A 30-Day Start

Week 1 — See what you have. Inventory every agent, built or adopted, and compare with the registry. Complete the registry and AI-BOM for the single highest-risk agent. Name the most consequential action it can take unsupervised.

Week 2 — Get one run working. Install the Harness and drive the agent end to end; ignore the score. Confirm tool calls appear in the evidence. Run twice unchanged to establish the noise floor.

Week 3 — Make it adversarial. Turn one real business policy into a five-turn trajectory. Add one injection that arrives through a document or a tool result rather than the user. Write the findings properly, root cause separated from manifestation.

Week 4 — Make it a decision. Write three hard-block conditions. Define PASS, REVIEW and BLOCK for this agent, and who approves. Wire the exit code into something that can actually stop a release. Record one release decision completely enough to reconstruct in six months.