Frame the decision
Define the launch, customer commitment, or architecture decision the evidence must support.
Signature GenAI assessment
Agent Authority is the signature focused engagement within the GenAI Security Assessment service area. It tests whether a production-bound agent stays within the authority intended for the right user, tenant, delegated task, tools, APIs, credentials, actions, and destinations. The exact boundary, schedule, delivery team, outputs, and fee are tailored to the client and documented before work begins.
Commercial terms, timing, and scope limits are defined in the tailored proposal.
Qualification determines whether the work should be a readiness review, active verification, focused authorization assessment, remediation retest, or another bounded scope. A signed proposal and agreement define the work.What it answers
The work begins with the important allowed and prohibited paths. It then evaluates whether application logic, agent orchestration, identity, API controls, credentials, tools, and downstream systems preserve those boundaries when assembled.
Prompt injection, indirect prompt injection, parameter manipulation, retries, fallbacks, alternate destinations, and state transitions may be used where they help answer the authority question. They are methods—not the whole category being sold.
The evidence record identifies production-parity assumptions, unavailable paths, environmental differences, and anything the approved assessment cannot establish.
Engagement sequence
Define the launch, customer commitment, or architecture decision the evidence must support.
Document actors, tenants, delegated tasks, identities, tools, destinations, credentials, and allowed actions.
Exercise approved allow-and-deny paths, capture evidence, and investigate discrepancies without expanding scope by implication.
Deliver the agreed engineering evidence, decision support, remediation priorities, and retest record where included in scope.
Active testing starts only after qualification, written authorization, access readiness, evidence rules, escalation contacts, and stop conditions are complete. Schedule and any retest window are stated in the signed engagement documentation.
The client remains responsible for launch, risk acceptance, compliance, and business decisions. LuxlyNight provides bounded technical evidence and recommendations within the signed scope; it is not certification, legal advice, compliance attestation, or a guarantee of security.
Client prerequisites
Explicit exclusions
Qualification
The fit check is anonymous and stays in your browser. No target or sensitive information is requested.
Check engagement fit