Skip to content
ARK productAvailable

ARK Agent Readiness

Make your systems usable by agents.

Evaluate whether agents can safely and reliably interact with your applications, APIs, tools and workflows.

Most systems were designed for humans clicking through a screen. Agents arrive through a different door: they discover capabilities, read schemas, authenticate as themselves and act without a person watching each step.

Agent readiness is the question of whether your systems can survive that. Not whether an agent can be made to work once in a demo, but whether it can act correctly, within its authority, and leave a record.

What it evaluates

Three layers, assessed separately.

A system can have a clean interface and no way to say who did what. These fail independently, so they are scored independently.

Interface

  • Discovery
  • APIs
  • MCP and agent protocols
  • Schemas
  • Tool interfaces

Authority

  • Authentication
  • Identity
  • Permissions
  • Approval paths
  • Revocation

Operations

  • Security
  • Reliability
  • Observability
  • Cost
  • Failure behaviour

Two ways to run it

Start free. Escalate if the answer is uncomfortable.

Free · self-assessed

Free

Agent Readiness Scorecard

20 questions across 7 dimensions, scored in your browser. Nothing is submitted anywhere. You get a band, the dimensions dragging the score down, and what to fix first.

  • Discovery
  • Interfaces
  • Identity
  • Permissions
  • Observability
  • Security
  • Reliability

Paid · evidence-based

2–3 weeks

Agent Readiness Assessment

Run by ARC against your actual systems rather than your impression of them. We inventory what is already live — including the agents a team switched on without telling anyone — rank what each one could damage, and put approval and revocation gates on the actions that matter.

  • Agent, tool and credential inventory
  • Blast-radius ranking per identity
  • Approval and revocation gates for irreversible actions
  • Spend guardrails with a named owner
  • 30/60/90 hardening plan

Why it is a different question

Agents arrive through a different door.

A human finds the button. An agent has to discover the capability, read the schema, authenticate as itself, resolve what it is allowed to do, act, and leave something behind that proves what happened.

Readiness is measured against that sequence. Each step can fail on its own, and a system that passes eight of nine is still the system that cannot tell you who did what.

Agent operating lifecycle

  1. 01

    Discover

    Find out which capabilities, tools and resources exist, and which ones apply to the task in hand.

  2. 02

    Authenticate

    Prove which agent is acting, on whose behalf, and under which credential.

  3. 03

    Understand

    Read schemas, contracts and side effects well enough to call a tool correctly the first time.

  4. 04

    Permission

    Resolve what this identity is allowed to do right now, including the actions that need a human.

  5. 05

    Execute

    Run the work in an environment that fits its privacy, latency, policy and cost constraints.

  6. 06

    Verify

    Collect evidence from the systems that were supposed to change, not from the agent's own report.

  7. 07

    Measure

    Attribute cost, latency and success to a unit of work a business can recognise.

  8. 08

    Remember

    Persist state so the next run starts from what happened, not from an empty context.

  9. 09

    Audit

    Keep a record someone can defend later: what was attempted, under what authority, with what result.

Limits

What this is not.

Stated on the page rather than discovered in month three.

  • It is not a penetration test and not a red-team exercise.
  • It does not certify anything. It tells you what is ready and what is not.
  • The free scorecard is self-reported, so it is a starting point rather than evidence.

Want the assessment rather than the self-assessment?

The full engagement runs against your real systems: the inventory, the blast-radius ranking, the approval gates and a hardening plan with named owners. Thirty minutes is enough to scope it.