Evaluation template

AI Governance Platform —
Request for Proposal

Vendor-neutral criteria for governing AI agents, tools, models and the data they reach. Take it, strike what does not apply, and send it to every vendor on your list — including us.

Download the PDF ↓

Purpose

Use this template to evaluate a control plane for agentic AI traffic — not a proxy in front of model providers.

The questions that decide whether you can put agents into production are who authorized this call, what data did it reach, what did it cost, and can you prove it a year from now. This template puts those first and model routing where it belongs.

How to score. Ask for a live demonstration of policy enforcement, not a dashboard. A refusal you can watch — with the reason it names — is worth more than any feature matrix, including this one.

✓ SupportedShipped, in the product today
◗ PartialSome of this; the row says what is missing
🔗 IntegratesDelivered through a named third party
○ RoadmapCommitted, not shipped
— Not offeredDeliberate; the row says why

The ten categories

Fifty-five criteria across ten categories, each with a priority and an honest answer for Magertron. The full matrix is in the PDF.

1  Identity and delegation
6  Endpoint reality
2  Authorization and data reach
7  Model access and routing
3  Supply-chain integrity
8  Guardrails
4  Cost governance
9  Deployment and ownership
5  Audit and evidence
10  MCP and agent operations

Download the full template (PDF) ↓


Questions to ask every vendor, including us

Independent of the matrix. The answers are more revealing than the checkmarks.

  1. Show me a refused call. Not a dashboard — a refusal, and the reason it gives. Does it name which check failed, which principal and which rule?
  2. Show me an allow record. Then ask it to reconstruct the permissions that were in force when that call happened.
  3. An agent acts for a person. Show me both identities on the record — and what happens when the person’s permissions are narrower than the agent’s.
  4. A tool’s vendor changes its schema overnight. What happens to the next call?
  5. Where does the component that authorizes calls run, and what data leaves my perimeter?
  6. What on this sheet would you mark partial? A vendor who cannot name one is either not listening or not telling you.