AI Ops Audit Start audit

Agent Governance Quick Audit Report - Northstar Growth Studio

Date: 2026-07-24

Industry: Marketing agency

Website: https://example.com

Team size: 12

Primary buyer: Founder

Executive summary

Recommended decision

Proceed with a paid implementation sprint. The upside is large enough to justify immediate workflow cleanup.

Subscription waste and controls

ToolCostUsageWorkflowRiskRecommendation
Jasper$125monthlyBlog draftsLowCancel or consolidate
Zapier$89rarelyLead notificationsLowCancel or consolidate
Report Builder Plugin$79rarelyClient reportingMediumCancel or consolidate
ChatGPT Team$300dailyContent drafts and client researchMediumKeep and monitor
Canva Pro$120dailyCreative productionLowKeep and monitor
HubSpot Starter$45dailyPipeline and follow-upLowKeep and monitor
Claude Team$240weeklyLong-form strategy docsHighKeep only with guardrails
Surfer SEO$219weeklySEO briefsLowRenegotiate or replace

Workflow automation backlog

PriorityWorkflowMonthly labor valuePainImpactAutomation idea
1Client reporting$1,42955Generate recurring client reports from source exports with review before sending.
2Support and client questions$97444Cluster repeated questions, draft approved replies, and route edge cases to a human.
3Sales follow-up$84435Build follow-up reminders and draft personalized responses from CRM notes.
4SEO content briefs$86644Create a brief-generation workflow with human approval and publishing checklist.
5Invoice explanation$52033Automate document collection, transaction explanations, and exception review.

Agent governance and risk

Use this before giving AI agents access to email, CRM, Slack, finance tools, GitHub, or customer-facing workflows.

Readiness score: 25/100

Authority exposure map

WorkflowSystems touchedAction levelCurrent approvalAudit evidenceControl to add
Client reportingGoogle Drive, reporting export, emailDraft and sendInconsistent owner reviewFinal file onlyDraft-only agent mode, owner approval before send, store prompt/output/reason code
Sales follow-upCRM, email, proposal docsDraft customer-facing emailFounder reviewCRM note after sendRequire pre-action approval checklist and log final sent copy
Content or support draftsClient docs, CMS or helpdesk draftCreate draftEditor or support lead reviewDraft stored in workspaceKeep read-only source access and block direct publish/send
Audit trail logPrompt library, tool calls, outputs, approvals, rollback notesEvidence onlyOwner reviews exceptionsPartial prompt historyStore prompts, tool calls, outputs, approvals, exceptions, and rollback decisions in one audit trail

Agent inventory and permission scope

Agent / workflowOwnerConnected systemsPermission scopeEmergency revocation pathEvidence gap
Client reporting agentAccount leadGoogle Drive, reporting export, emailDraft report and draft email onlyDisable email/API token and revert to manual report templateNo single inventory record or revocation runbook
Sales follow-up assistantFounderCRM, email, proposal docsDraft reply from CRM notesRemove CRM/email OAuth grant and use CRM task queueApproval state is not tied to the final sent copy
Content/support drafting assistantEditor or support leadClient docs, CMS/helpdesk draftsRead sources and create draftsRemove CMS/helpdesk token and keep manual draft reviewSource data rules are not documented

Business-unit registry and duplicate-agent cleanup

Business unitAgent / workflowDuplicate riskSpend ownerCleanup decision
SalesCRM follow-up assistantMay overlap with email follow-up automationFounderKeep one CRM-owned workflow and retire duplicate email-only drafts
SupportHelpdesk drafting assistantMay overlap with chatbot, FAQ generator, or inbox assistantSupport leadKeep draft-only helpdesk agent until quality and escalation are measured
OperationsReporting assistantMay overlap with client-reporting scripts or BI exportsOps leadCreate one registry entry and require teams to discover-before-they-build

AI coding agent rollout and code provenance

ControlWhy it mattersEvidence to keep
AI-generated code labelTeams need to distinguish AI-generated code from human-written code during incidents and auditsPR tag, commit note, or review checklist field
Intent and ownerEvery AI-generated change needs a stated purpose and a human accountable in productionIssue link, owner, expected behavior, rollback note
Review bottleneckAI coding shifts work from writing code to reviewing and validating itReviewer approval, test result, risk class, merge decision
Toolchain traceabilityFragmented coding tools make code origin and policy enforcement harderAgent/tool name, prompt or task summary, generated diff, validation result

Main risks

Required controls before expansion

Pre-action approval map

ActionRiskApproval ruleFallback
Send client emailMediumOwner approves final text before sendSave as draft and notify owner
Publish CMS or helpdesk contentHighEditor approval plus source checkKeep draft unpublished
Update CRM deal stageMediumOwner approves when value or next step changesAdd note only
Trigger invoice, refund, or payment requestHighFounder approval and finance evidence requiredCreate finance task
Revoke agent accessHighOwner confirms incident or expiry and logs affected systemsDisable tokens, OAuth grants, and scheduled jobs

AI guardrails to add

30-day implementation plan

Week 1

Week 2

Week 3

Week 4

Upsell offer

Recommended next step: a fixed-price implementation sprint to remove waste, build the first automation, and add guardrails.