ConsultingWorkbench-backed AI security engagements — map, attack, defend, and prove your AI systems.
Scope a Review
Deliverablesdeliverable
deliverable
public-sample

Northstar Support Cloud Sample Pack

A guided sample pack showing how the Northstar Support Cloud engagement turns intake, inventory, architecture, retrieval, tools, evidence, and remediation into a coherent buyer story.

14-24 pages4 offers2 CTAs3 personas
Publication overview
public-sample
14-24 pages4 offers3 personas2 CTAs
System
Northstar Support Cloud Sample Pack
Environment
Production pilot
# Northstar Support Cloud Sample Pack
Guided Sample Pack

Executive Summary

This sample pack shows the buyer journey for a fictional but realistic AI Product Security engagement. It follows Northstar Support Cloud and its Customer Support Copilot from first intake through architecture review, retrieval authorization, tool permissions, evidence packaging, release gating, and remediation. The value of the pack is not that it contains every artifact. The value is that it shows how the artifacts fit together into a proof chain a buyer can understand.

Decision · planned

Sample pack decision

northstar-support-cloud-sample-pack

Use this pack as the guided tour for buyer-facing samples. Lead with the intake pack, system inventory, architecture review, RAG authorization review, tool inventory, evidence pack, and release gate.

Metrics

Sample Pack Snapshot

northstar-support-cloud-sample-pack
Buyer journey stages
8
Featured artifacts
13
Primary owners
7
Release blockers
4
Buyer-safe proof points
5
executive

What buyers should learn

Buyers should leave this pack understanding what they actually get: intake, inventory, architecture evidence, retrieval proof, delegated-action boundaries, control gaps, buyer-safe evidence, and a remediation roadmap.
## Engagement context

Northstar Support Cloud context

northstar-support-cloud-sample-pack
FieldValue
ClientNorthstar Support Cloud
ProductCustomer Support Copilot
Environmentproduction pilot
Core AI surfacesupport copilot with RAG, model gateway, case management, customer messaging, billing read access, and internal notifications
Key concernproof that retrieval and tool authority stay inside defined boundaries
## Buyer journey

Buyer journey through the sample pack

northstar-support-cloud-sample-pack
StageArtifactWhat it proves
1AI Security Discovery / Intake Packscope, urgency, stakeholders, and evidence gaps
2AI System Inventory / Application Registerowners, systems, retrieval, tools, and trace state
3AI Architecture Reviewboundary evidence and launch readiness
4RAG Authorization Reviewretrieval ACL proof and negative testing posture
5Agent Tool Inventory / Tool BOMtool authority, credentials, and actions
6Agent Tool Permission Matrixallowed, conditional, blocked, and denied actions
7AI Control Gap Assessmentowned gaps and release blockers
8Enterprise AI Security Evidence Packbuyer-safe proof and questionnaire answers
9AI Governance Evidence Matrixcontrol-to-evidence mapping
10AI Release Gate Checklistsafe change and launch gate
11AI Red Team Assessment Executive Summaryadversarial validation and executive summary
12AI Security Remediation Roadmapremediation sequencing
## Featured artifacts
Artifact

AI Security Discovery / Intake Pack

The intake pack is the first step in the Northstar sample story.

/deliverables/ai-security-discovery-pack
Artifact

AI System Inventory / Application Register

The inventory names the owners, surfaces, and evidence gaps.

/deliverables/ai-system-inventory
Artifact

AI Architecture Review

The architecture review proves where AI authority starts and stops.

/deliverables/ai-architecture-review
Artifact

RAG Authorization Review

The retrieval review proves whether access control survives indexing and assembly.

/deliverables/rag-authorization-review
Artifact

Agent Tool Inventory / Tool BOM

The tool inventory names the tools, credentials, and action classes.

/deliverables/agent-tool-inventory
Artifact

Agent Tool Permission Matrix

The permission matrix shows what is allowed, conditional, blocked, or denied.

/deliverables/agent-tool-permission-matrix
Artifact

AI Control Gap Assessment

The control gap assessment turns partial posture into owned remediation.

/deliverables/ai-control-gap-assessment
Artifact

Enterprise AI Security Evidence Pack

The evidence pack shows how to answer procurement and trust questions.

/deliverables/enterprise-ai-security-evidence-pack
Artifact

AI Governance Evidence Matrix

The governance matrix maps claims to evidence.

/deliverables/ai-governance-evidence-matrix
Artifact

AI Release Gate Checklist

The release gate shows how AI changes are prevented from shipping unsafely.

/deliverables/ai-release-gate-checklist
Artifact

AI Red Team Assessment Executive Summary

The red-team summary shows validation, impact, and remediation pressure.

/deliverables/ai-red-team-executive-summary
Artifact

AI Security Remediation Roadmap

The roadmap turns findings into sequenced work.

/deliverables/ai-security-remediation-roadmap
## Buyer questions

Questions this sample pack should answer

What AI features are in scope?
Where does the AI gateway enforce boundaries?
Can retrieval bypass authorization?
What can the tools actually do?
What evidence exists for enterprise review?
## Print note