Sample deliverable / AI security review

A useful finding connects a risk to evidence and a decision.

Illustrative example using a fictional support assistant. This is not a client engagement, an executed security test or evidence about any deployed product.

01 / Question and scope

Can a support assistant safely retrieve customer records and prepare refund requests? This example covers one authenticated user, a retrieval service and a refund tool. Identity-provider configuration, infrastructure and model-provider internals are outside scope.

User → application authorization → retrieval → model → tool authorization → approval → refund service

02 / Prioritized findings

High / Cross-customer retrieval

The model must not choose the authorization boundary.

Illustrative evidence: a retrieval tool accepts a customer ID in generated arguments, without a server-side membership check in the assumed design.

Recommendation: derive the permitted customer scope from the authenticated session; enforce it in the query. Treat model arguments as untrusted input.

Acceptance check: an authorized test account requesting another customer's record is denied before retrieval. No such test was run for this sample.

High / Refund authority

Preparing a refund and executing it need separate permissions.

Illustrative evidence: the assumed tool can issue a refund with the same credential used to read order status.

Recommendation: separate read and write privileges, require explicit approval tied to the exact order and amount, and reject reused approvals.

Acceptance check: changed amounts, expired approvals and repeated requests cannot produce an unintended refund.

Medium / Evidence gap

Record decisions without copying private conversations into logs.

Illustrative evidence: the assumed log records generated text but lacks a stable action ID and authorization outcome.

Recommendation: record action identifiers, policy decisions and approval references with bounded retention. Exclude customer messages and secrets.

Acceptance check: an operator can reconstruct why an action was allowed without accessing raw conversation content.

03 / Decision and follow-through

For this fictional design, keep refund execution disabled until authorization and approval checks pass. A read-only pilot still requires verified customer isolation. Assign each unresolved item an owner and a verification date.

A real assessment distinguishes observed behavior, reviewed materials, assumptions and untested boundaries. A review does not certify the entire system.

Discuss a technical review → About AI systems & security reviews →