> > > > > >
AI Agent Readiness Assessment · Fixed price · Three weeks · One workflow, end to end

Is your workflow ready for AI agents — or only ready to be watched by one?

An AI agent readiness assessment for Operations and IT teams preparing a real business workflow for autonomous execution. Not an enterprise readiness score — one workflow, mapped as it actually runs, assessed across the three layers that decide whether an agent can work it. auxfirst calls this the Agent Operability Audit.

Most enterprises are discovering the same thing IT leaders now say openly: agents fail not because the models are weak, but because the workflow underneath them was never designed to be operated by anything except a human with tribal knowledge and a browser. The data isn't shaped for machine consumption, the process has undocumented human judgment baked into every third step, and nobody can answer the question that decides everything: what is this agent allowed to do, as whom, and who owns what it produces?

Book the scoping call Read the field guide

€9,500 fixed · One workflow, three weeks · Delivered as a working session

The category, defined

What AI agent readiness actually means

AI agent readiness is a property of a workflow, not of a company. A workflow is agent-ready when three conditions hold at the same time: an agent can consume the data the work actually runs on, the process is explicit enough that every step can be deliberately assigned to a human or to an agent, and the agent has its own identity, its own permission envelope, and an accountability trail for what it produces. The weakest of the three sets the ceiling. An organization with excellent data and no permission model is not agent-ready — it is agent-curious.

This matters because readiness is usually assessed one level too high. A company can score well on data maturity, cloud posture, skills and policy while every workflow it actually wants to delegate remains impossible to delegate — because the approval step lives in someone’s inbox, because the vendor portal has no API, or because no one can say which identity the agent acts as when it touches the finance system.

Three questions decide it, and they are answered per workflow:

Can an agent read this?Not “do we have data” — can the specific inputs this work depends on be consumed by software, including the parts that currently live in email threads, PDFs, and people’s heads.
Can an agent be given this?Not “is the process documented” — can each step be classified as something an agent reads, drafts, decides, or executes, with the judgment-carrying steps deliberately left to humans.
Can an agent be held to this?Not “do we have an AI policy” — does the agent have a role, a credential, a permission boundary and a log that a security reviewer would accept.
The distinction that matters commercially

Why workflow readiness is different from AI readiness

Generic AI readiness assessments score the organization and return a maturity level with a roadmap attached. That was the right instrument when the question was whether to adopt a model at all. It is the wrong instrument when the question is whether a specific piece of work can be handed over — because maturity scores average away the one blocker that stops the project, and the blocker is almost never at the enterprise level.

The practical difference shows up in what you can do the next morning:

Enterprise AI readiness assessmentWorkflow agent readiness assessment
Unit assessedThe organizationOne workflow, end to end
Typical outputMaturity score, capability roadmapOperability map, operating model, identity card, decision
AnswersAre we ready to adopt AI?Can an agent work this, as whom, and who answers for the result?
Time to a decisionQuartersThree weeks
Failure modeAverages away the one blockerOnly tells you about the workflow you picked
Best used whenSetting AI strategyDeciding whether to fund a specific pilot

The second is not a smaller version of the first. It is the diagnostic that stops the first from producing pilots that die in security review. The lifecycle this sits inside — from framing through supervision — is covered in the AI agent development lifecycle.

The distinction that decides everything

The Agent Operability Audit answers it — for one workflow, in three weeks, at a fixed price.

Watched, not worked

The demo posture

The agent summarizes, observes, and impresses — on preselected data, with controlled exceptions, under a borrowed login. Nothing has actually moved, so nothing has actually been proven.

Worked, not watched

The production posture

The agent performs a defined share of the work — with shaped context, deliberate autonomy per action, its own identity and permission envelope, and an accountability trail that survives an audit.

Scope · One workflow, three layers

What the readiness assessment covers

One workflow, end to end. You pick it — invoice handling, campaign QA, RFP response, customer onboarding, vendor compliance. We map it as it actually runs, not as the process doc claims.

Layer 1 · Data shape

Can an agent actually consume what this workflow runs on?

We assess structured and unstructured sources, where knowledge lives only in people's heads or inboxes, and what needs restructuring before an agent can act rather than merely summarize.

