Submitting an Agent for Review
Agent owners submit their agents for agent review by completing a security questionnaire. This page walks through the entire submission process from start to finish.
Before you start
- Your agent must be in draft status.
- The Agent Review must be enabled on your organization.
- You must be the owner of the agent (or an org admin).
- Your agent's environment (non-prod or prod) must match agent review's required environment setting.
What the submission includes
A submission contains your answers to the security questionnaire (covering data flow, tool scope, autonomy, network access, compliance, privacy, and prompt security), plus your selections for which MCP servers and skills the agent should have access to. These answers are compiled into a guardrail profile that enforces security rules at runtime.
Open your agent's detail page
Navigate to AI Company → Agents and click on the agent you want to submit. Or go directly to /dashboard/ai-company/agents/[id].
Complete identity verification
Before the questionnaire opens, you'll need to verify your identity. This prevents automated or accidental submissions.
- If you have SignedApproval connected: A push notification is sent to your mobile app. Approve it within 5 minutes.
- Otherwise: Complete a Cloudflare Turnstile CAPTCHA challenge.
Select the deployment environment
The first step of the wizard asks which environment this agent will run in:
- Non-Production — Development, staging, or testing environments.
- Production — Live environments serving real users or data.
- Both — The agent will run in both environments.
Answer the security questionnaire
Work through the multi-step wizard. The questionnaire has 14 steps covering:
- Environment — Deployment target
- Operations — Expected workload description
- Triggers — How the agent is activated
- Data Flow (D1–D7) — PII, PHI, financial data, persistence, key interception
- Tool Scope (T2–T5) — Browser automation, models, APIs, write permissions
- Autonomy (A1–A6) — Budget, rate limits, session duration, approval gates
- Network (N1–N3) — Domain restrictions, private networks, URL blocking
- Compliance (C1–C6) — Frameworks, audit logging, retention
- Privacy (PV1–PV7) — Data storage, third-party sharing, minors, cross-border
- Prompt Security (P1–P4) — Untrusted input, multi-step chains, system prompt protection
- Security Context (S1–S6) — Authorized sources, exfiltration boundaries, threat model
- Review — Summary of all answers
- Key Access — Provider key bindings for the agent
- Verify & Submit — Final confirmation
Select MCP servers and skills
During the Tool Scope section, you'll select which MCP servers and skills the agent should have access to. Only governed integrations will be available at runtime — any tool not on this list will be blocked by the gateway.
Review and submit
The Review step shows a summary of all your answers. Check everything carefully — once submitted, you can only withdraw and resubmit, not edit in place. Click Submit for Review to send the submission to reviewers.
Wait for agent review
Your submission is now pending. Reviewers will be notified (if they have notifications enabled). You can track the status on Agent Review page or in your agent's detail view.
If your submission is rejected, you'll receive feedback in the rejection rationale. You can address the concerns and resubmit.