PARTNERS

Add selected Workbench capabilities through bounded OEM and partner integrations

Deliverablesdeliverable
deliverable

AI Red Team Figures

Canonical figures for the AI Red Team and Adversarial Testing service.

Public sample
Client deliverable
public-sample
System
AI Red Team Figures
Environment
Production pilot

# AI Red Team Figures

RED-01coverage matrix

AI Red Team Scope

AI red teaming should state which prompt, retrieval, tool, agent, authority, multimodal, and workflow surfaces are actually tested.

Matrix showing AI red-team coverage across prompt, retrieval, agent, tool, authority, multimodal, and workflow surfaces.

Prompt and instruction

Direct and indirect instruction manipulation, policy conflict, and boundary testing.

Hypothesis
Included
Execution
Included
Reproduction
Included
Evidence
Included
Retest
Optional

Retrieval and corpus

Indirect prompt injection, poisoning, provenance, ranking, and tenant boundaries.

Hypothesis
Included
Execution
Included
Reproduction
Included
Evidence
Included
Retest
Optional

Agent and orchestration

Planning, delegation, memory, tool choice, and workflow transitions.

Hypothesis
Included
Execution
Partial
Reproduction
Partial
Evidence
Included
Retest
Optional

Tools and MCP

Tool schemas, parameter handling, approval, action scope, and external effects.

Hypothesis
Included
Execution
Included
Reproduction
Included
Evidence
Included
Retest
Optional

Identity and authority

User, service, agent, delegated permission, and approval composition.

Hypothesis
Included
Execution
Partial
Reproduction
Partial
Evidence
Included
Retest
Optional

Multimodal input

Images, documents, audio, and mixed-media instruction or data handling.

Hypothesis
Included
Execution
Partial
Reproduction
Partial
Evidence
Included
Retest
Optional

Application workflow

Business logic, state transitions, handoffs, and human approval paths.

Hypothesis
Included
Execution
Included
Reproduction
Included
Evidence
Included
Retest
Optional

Service states

IncludedPartial or environment-dependentOptionalRequires scope confirmation
The matrix is a scope-control device. Every cell must be reconciled against the actual engagement and target environment.
RED-02

Red Team Engagement Flow

A controlled engagement moves from scoping and scenario design through execution, reproduction, evidence, and reporting.

Six-stage AI red-team engagement flow from authorization and scoping through scenario design, controlled execution, reproduction, evidence review, and reporting.

Authorize and scopeSTEP 1Map the targetSTEP 2Design scenariosSTEP 3Execute under controlSTEP 4Reproduce andchallengeSTEP 5Report and hand offSTEP 6Safety and decision controlsCustomer approval governs consequential actions • Sensitive data andtenant boundaries remain explicit • Stop conditions and escalationremain visible
RED-03

What Qualifies as a Finding

Theoretical exposure, observed anomaly, reproduced failure, evidence-qualified path, and analyst-reviewed finding are different claim states.

Claim boundary separating theoretical exposure, observed anomaly, reproduced failure, evidence-qualified path, rejected result, and analyst-reviewed finding.

SUPPORTED CLAIMSupported failureReproduced failureEvidence-qualified consequenceRetest-confirmed reproducibility1Theoretical exposure

A design or capability could permit a failure under some conditions.

2Observed anomaly

Unexpected behavior was captured, but cause and consequence may remain unresolved.

3Challenge alternative explanations4Confirm service and target scope5Assign reportable finding state