Layer 2 · Process design

Which steps carry judgment, and which are mechanical?

Which steps carry human judgment that should stay human, which are mechanical and should move, and where the handoffs break. We redraw the workflow as a human–agent operating model using the Action Heat Ladder: what the agent reads, drafts, decides, and executes — and at what temperature.

Layer 3 · Trust & permissions

As whom does the agent act — and who answers for the result?

The layer everyone skips and the reason most pilots die in security review. Cross-functional workflows need access no single employee has, which means the agent needs its own role, its own privileges, and its own accountability trail. We define the agent's identity, its trust tier, its permission envelope, and the authorship layer that makes its output auditable. Agents can't keep things secure on their own — the architecture around them has to.

Deliverables

What you get from the assessment

Deliverable AWorkflow operability map

The workflow's current state versus its agent-ready state — where operability breaks, layer by layer, attached to specific steps.

Deliverable BData readiness assessment

What the agent can consume today, what's trapped in tribal knowledge, and a prioritized fix list tied to the actions being delegated — not a generic cleanup backlog.

Deliverable CHuman–agent operating model

The workflow redrawn: what the agent reads, drafts, decides, and executes, at what heat, with which approvals — and where humans stay load-bearing.

Deliverable DAgent Identity Card

The one-page operating contract defining the agent's role, trust tier, permission envelope, escalation paths, and review lifecycle — the artifact security review actually wants to see.

Deliverable EBuild / buy / orchestrate / wait recommendation

An evidence-backed decision with a scoped implementation path. "Wait" is a legitimate answer — it means not funding a pilot whose constraints are already visible.

Delivered as a working session with your IT and business owners — not a PDF that dies in a drive.

Run it yourself first

A twelve-point AI agent readiness checklist

Run this against the workflow you have in mind before you talk to anyone, including us. Four checks per layer. Any layer where you can’t answer three of four is where your pilot will stall.

Layer 01 · Data shape

  1. Can an agent retrieve every input this workflow needs without a human forwarding something?
  2. Are the exceptions and edge cases written down anywhere other than in an experienced person’s memory?
  3. Do the systems involved expose an API, or does the work depend on someone clicking through a portal?
  4. Is there a single authoritative version of the record the work updates?

Layer 02 · Process design

  1. Can you list the workflow’s steps in order, as it actually runs rather than as the process doc claims?
  2. For each step, can you say whether it should be read, drafted, decided or executed by an agent?
  3. Do you know which steps carry judgment that must stay human, and why?
  4. Is there a defined outcome that counts as success, and a defined state that counts as a dead end?

Layer 03 · Trust & permissions

  1. Does the agent have its own identity, or would it act under a person’s login?
  2. Can you state the agent’s permitted actions individually, rather than as an autonomy level?
  3. Is there an approval point before every consequential action, and a named human behind it?
  4. If someone asked in twelve months what the agent did and why, could you reconstruct it from the log?

Ten or more: your workflow is a strong candidate, and the audit will mostly be about sequencing. Six to nine: the common case — the gaps are known and fixable, and the audit tells you which ones actually block the delegation you want. Five or fewer: valuable to know now rather than two quarters into a pilot.

The longer version — a scored 42-item self-assessment — is in the free field guide, The Agent-Operable Enterprise.

What actually breaks

Five workflows, and what usually breaks in each

These are the workflows clients most often bring. The pattern is consistent: the blocker is rarely the model, and rarely the one the team expected. Illustrative composites, not client cases.

Invoice handling.Data shape is usually fine. It breaks at layer three: the agent needs write access to the finance system, no individual employee has exactly the right access, and nobody has decided whose credential it borrows.
Campaign QA.Process design is the blocker. “Check it’s on brand” is four different judgments performed by three different people, none of them written down, and an agent cannot be given a rule that has never been stated.
RFP response.The knowledge is real but trapped — in past proposals, in a shared drive with six near-identical versions, and in the two people who know which version was the one that won.
Customer onboarding.Usually the readiest of the five, and it still stalls, because the workflow crosses three teams and no one owns the outcome end to end. An agent inherits that ambiguity and amplifies it.
Vendor compliance.The agent is asked to make determinations with legal consequence. The right answer is often a narrower mandate: the agent assembles the evidence, a named human makes the call.
Honest scope

What this AI agent readiness assessment is not

Not a data cleanup project

Fixes are prioritized against the delegation case — the smallest shaping work that makes the action safe, not a multi-year transformation.

