An example, not your data: this is what uvx ranwhat demo --html report.html writes for a bundled sample agent. What the scores mean · Run it on your own

ranwhat · agent authority & insurability

support-copilot

Generated by ranwhat demo · read-only credential introspection
UNINSURABLE

Cannot reconstruct past actions

An underwriter cannot distinguish this deployment from the worst case, because it cannot produce the tool call, the authority used, and the guardrail decision for a named past action. Expect declined coverage or flat-rate penalty pricing regardless of how well the agent actually behaves.

Authority
19/100 · F
Observability
25/100 · F
Reversibility
24/100 · F

Exposure

Permissions granted23
Exercised in window8
Never exercised15
Financial authorityunbounded
Irreversible actions available13
Blast radiusdata_egress, external_comms, identity, infrastructure, monetary

Usage coverage

No usage pull was run. Granted permissions could not be compared against exercised ones.

Findings

critical

High-authority permissions granted but never used

5 permission(s) that can move money or destroy data have not been exercised in the observed window. This is pure downside: full liability, zero utility.

critical

Actions are not reconstructable

Traces do not carry tool name, arguments, credential identity and guardrail decision. You cannot answer the question an underwriter or a plaintiff will ask: what exactly did the agent do, and under whose authority.

critical

Destructive authority held

These permissions allow irreversible destruction of data or infrastructure. Several also allow deletion of the records that would evidence the action.

critical

Unbounded financial authority

The agent can move money with no per-action spend cap configured.

high

No human approval gate

Documented human oversight is becoming a condition of coverage, not a best practice. Its absence shifts liability squarely onto the operator who configured the agent.

high

No kill switch

There is no documented mechanism to halt the agent mid-task.

medium

Unclassified permissions

1 scope(s) are not in the capability catalog and were classified by action verb. Confirm these manually.

low

Usage is self-attested for 5 provider(s)

Usage for these providers was declared in the profile rather than pulled from the provider's own audit trail. The findings hold only as far as that declaration does. Run `uvx ranwhat scan <profile> --pull-usage` to make them independently evidenced.

Granted permissions

ScopeProviderAuthorityReversibleUsage
s3:*
Full S3 control
awsdestructivenounused
workflow
Update GitHub Actions workflows
githubdestructivenounused
https://www.googleapis.com/auth/drive
Full Drive access
googledestructivenounused
charges:write
Create and capture charges
stripefinancialnounused
refunds:write
Issue refunds
stripefinancialnoused
transfers:write
Move money to connected accounts
stripefinancialnounused
ses:SendEmail
Send email
awswritenounused
lambda:InvokeFunction
Invoke functions
awswriteyesused
dynamodb:PutItem
dynamodb:PutItem
awswritenounused
repo
Full control of private repositories
githubwritenounused
gist
Create gists
githubwritenounused
https://www.googleapis.com/auth/gmail.modify
Read, send, modify and label mail
googlewritenoused
https://www.googleapis.com/auth/gmail.send
Send mail as the user
googlewritenoused
https://www.googleapis.com/auth/calendar
Read/write calendar
googlewriteyesunused
https://www.googleapis.com/auth/contacts
Read/write contacts
googlewriteyesunused
chat:write
Post messages
slackwritenoused
customers:write
Modify customer records
stripewriteyesunused
read:org
Read org membership
githubreadyesused
channels:history
Read public channel history
slackreadyesused
groups:history
Read private channel history
slackreadyesunused
im:history
Read direct messages
slackreadyesunused
files:read
Read files
slackreadyesunused
customers:read
Read customer records
stripereadyesused