Sample deliverable / AI security review
A useful finding connects a risk to evidence and a decision.
Illustrative example using a fictional support assistant. This is not a client engagement, an executed security test or evidence about any deployed product.
01 / Question and scope
Can a support assistant safely retrieve customer records and prepare refund requests? This example covers one authenticated user, a retrieval service and a refund tool. Identity-provider configuration, infrastructure and model-provider internals are outside scope.
User → application authorization → retrieval → model → tool authorization → approval → refund service
02 / Prioritized findings
High / Cross-customer retrieval
The model must not choose the authorization boundary.
Illustrative evidence: a retrieval tool accepts a customer ID in generated arguments, without a server-side membership check in the assumed design.
Recommendation: derive the permitted customer scope from the authenticated session; enforce it in the query. Treat model arguments as untrusted input.
Acceptance check: an authorized test account requesting another customer's record is denied before retrieval. No such test was run for this sample.
High / Refund authority
Preparing a refund and executing it need separate permissions.
Illustrative evidence: the assumed tool can issue a refund with the same credential used to read order status.
Recommendation: separate read and write privileges, require explicit approval tied to the exact order and amount, and reject reused approvals.
Acceptance check: changed amounts, expired approvals and repeated requests cannot produce an unintended refund.
Medium / Evidence gap
Record decisions without copying private conversations into logs.
Illustrative evidence: the assumed log records generated text but lacks a stable action ID and authorization outcome.
Recommendation: record action identifiers, policy decisions and approval references with bounded retention. Exclude customer messages and secrets.
Acceptance check: an operator can reconstruct why an action was allowed without accessing raw conversation content.
03 / Decision and follow-through
For this fictional design, keep refund execution disabled until authorization and approval checks pass. A read-only pilot still requires verified customer isolation. Assign each unresolved item an owner and a verification date.
A real assessment distinguishes observed behavior, reviewed materials, assumptions and untested boundaries. A review does not certify the entire system.
Discuss a technical review → About AI systems & security reviews →