> > > > > >
An AI agent readiness assessment for Operations and IT teams preparing a real business workflow for autonomous execution. Not an enterprise readiness score — one workflow, mapped as it actually runs, assessed across the three layers that decide whether an agent can work it. auxfirst calls this the Agent Operability Audit.
Most enterprises are discovering the same thing IT leaders now say openly: agents fail not because the models are weak, but because the workflow underneath them was never designed to be operated by anything except a human with tribal knowledge and a browser. The data isn't shaped for machine consumption, the process has undocumented human judgment baked into every third step, and nobody can answer the question that decides everything: what is this agent allowed to do, as whom, and who owns what it produces?
Book the scoping call Read the field guideCan an agent actually consume what this workflow runs on?
What should it read, draft, decide, or execute — and at what temperature?
As whom does it act, with what privileges, accountable to whom?
AI agent readiness is a property of a workflow, not of a company. A workflow is agent-ready when three conditions hold at the same time: an agent can consume the data the work actually runs on, the process is explicit enough that every step can be deliberately assigned to a human or to an agent, and the agent has its own identity, its own permission envelope, and an accountability trail for what it produces. The weakest of the three sets the ceiling. An organization with excellent data and no permission model is not agent-ready — it is agent-curious.
This matters because readiness is usually assessed one level too high. A company can score well on data maturity, cloud posture, skills and policy while every workflow it actually wants to delegate remains impossible to delegate — because the approval step lives in someone’s inbox, because the vendor portal has no API, or because no one can say which identity the agent acts as when it touches the finance system.
Three questions decide it, and they are answered per workflow:
Generic AI readiness assessments score the organization and return a maturity level with a roadmap attached. That was the right instrument when the question was whether to adopt a model at all. It is the wrong instrument when the question is whether a specific piece of work can be handed over — because maturity scores average away the one blocker that stops the project, and the blocker is almost never at the enterprise level.
The practical difference shows up in what you can do the next morning:
| Enterprise AI readiness assessment | Workflow agent readiness assessment | |
|---|---|---|
| Unit assessed | The organization | One workflow, end to end |
| Typical output | Maturity score, capability roadmap | Operability map, operating model, identity card, decision |
| Answers | Are we ready to adopt AI? | Can an agent work this, as whom, and who answers for the result? |
| Time to a decision | Quarters | Three weeks |
| Failure mode | Averages away the one blocker | Only tells you about the workflow you picked |
| Best used when | Setting AI strategy | Deciding whether to fund a specific pilot |
The second is not a smaller version of the first. It is the diagnostic that stops the first from producing pilots that die in security review. The lifecycle this sits inside — from framing through supervision — is covered in the AI agent development lifecycle.
The agent summarizes, observes, and impresses — on preselected data, with controlled exceptions, under a borrowed login. Nothing has actually moved, so nothing has actually been proven.
The agent performs a defined share of the work — with shaped context, deliberate autonomy per action, its own identity and permission envelope, and an accountability trail that survives an audit.
One workflow, end to end. You pick it — invoice handling, campaign QA, RFP response, customer onboarding, vendor compliance. We map it as it actually runs, not as the process doc claims.
We assess structured and unstructured sources, where knowledge lives only in people's heads or inboxes, and what needs restructuring before an agent can act rather than merely summarize.
Which steps carry human judgment that should stay human, which are mechanical and should move, and where the handoffs break. We redraw the workflow as a human–agent operating model using the Action Heat Ladder: what the agent reads, drafts, decides, and executes — and at what temperature.
The layer everyone skips and the reason most pilots die in security review. Cross-functional workflows need access no single employee has, which means the agent needs its own role, its own privileges, and its own accountability trail. We define the agent's identity, its trust tier, its permission envelope, and the authorship layer that makes its output auditable. Agents can't keep things secure on their own — the architecture around them has to.
The workflow's current state versus its agent-ready state — where operability breaks, layer by layer, attached to specific steps.
What the agent can consume today, what's trapped in tribal knowledge, and a prioritized fix list tied to the actions being delegated — not a generic cleanup backlog.
