Home / AI & Agentic Readiness / The Agent-Ready X-ray

The Agent-Ready X-ray

An agent performs only as well as the process it runs in.

A fixed-fee examination of up to three AI or agentic use cases, run on your own operational data. Where each one sits in the value stream, how much autonomy it holds, who owns the decision rights, and what is exposed if it acts wrongly.

You finish with a proceed, redesign, constrain or stop recommendation for each use case — with the reasoning, the value at stake and the value at risk written down.

  • Up to three use cases
  • Three weeks
  • Fixed fee
  • Credited back

An agent is a participant in your process, with authority to act.

It takes actions, in sequence, inside work that already carries owners, controls and consequences. Agent failures are operating-model failures that happen to involve a model.

The X-ray treats each use case the way we would treat a new participant in a process: the work it does, what it is permitted to touch, who answers for the outcome, the evidence it leaves behind, and how it is stopped.

It runs on the same engine as our Operations X-ray — your process reconstructed from your systems' own record — with an autonomy and control pass on top.

What we look for

Up to three use cases. Five questions each.

We cap the use-case count deliberately. Three weeks is a promise, and three use cases examined properly carry more value than a dozen skimmed.

01

Where it sits

The use case mapped into the real value stream and the real process, as your systems recorded it.

What we establish
Which process, which steps, which upstream and downstream handovers, and what the process looks like once reconstructed from your event log.
Why it matters
An agent deployed on an unmeasured process makes an unmeasured process faster. Most of the value at stake becomes visible once the real flow is on the table.
02

How much autonomy it holds

Autonomy graded against what the system can do today.

What we establish
Where each use case sits on the ladder — observe, advise, act with approval, act within guardrails — and whether the controls at that rung exist in practice.
Why it matters
The gap between assumed and actual autonomy is where incidents begin. A recommendation accepted automatically 98% of the time is a decision.
Observe Advise Act with approval Act within guardrails assumed → actual the gap where incidents begin AUTONOMY, AND THE CONTROLS EACH RUNG REQUIRES →

A recommendation accepted automatically 98% of the time sits on the fourth rung, whatever the business case calls it.

03

Who decides, and where the human sits

Decision rights, accountable ownership and the points at which a person must be in the loop.

What we establish
Named accountable owner per use case, the approval thresholds, the escalation path, and whether the human control point functions as a genuine gate.
Why it matters
The Commonwealth policy and the NSW framework both require a named accountable owner per use case. Most organisations discover during the X-ray that they cannot name one.
04

What it depends on

Data, model, supplier and operational dependencies — including the ones two steps removed.

What we establish
Which data feeds it and whether that data is fit for the decision; which models and vendors sit behind it; and where third- and fourth-party concentration risk sits.
Why it matters
APRA's April 2026 letter requires visibility of the full AI supply chain including fourth parties. For SOCI-regulated operators the same dependencies land in the risk management program.
05

What you can evidence

Current controls mapped against what you will be asked to produce, with the gaps priced.

What we establish
Existing controls mapped to the DTA agentic AI addendum, ISO/IEC 42001 and the NIST AI Risk Management Framework — and to whichever dated obligation reaches you first.
Why it matters
The register, the impact assessment and the attestation each require evidence. Finding the gap a week before the deadline is expensive.

Both sides of the ledger

Every use case gets two numbers.

We price both sides, because a board weighs a dollar figure more readily than an amber square.

  • Value potential — what the use case is worth once it works, baselined against your measured current process.
  • Value at risk — what is exposed if it behaves incorrectly at the autonomy level it actually holds: cost, rework, regulatory exposure, and the cost of switching it off.
Value at risk Value potential
Use case 01 · Proceed $0.9m $2.4m Use case 02 · Constrain $0.5m $1.6m Use case 03 · Stop $1.8m $0.6m

Illustrative — figures are realistic placeholders, not a client result.

Where AI is the wrong intervention for a use case, we say so. That is a normal outcome, and it is worth the fee on its own.

What you get

Six deliverables, short and evidenced, usable directly as inputs to the register and impact assessment you already owe.

  • A use-case inventory — every AI and agentic use case we find, including the ones nobody mentioned, in the register format your policy requires.
  • The process context — each use case placed in the reconstructed as-is flow, with the value stream it touches.
  • An autonomy and impact classification — graded per use case, with the controls each rung requires and the ones you hold today.
  • The decision-rights map — accountable owner, approval thresholds, escalation and human control points, named.
  • A control gap register — mapped to the obligation that reaches you first, with each gap sized.
  • A one-page recommendation per use case — proceed, redesign, constrain or stop, with value potential and value at risk in dollars.

How it works

01

Scoping call

We agree which use cases, the data path and the fixed fee. Sixty minutes, no obligation.

02

Discovery

The minimised event log and the use-case documentation are prepared, in your environment or under NDA. The three-week clock starts here.

03

The X-ray

Process reconstruction, autonomy and impact classification, decision-rights mapping, dependency and control assessment.

04

Readout

A one-page recommendation per use case and a findings session with the people who can act on it. Three weeks, fixed.

Where the data lives

In your environment, with data held inside your boundary. This is the default for defence and SOCI-regulated operators. Alternatively: a minimised, de-identified extract under NDA, held in Australia, processed onshore, destroyed on completion.

What we take

A minimised event log — timestamps, activity names and roles — plus your existing use-case documentation, model and vendor list, and any approvals already recorded.

How we connect

Read-only access, isolated from live and OT systems. Every system stays as we found it, and agents remain untouched throughout the X-ray.

Commercials

A single fixed fee, agreed on the scoping call and confirmed in writing. If you proceed to operating-model design or delivery within 90 days, the X-ray fee is credited in full.

The scope is up to three use cases and the duration is three weeks — a fixed price, on a fixed clock.

Book the scoping call

Sixty minutes to agree the use cases, the data path and the fee. Where your use cases are still too early to X-ray, we will tell you on that call.