Assurance Agent
Runs the automated check battery on every submitted asset and composed workflow: quality against the declared benchmarks, security and supply-chain integrity of the artefact, bias and Responsible AI screening, and malicious-content scanning. Assembles the check report and flags anomalies against comparable assets.
An agent executes the process end to end and logs what it did. No human is in the path, because there is no discretion to exercise and no consequence to carry.
- Acts for
- Governance & Certification
- Action class
- read-only
- Decisions / 30d
- 61
- Safe-state returns / 30d
- 1
Processes covered
- Automated assurance: quality, security, bias, malicious content, supply chain
- Conformance testing of composed workflows
Memory
Retains check reports for the life of the asset version; purged on retirement.
Safe state
Marks the check as 'not run' and blocks routing to sign-off when any scanner is unavailable, rather than passing the stage.
Reviewer time per case: 0 min with this agent, 75 without.
Tools
- Artefact and image scanner
- SBOM and signature verifier
- Benchmark harness
- Bias and RAI screening suite
- Check-report writer
Data access scope
- Read-only: artefacts, SBOMs, evaluation datasets referenced in the manifest
- Read-only: check reports of comparable certified assets
- Write: check report attached to the case only
Guardrails
- A failed security or malicious-content check blocks routing to sign-off automatically
- Never modifies an artefact; findings are reported, not fixed
- Anomaly flags always show the comparable set they were judged against
Human-in-the-loop
- Governance officer reads the check report before any sign-off
Orchestration
Every tool call is scoped by the declared data access above; the orchestrator cannot reach systems outside it. Owning entity: MCIT.
Live demo run
Watch the agent execute a real scenario step by step, every tool call, validation, and human checkpoint is traced and auditable. Typical run: ~6.9s.
Owning entity
Updated 2026-07-30. Run traces retained 24 months for audit under the platform governance policy.
Community · 0 threads
Questions, findings and requests from the entities that use this asset. Owners reply here; threads with upvotes surface to the owning entity's inbox.