# AI vendor assessment: <product or agent>

Assess the agent or workflow, not the vendor as a whole. One sheet per agent.

## What it does

1. Purpose and the workflows it runs
2. Inputs it reads, outputs it produces, actions it executes in which systems
3. Autonomy level as documented: assistance, copilot, action, workflow, autonomous
4. Human approval: where required, where optional, where absent

## Control

5. Audit log of actions: exists, exportable, retention
6. Explainability: can a user see why an action was taken
7. Guardrails: limits, allow-lists, rollback

## Data

8. Which of our data is sent to the model, and to whose model
9. Training on our data: yes/no, contractual basis
10. Data residency and retention

## Evidence

11. Documentation links for 1 to 10
12. What we were able to verify ourselves, and how (demo, sandbox, reference)

## Outcome

Fit for <use case>: yes / with conditions / no, with the evidence that decides it.
