aisecurity.llc
hello@aisecurity.llc
Legal Agreement · Negotiation Draft
Agentic Workflow ROE Addendum
Bounds testing of tool-using agents and automated workflows — tools/actions in scope, authorized adversarial techniques, action boundaries, rollback, persistence prohibition, and audit-gap reporting.
1. Purpose
This addendum bounds testing of tool-using agents and automated workflows for engagement the engagement agreed during scoping under the applicable Statement of Work. It applies where the scope includes an agent, copilot, or workflow that can read data, decide, invoke tools, change state, or trigger downstream actions.
2. Agent Tools and Actions In Scope
The agent's tools, actions, and connected systems that may be exercised during testing:
- The agent tools, actions, connectors, and downstream systems enumerated and confirmed in writing during scoping.
- Any tool, connector, or downstream system not listed is out of scope, and irreversible real-world actions are not triggered unless explicitly authorized.
Any tool, connector, or downstream system not listed here is out of scope. Testing does not trigger irreversible real-world actions (payments, production writes, customer-facing messages) unless explicitly authorized below.
3. Authorized Adversarial Techniques
Within safe limits, the following agent-focused techniques are authorized:
- Prompt injection (direct and indirect)
- Jailbreak and policy-bypass attempts
- Context-window manipulation
- RAG corpus poisoning simulation (read-only unless separately authorized)
- Tool misuse and function-call abuse
- Unsafe action-path exploration
- Output-handling and data-exfiltration-via-output testing
- Agent goal hijacking
- Additional technique families only as confirmed in writing during scoping
Testing focuses on tool-permission abuse, unauthorized action paths, prompt and indirect-prompt injection, memory/context abuse, connector-scope abuse, and audit-gap discovery.
4. Action Boundaries and Rollback
- Destructive or irreversible actions are simulated against non-production targets unless a specific action is explicitly authorized against a named target.
- Human-approval and rollback paths identified during scoping are exercised, not bypassed in production.
- Provider does not establish persistence (modified prompts, stored instructions, lingering connectors) in any environment.
Prohibited Actions
- Accessing, modifying, exfiltrating, or destroying production data not in the authorized targets
- Attacking systems, endpoints, or accounts not in the authorized targets
- Social engineering of Client personnel unless separately authorized
- Denial of service or load testing unless separately authorized
- Introducing persistent artifacts (backdoors, modified prompts) into any environment
- Sharing test artifacts, prompts, or findings outside the named delivery contacts
- Publishing or referencing Client systems or findings without written consent
5. Evidence, Logging, and Escalation
- Agent test artifacts (prompts, tool-call traces, outputs) are confidential and stored in an access-controlled, encrypted store available only to named delivery contacts.
- Where audit logs exist, Provider correlates findings to logged actions; gaps in audit coverage are themselves reported.
- Evidence retention, emergency stop, and escalation follow the Rules of Engagement and the Evidence Handling Policy.
6. Signatures
Client:
Signature: ______________________________ Name: ______________________________ Date: ____________
Provider (aisecurity.llc):
Signature: ______________________________ Name: David Wolf Title: Principal Date: ____________
These materials are provided for transparency and scoping. They are not legal advice and do not replace a final signed agreement. Consult qualified legal counsel before execution.