# The vendor question card

**Ships with:** The Assurance Line.
**Who this is for:** whoever sits on the buying side of an agent platform evaluation. Procurement,
architecture review, and the person who will own the thing after the deal closes.
**Who this is not for:** using as a gotcha. See the note at the end — it matters.
**Format:** one page. Print it, take it into the room.

---

## The question

> **"Pick a Tuesday. Last Tuesday.**
> **Show me one action your agent took that day — and everything you would hand a regulator who asked
> why it was allowed."**

Then stop talking.

**Say it exactly this way each time.** The value is not that the question is clever; it is that asking
it identically makes the answers comparable across vendors, and the comparison is the finding.

**Two clarifications to have ready**, because you will be asked for them:

- *"Not the dashboard, and not the architecture. One action, and its authority record."*
- *"A real day, not a demo tenant."*

---

## The four answers, and what each one tells you

### ① The demo that answers a different question

They show you the observability product. Traces, spans, a timeline of what the agent did, possibly
very good.

**What it tells you:** they have *telemetry* and are treating it as *evidence*. These are not the same
artifact. Telemetry records what happened. An authority record states what was permitted and by whom —
and it has to exist at the moment of the action, not be reconstructed from logs afterward.

**The follow-up:** *"Does any line in that trace say what the human agreed to, or only what the system
did afterward?"*

---

### ② The architecture diagram offered instead of a record

They explain the design. Roles, policies, a permissions model, possibly a well-built one.

**What it tells you:** the control exists in the design. Whether it produced a record for that specific
Tuesday is a separate and unanswered question. Design is a claim about the general case; you asked for
one instance.

**The follow-up:** *"I believe the design. I'm asking what it emitted on Tuesday. Can you retrieve it?"*

---

### ③ The honest "we'd have to build that"

They say the record does not exist in the form you are asking for.

**What it tells you:** more than the other three, and it is the best answer on this list that is not ④.
You now know the true state, you know it before signing, and you are talking to someone who will tell
you an inconvenient thing. **Treat this as a positive signal about the relationship**, and move
immediately to what it would take and who owns it.

**The follow-up:** *"What would it take, on your side and mine, and would it be in the product or in
my integration?"*

---

### ④ They hand you the record

Rare. It happens.

**What it tells you:** the product was built to be examined, which is a deliberate and expensive
choice somebody made early. Now read what they gave you — score it with the **approval-record scoring
worksheet** in the approval-record scoring worksheet. A record that exists can still fail to name a principal, an action, a
boundary, or an expiry.

**The follow-up:** run the four questions on it, in the room, while you have their attention.

---

## The four follow-ups, in order

Whatever the first answer, these are the same every time and they escalate cleanly:

1. **"Who is the agent, to the system, at the moment it acts?"**
   Looking for a principal — not an account, not a role.
2. **"What were the edges of what was approved?"**
   Looking for a stated boundary, not the presence of assent.
3. **"If I revoked it right now, what still lands?"**
   Looking for whether anyone has measured it. "Immediately" means nobody has.
4. **"Could you answer question one about a call from six months ago?"**
   Looking for retention that survives credential rotation.

---

## The scoring sheet

| Vendor | Answer type ①②③④ | Principal named? | Boundary stated? | Revocation measured? | 6-month retention? |
|---|---|---|---|---|---|
| | | | | | |
| | | | | | |
| | | | | | |

---

## ⚠️ How not to use this

**This is not a gotcha, and using it as one will cost you the information you came for.**

A vendor who cannot answer is not necessarily selling you something bad. They may be selling you
something that was never built to be examined — which is a fact about the product, and a legitimate
one to weigh, and **not a verdict on the company or the people in the room.** Most of them are
describing a product decision they did not make.

Say so, out loud, when you ask. You will get better answers, and the honest ③ — which is the answer
you most want to hear — only comes from someone who does not think they are being trapped.

**And ask it of yourself first.** Every question on this card applies to systems you have already
built. If your own answer is ② the vendor's ② is not disqualifying, it is the industry.

---

*Vikram Jha · The Assurance Line · vikramjha.work*
*Free to use, copy, and adapt. No attribution required, nothing gated.*