Not an AI strategy deck

One workflow, mapped as it actually runs. Operability lives at the level where work happens — not in an enterprise-wide readiness claim.

Not a pilot

It's the diagnostic that tells you whether the pilot you're about to fund will survive contact with your permissions model — before you spend two quarters finding out.

Scope, price, timeline

One workflow. Three weeks. Fixed.

If the workflow turns out to be agent-ready, you'll know exactly why. If it isn't, you'll have the shortest path to making it so — with the gaps tied to specific actions and the owner for each fix. Either way, you leave with the first reusable piece of your delegation architecture.

The methodology, in the open

We published the field guide. The audit runs it with rigor.

The Agent-Operable Enterprise — the free field guide behind this audit — covers the full three-layer model, the Action Heat Ladder, the Agent Identity Card, the permissions problem, headless vendor readiness, the 90-day path, and the scored 42-item self-assessment. We give away most of the methodology deliberately: the value isn't knowing the steps exist. It's running them with rigor and cross-functional accountability.

agentoperability.com
The Agent-Operable Enterprise
01 Data shape02 Process design03 Trust + permissions
Read it free →
€9,500
Fixed · one workflow · three weeks
  • Workflow operability map, current vs. agent-ready
  • Data readiness assessment + prioritized fix list
  • Human–agent operating model on the Heat Ladder
  • Agent Identity Card: role, tier, permissions
  • Build / buy / orchestrate / wait, with a scoped path
  • Working-session readout with IT & business owners
From the auxfirst canon

Three audits, three questions.

Each auxfirst audit answers one question with evidence. This one asks whether your workflow is ready. Its siblings ask about your agent — and about your brand.

Before the scoping call

Questions we get before the scoping call

What is an AI agent readiness assessment?

A structured evaluation of whether a specific business workflow can be performed by an AI agent rather than merely observed by one. It assesses the data the workflow runs on, the design of the process itself, and the identity and permissions the agent would need. auxfirst delivers it as the Agent Operability Audit: one workflow, three weeks, €9,500 fixed.

How is this different from an AI readiness assessment?

Scope. An AI readiness assessment scores an organization's overall capability to adopt AI. This assesses one workflow's capability to be delegated. Organizations routinely score well on the first and fail the second, because the blocker is usually a specific permission, a specific undocumented judgment, or a specific system with no API.

How long does it take, and what does it cost?

Three weeks, €9,500, fixed. Delivered as a working session with your IT and business owners rather than a document.

What do we need to prepare?

The workflow, its business owner, and someone who can speak to the systems it touches. You don't need to clean data, write documentation or build anything first — mapping the workflow as it actually runs is part of the assessment.

What happens if the workflow isn't ready?

You get the shortest path to making it so, with each gap tied to a specific action and a named owner. Wait is one of the four recommendations and it is a legitimate outcome — it means not funding a pilot whose constraints are already visible.

Who should be in the room?

The workflow's business owner and someone from IT or security with authority over access. Cross-functional workflows need access no single employee has, which is exactly the question the third layer resolves — and it cannot be resolved without both sides present.

Do you build the agent afterwards?

The assessment ends in a build / buy / orchestrate / wait recommendation with a scoped implementation path. auxfirst can design the build — that engagement is AI agent workflow design — but the assessment is deliberately independent of it, because an assessment that can only conclude build isn't an assessment.

Ready when you are

Pick the workflow. We'll tell you if an agent can work it.

Invoice handling, campaign QA, RFP response, customer onboarding, vendor compliance — or the one that's been stuck in "pilot" for two quarters. Book the scoping call and bring the workflow's owner if you can.

Book the scoping call

In the message, mention "Agent Operability Audit" plus the workflow you have in mind — that's all we need to scope it.

Audits are led personally by Emil Krzemiński, founder of auxfirst, the agentic experience design agency — and author of The Agent-Operable Enterprise, the field guide this audit runs with rigor. Read the launch note: What is agent operability — and why your enterprise needs it.