The workflow redrawn: what the agent reads, drafts, decides, and executes, at what heat, with which approvals — and where humans stay load-bearing.
The one-page operating contract defining the agent's role, trust tier, permission envelope, escalation paths, and review lifecycle — the artifact security review actually wants to see.
An evidence-backed decision with a scoped implementation path. "Wait" is a legitimate answer — it means not funding a pilot whose constraints are already visible.
Delivered as a working session with your IT and business owners — not a PDF that dies in a drive.
Run this against the workflow you have in mind before you talk to anyone, including us. Four checks per layer. Any layer where you can’t answer three of four is where your pilot will stall.
Ten or more: your workflow is a strong candidate, and the audit will mostly be about sequencing. Six to nine: the common case — the gaps are known and fixable, and the audit tells you which ones actually block the delegation you want. Five or fewer: valuable to know now rather than two quarters into a pilot.
The longer version — a scored 42-item self-assessment — is in the free field guide, The Agent-Operable Enterprise.
These are the workflows clients most often bring. The pattern is consistent: the blocker is rarely the model, and rarely the one the team expected. Illustrative composites, not client cases.
Fixes are prioritized against the delegation case — the smallest shaping work that makes the action safe, not a multi-year transformation.
One workflow, mapped as it actually runs. Operability lives at the level where work happens — not in an enterprise-wide readiness claim.
It's the diagnostic that tells you whether the pilot you're about to fund will survive contact with your permissions model — before you spend two quarters finding out.
If the workflow turns out to be agent-ready, you'll know exactly why. If it isn't, you'll have the shortest path to making it so — with the gaps tied to specific actions and the owner for each fix. Either way, you leave with the first reusable piece of your delegation architecture.
The Agent-Operable Enterprise — the free field guide behind this audit — covers the full three-layer model, the Action Heat Ladder, the Agent Identity Card, the permissions problem, headless vendor readiness, the 90-day path, and the scored 42-item self-assessment. We give away most of the methodology deliberately: the value isn't knowing the steps exist. It's running them with rigor and cross-functional accountability.
Each auxfirst audit answers one question with evidence. This one asks whether your workflow is ready. Its siblings ask about your agent — and about your brand.
A structured evaluation of whether a specific business workflow can be performed by an AI agent rather than merely observed by one. It assesses the data the workflow runs on, the design of the process itself, and the identity and permissions the agent would need. auxfirst delivers it as the Agent Operability Audit: one workflow, three weeks, €9,500 fixed.
Scope. An AI readiness assessment scores an organization's overall capability to adopt AI. This assesses one workflow's capability to be delegated. Organizations routinely score well on the first and fail the second, because the blocker is usually a specific permission, a specific undocumented judgment, or a specific system with no API.
Three weeks, €9,500, fixed. Delivered as a working session with your IT and business owners rather than a document.
The workflow, its business owner, and someone who can speak to the systems it touches. You don't need to clean data, write documentation or build anything first — mapping the workflow as it actually runs is part of the assessment.
You get the shortest path to making it so, with each gap tied to a specific action and a named owner. Wait is one of the four recommendations and it is a legitimate outcome — it means not funding a pilot whose constraints are already visible.
The workflow's business owner and someone from IT or security with authority over access. Cross-functional workflows need access no single employee has, which is exactly the question the third layer resolves — and it cannot be resolved without both sides present.
The assessment ends in a build / buy / orchestrate / wait recommendation with a scoped implementation path. auxfirst can design the build — that engagement is AI agent workflow design — but the assessment is deliberately independent of it, because an assessment that can only conclude build isn't an assessment.
Invoice handling, campaign QA, RFP response, customer onboarding, vendor compliance — or the one that's been stuck in "pilot" for two quarters. Book the scoping call and bring the workflow's owner if you can.
Book the scoping callIn the message, mention "Agent Operability Audit" plus the workflow you have in mind — that's all we need to scope it.
Audits are led personally by Emil Krzemiński, founder of auxfirst, the agentic experience design agency — and author of The Agent-Operable Enterprise, the field guide this audit runs with rigor. Read the launch note: What is agent operability — and why your enterprise needs it.