監査で確認する範囲
applicationとAgentを一緒に検証します。identity、authentication、authorization、tenant isolation、data、MCP/API tools、memory、upload、payment、secret、log、limit、approval、recoveryが対象です。
active testの前にscope、test account、手法、時間帯、停止条件、evidenceの扱い、owner approvalを書面で合意します。
結果は特定日時のrisk snapshotであり、絶対安全のcertificateではありません。business impact順に直し、access、tools、memory、payment、model、infrastructureの重要変更後に再監査します。