the audit covers
01. Identities and service accounts
We review service accounts, OAuth and API tokens, roles, and scopes for agents running in Google Workspace, Microsoft 365, CRM, Slack/Teams, n8n, Make, Zapier, in-house systems, and on VPS. We verify that each automation has its own identity and only the access needed for its task.
02. Data flows
We identify where the agent pulls content from (email, documents, web pages, APIs, CRM) and where it sends data. We check whether sensitive data traverses channels that were not intended for it, and whether data classification is respected.
03. Tools and actions
We verify which functions the agent can invoke (send messages, edit, delete, export, publish, pay, deploy) and whether access is limited to a specific task. Unrestricted scope is the classic pattern of excessive agency.
04. Approval controls
We check which operations are fully automatic and which require a human approval or an independent policy rule. We verify whether the agent can perform irreversible actions on its own (sending, exporting, changing permissions, deploying).
05. Prompt injection and untrusted content
We check how the agent treats content from emails, documents, web pages, and external systems. We verify that system instructions are separated from data, input sources are restricted, and manipulation scenarios are tested before production deployment.
06. Logging and audit trail
We check whether logs let the organisation establish who initiated a task, which data source the agent used, which tools it invoked, which action it performed, and on what basis it was authorised. We also verify rate limits on high-volume actions and anomaly alerts.
Engagement plans
Starter — single audit
Map of agents and integrations, review of permissions, data flows, and approval controls. Report with priorities in business and technical language.
individual quotation
Growth — audit plus automation policy
AI agent audit plus a written policy: data source rules, classification, approval procedures for high-impact actions, and prompt injection controls.
individual quotation
Enterprise — audit, implementation, recurring reviews
Audit, policy, in-environment implementation, and recurring reviews after integration changes, new agents, or incidents.
individual quotation
Before and after
- Before: an AI agent shares an account with the administrator and can send emails, edit CRM records, and export files on its own. After: a dedicated technical identity, least privilege, and access restricted to the specific task.
- Before: no approval gate for messages, exports, permission changes, or deployments. After: every high-impact action passes a system rule or human approval.
- Before: emails or customer documents contain hidden instructions that the agent treats as commands. After: external content is treated as untrusted, separated from system instructions, filtered, and tested before production.
- Before: no logs to reconstruct the agent\u2019s decision. After: full trail: who launched the task, which source, which tools, which action, and who approved it.
What this service does not include
- It is not a penetration test or an unauthorised attempt to take over an agent — every activity runs with client authorisation and within the previously approved scope.
- It does not analyse AI model source code (GPT, Claude, Gemini, Copilot) — this is an audit of your working environment and automations, not of the AI vendor.
- It does not replace a regulatory compliance audit (NIS2, DORA, GDPR) — it can complement one, but not substitute for it.
- We do not promise full protection of AI automation — we organise risks and priorities, but no audit eliminates all risk.
- Continuous monitoring is not part of this service — exposure and change monitoring is a separate offering (see Digital Exposure Monitoring).
Frequently asked questions
Does the M365 audit require administrator access?
Yes. The audit needs read-only access to the Microsoft 365 admin centre, audit logs, and Copilot settings. Access is granted by the client and revoked at the end of the engagement.
How long does a Microsoft 365 and AI audit take?
A standard audit takes 5 to 10 business days, depending on the number of users, applications, and integrations. The final report contains priorities and concrete remediation guidance.
Does the audit cover Copilot and other AI tools?
Yes. We review Microsoft Copilot configuration, the use of other AI assistants integrated with M365, and the general AI use policy in business processes (custom agents, OpenAI/Anthropic integrations).
Do I need management authorisation?
Yes, the audit requires formal authorisation from the board or a person delegated to manage IT infrastructure. We provide a standard authorisation and scope template before work begins.
How is an M365 audit different from a vulnerability audit?
The M365 audit focuses on configuration, permissions, and AI workflows in the Microsoft ecosystem. The Vulnerability Audit covers a selected domain, website, or web application within an agreed scope. The two services complement each other.
Related services
- When you want to test the technical resilience of a website or application → Vulnerability Audit
- When you want to protect your domain from impersonation → Email and Domain Audit
- When you need a one-shot view of external exposure → Internet Exposure Scan
- When you need continuous monitoring of exposure changes → Digital Exposure Monitoring
- When you use Microsoft Copilot and the Microsoft ecosystem → Microsoft 365 and AI Security Audit
Request an AI agent security audit
We define the audit scope after a short briefing: list of agents and automations, used systems (Google Workspace, Microsoft 365, CRM, Slack/Teams, n8n, Make, Zapier, APIs, VPS), regulatory requirements. We return with a work plan and an indicative delivery time.
Eng. Marcin Białczyk, CHORS.NET operator — learn how I work.