Free assessment
How ready is your organization to govern AI agents?
15 questions on whether you can see, control, and evidence what AI agents and coding assistants are allowed to do. You get a score, a breakdown by area, and the gaps in priority order.
15 questions. About four minutes.
- No email required. Your score appears as soon as you finish.
- Your answers stay in this browser. They are not saved or sent anywhere unless you ask us to email you the summary.
- “Not sure” is a real answer. Not knowing is itself a finding, and the report says so.
This is a self-assessment, not a certification or an audit. It produces a starting point for a conversation, not a compliance result.
What it covers
Eight areas of AI agent governance
Each area is scored on its own, because a strong average can hide one surface where nothing is enforced at all.
AI visibility
- Do you know which AI tools and coding agents are being used across your organization?
- Can you see what AI tools and agents are actually doing, not just that they are in use?
Agent identity
- Can you identify the human or service identity responsible for an agent action?
Action authorization
- Can policies evaluate an action before it executes?
- Can policy decisions change based on repository, environment, resource, or user context?
Coding agent governance
- Can AI coding agents execute shell commands in your environments?
- Can AI coding agents modify files without review?
- Can AI agents install dependencies?
MCP / tool governance
- Can agents invoke MCP servers or external tools?
- Are MCP and tool permissions restricted by least privilege?
Sensitive resource protection
- Can AI agents access production or business-critical repositories?
- Are sensitive credentials and resources detected and protected in AI workflows?
Approval & exception workflows
- Can high-risk AI actions require human approval before proceeding?
- Can users request a documented exception when a control blocks legitimate work?
Audit & evidence
- Are AI action decisions recorded in an audit trail that explains why the outcome occurred?
Scoring
How the score is calculated
Written out so you can check it. A score you cannot reproduce is a score you cannot argue with internally, which makes it useless in the meeting where it matters.
Every question is worth up to 100 points: yes scores 100, partially scores 50, and both no and not sure score 0. Your overall score is the plain average of the questions you answered — no weighting, no hidden multipliers.
Question severity orders the gap report so the findings that widen the blast radius most appear first. It deliberately does not affect the score, because a weighted model would be defensible in a dozen different ways and checkable in none of them.
0–39
Critical gaps
40–59
Developing
60–79
Established
80–100
Advanced
The model
What the questions are testing for
Every question maps to one part of a single decision: can this actor, through this agent, take this action, on this resource, in this context?
- Actor
- Agent
- Action
- Resource
- Context
- Policy
- Decision
- Evidence
Oconee Runtime evaluates that chain at the point of action and returns ALLOW, WARN, BLOCK or REDACT, keeping the decision as evidence either way. A low score in an area usually means one link in that chain is missing — most often the identity, or the record.
Questions
About this assessment
What does the AI governance readiness assessment measure?
It measures whether your organization can see, control, and evidence what AI agents and coding assistants actually do. The 15 questions cover eight areas: visibility into AI usage, identity and attribution, authorization before action, coding agent controls, tool and MCP access, sensitive resource protection, exception handling, and audit evidence.
Is this a compliance certification?
No. It is a self-reported maturity check, not a certification, an audit, or a guarantee of compliance with any framework. It produces a starting point for a conversation about where AI agent controls are missing. Nobody verifies the answers, and no certificate is issued.
Do I have to give an email address to see my score?
No. The score, the area breakdown, and the prioritized gaps all appear as soon as you answer the last question. Emailing yourself the summary is optional and comes after the result.
What happens to my answers?
They stay in your browser. Individual answers are never sent to our analytics or stored on our servers. If you ask us to email you the summary, we receive the score and the findings — not your question-by-question answers.
How is the score calculated?
Each question scores 100 for yes, 50 for partially, and 0 for no or not sure. The overall score is the plain average of the questions you answered, so you can recalculate it by hand. Bands: 0-39 Critical gaps, 40-59 Developing, 60-79 Established, 80-100 Advanced.
Why does 'not sure' score zero?
Because an unconfirmed control is not a control. If nobody can say whether agent actions are attributable to an identity, then in an incident they will not be. The result reports how many questions you were unsure about separately, because a visibility gap and a deliberate decision not to enforce are different problems with different fixes.
How long does the assessment take?
About four minutes. There are 15 questions with four answer options each.
Go deeper
Background on the controls the assessment asks about.
- Runtime AI GovernanceWhat is runtime AI governance, and how is it different from an AI policy document?
- Enterprise AI governance and action controlHow context-aware policy is applied to what AI tools and agents attempt to do, across browser and engineering workflows.
- AI agent security and runtime governanceThe authorization boundary for AI-assisted actions, and the evidence it leaves behind for security teams.
- What Belongs in an AI Audit TrailWhat belongs in an AI audit trail, and what should be left out?