Sample data — illustrative only, not a real organisation

Agent Passport — worked example

Vendor Invoice Reconciliation Agent

This is what a real Agent Passport looks like once it's been through registration, risk assessment, control tracking and approval — the actual product, not a mockup of it.

ApprovedElevated

Accountability

Named principal

Priya Sharma, Finance Systems Lead

Business owner

Finance Operations

Technical owner

Platform Engineering

Next review

19 Jan 2027

Purpose

Business purpose

Matches incoming vendor invoices against purchase orders and flags discrepancies for human review before payment release.

Permitted tasks

Read invoice data from the AP inbox. Cross-reference against the PO system. Write a match/discrepancy flag. Draft (not send) a query email to the vendor contact on file.

Explicitly prohibited

Cannot approve or release payment. Cannot modify PO records. Cannot send vendor communications without human review.

Risk

Elevated. This agent can write to internal systems and drafts (but does not send) external communications — meaningful capability, with no path to irreversible financial action.

Score 14 / 42 · assessed under model version 2026.1

Required controls

7 of 7 mandatory controls closed — 6 implemented, 1 under a current, complete exception. This is what actually gates approval now, not just informational text.

INV-01
Central agent register
Owner: platform-team@example.com · closed 3 weeks ago
implemented
IDN-01
Unique agent identity
Owner: iam@example.com · closed 3 weeks ago
implemented
IDN-02
Named human principal
Priya Sharma confirmed at registration
implemented
ENT-01
Least-privilege entitlements
Owner: finance-systems@example.com · closed 2 weeks ago
implemented
CRD-01
Vaulted, short-lived credentials
Owner: platform-team@example.com · closed 4 days ago
implemented
AUD-01
Append-only action log
Owner: security-eng@example.com · closed 1 week ago
implemented
LFC-01
Scheduled recertification
exception
Exception record

New agent, first recertification cycle not due until the standard 90-day mark. Tracked via the finance-systems team's existing quarterly access review instead of a separate campaign for now.

Expires 18 Oct 2026 · Approved by raj.kumar@example.com (CISO)

Decision

Approved 19 Jul 2026 by Raj Kumar (CISO).

Approval here required a named principal, a scheduled review date, and every mandatory control closed — implemented, or under a complete, current exception. That's not informational text; it's an actual gate. LFC-01's exception above (reason, expiry, named approver) is what closed that control, not a status dropdown flipped without a record behind it — an incomplete or expired exception would have kept this Passport blocked at Pending approval.

History

12 Jul 2026, 09:14passport_created by priya.sharma@example.com
12 Jul 2026, 09:41control_updated — INV-01 marked implemented by priya.sharma@example.com
15 Jul 2026, 14:02control_updated — IDN-01 marked implemented by iam-team@example.com
18 Jul 2026, 11:30status_pending_approval by priya.sharma@example.com
19 Jul 2026, 16:47status_approved by raj.kumar@example.com (CISO)

This is one agent, fully governed. A real pilot builds this for up to ten of yours in thirty days.

See the pilot →

© 2026 Aseem Mohan · Assessment · Sample Estate · Methodology · Control library