AGCP Human Verified Assessment

Commercial Offer

AGCP Human Verified Assessment

Runtime Governance Technical Assessment for AI and Autonomous Systems

Know what the implementation actually does — not just what policy says it should do.

The AGCP Human Verified Assessment evaluates one defined AI or autonomous system against up to 122 applicable AGCP runtime-governance requirements. AGCP combines private AI-assisted source-code semantic analysis with customer-supported human verification to produce control-level, decision-quality technical evidence.

$12,500 Fixed Fee
Up to 122 Applicable AGCP Controls
Approx. 2–3 Weeks Typical Completion

Evidence-Based Runtime Governance Assessment

AGCP evaluates the customer’s implementation for semantic equivalence to each applicable AGCP control. The assessment does not depend on AGCP-specific names, keywords, schemas, or one prescribed internal architecture.

Applied experience: AGCP’s assessment methodology has been applied to 11 company systems — 10 through the AGCP assessment pathway and one independently implemented AGCP v1.0 system that was manually assessed. An ongoing Fall 2026 University capstone is applying runtime governance to AI-driven cybersecurity operations.

What Is Assessed

  • Source code: private AI-assisted analysis against applicable AGCP controls.
  • Supporting evidence: architecture diagrams, schemas, configuration, documentation, tests, logs, screenshots, and other relevant artifacts.
  • Live verification: customer technical personnel help demonstrate or clarify controls that cannot be established from source code alone.
  • Human adjudication: a human assessor verifies key findings and resolves evidence gaps before final dispositions are issued.

What You Receive

  • Executive Assessment Summary — material strengths, gaps, uncertainties, and decision-relevant findings.
  • Control Assessment Matrix — disposition of each applicable AGCP control within the agreed scope, with supporting evidence and confidence indicators.
  • Remediation Priorities — material gaps and recommended areas for engineering or governance attention.
  • Technical Findings Review — customer session covering results, supporting evidence, and next-step considerations.

The Human Verified Method

1

Private AI Source-Code Analysis

Semantic-equivalency assessment across the applicable controls.

2

Customer Evidence Participation

Targeted evidence, demonstrations, screenshots, diagrams, logs, and technical clarification.

3

Human Verification and Final Findings

Control-level adjudication, quality assurance, report preparation, and findings review.

Assessment Process

Up to 122 Controls, Assessed with Customer Participation

The Human Verified Assessment is a structured control-by-control process. Private AI analysis accelerates evidence discovery; customer participation and human verification establish the final assessment.

1

Scope and Applicability

Define the system/version and assessment boundary. Confirm which of the 122 AGCP controls apply and identify the customer technical contacts who will support verification.

2

Secure Intake

Receive the agreed source-code package and initial supporting materials, such as architecture diagrams, schemas, configuration information, documentation, and available tests.

3

Private AI Semantic Analysis

Analyze source code for semantic equivalence to each applicable control — looking for substantive governance behavior rather than AGCP-specific terminology or one prescribed architecture.

4

Preliminary Control Findings

Develop a control-level evidence map identifying preliminary dispositions, supporting code evidence, confidence, and questions or evidence gaps that require customer participation.

5

Customer-Assisted Verification

Work with customer technical personnel to verify applicable controls using targeted additional evidence. Evidence may include live screens or screenshots, demonstrations, architecture diagrams, logs, schemas, configuration, tests, or technical explanations.

6

Human Adjudication and QA

Reconcile source-code analysis, customer evidence, and human technical judgment. Distinguish true control gaps from insufficient evidence or technically different implementations that satisfy the required semantics.

7

Report and Findings Review

Deliver the final Human Verified Assessment package and conduct a structured review of material findings, evidence strength, gaps, and remediation priorities.

Customer participation is part of the assessment. The fixed-fee engagement assumes reasonable access to customer technical personnel and the supporting information needed to evaluate applicable controls. A control may remain unresolved or evidence-limited when sufficient verification evidence is not available.

Optional AGCP Registry Listing

Registry listing is optional and is not the primary assessment outcome.

A customer may complete the Human Verified Assessment with no public listing or disclosure of its assessment results.

If elected, Registry publication is a separate downstream step, limited to verified and Registry-eligible information and requiring AGCP review and explicit customer authorization.

Explore the AGCP Registry

Assessment Leadership

Each Human Verified Assessment is currently performed or directly supervised by John M. Willis, AGCP founder and principal architect.

His 20+ years of cybersecurity assessment and security-architecture experience include NIST RMF / SP 800-53 control assessments, federal High Value Asset and cloud-architecture assessments, and Zero Trust initiatives. He has led assessment activity across more than 90 federal FISMA systems annually and holds the CISA High Value Asset Technical Lead Assessment Qualification.

Material control determinations are human verified under direct AGCP assessment oversight.

Scope and Claim Boundaries

  • One qualifying system/version and one agreed assessment boundary.
  • Not a questionnaire, keyword scan, legal opinion, safety certification, or guarantee of production readiness.
  • Does not require AGCP’s proprietary Runtime or one prescribed internal architecture.
  • Typical completion is approximately 2–3 weeks after a complete submission; timing varies with complexity, applicable controls, customer availability, and evidence gaps.
  • Materially broader scope, multiple systems/versions, or unusual evidence requirements may require separate scoping.
  • Customer materials are processed in AGCP’s private AI assessment environment and are not used for AI training.

Ready to Assess Your System?

Discuss the assessment boundary, applicable controls, evidence requirements, and technical participation needed for an AGCP Human Verified Assessment.