Jump to the sections that matter for your role. Executive Summary remains Section 01 for leadership readers who want the verdict first.
Vertex Global has decomposed a Password Reset Agent workflow into 7 steps. 2 of 7 steps meet production-ready thresholds. Overall readiness is 51/100 (FAIR). Primary gaps are in entity resolution and source of truth, not necessarily in the AI models themselves. Overall governance risk: HIGH.
Data orchestration is the production layer between enterprise data and AI agent action.
The agent reasons. Data orchestration prepares, routes, validates, governs, and records what the agent is allowed to reason on - trusted data, approved rules, permissions, tools, approvals, logs, and rollback paths.
The agent reasons. Data orchestration prepares, routes, validates, governs, and records what the agent is allowed to reason on - trusted data, approved rules, permissions, tools, approvals, logs, and rollback paths.
Each question maps to Prepare · Route · Validate · Govern · Record - gap rows link to TC Fix playbooks; live controls via TC Fix deploy + TC Protect.
3 yes · 5 partial · 2 gap - spec in TC Diagnose; live controls via TC Fix deploy + TC Protect.
Each dimension scored 0-100 across all workflow steps. 80+ is production-ready; 70+ on audit & compliance readiness supports enterprise security reviews. Scores reflect uploaded artifacts and workflow context, platform-agnostic.
Agent risk register for Password Reset Agent. Risk rated High / Medium / Low per dimension.
Recommendations prioritized by enterprise deal impact and production readiness lift. Effort: S (1-2 weeks) / M (2-4 weeks) / L (4-8 weeks).
What work is required and which roles typically own it. If you have these skills in-house, staff it internally, every item in this report can be executed by your team. TekCapitol is optional delivery support if you want help implementing.
Effort in person-months and person-days - fixed-scope deliverables, not a fractional hire recommendation.
Each row is a scoped deliverable with role, skills, and estimated effort. Staff in-house or with TekCapitol - your choice.
Person-months of effort (1.0 ≈ 20 working days). Scoped deliverables, not a headcount or hire recommendation.
Model routing, token estimates, cost projection, and human-in-the-loop gates per workflow step. Generated from your decomposed agent workflow.
5 of 7 steps need no LLM · 2 uses LLM
Based on recommended models and token estimates at 680 runs/day. List prices only; excludes caching, batch discounts, and platform fees.
Permission audit, compliance mapping, and kill-switch authority matrix, aligned to NIST AI RMF and SP 800-53.
Data quality alerts, LLM eval criteria, circuit breakers linked to kill-switch levels, ops runbook, and KPIs.
TC360 is Diagnose · Fix · Protect. This TC Diagnose report identified production gaps; TC Fix and TC Protect are the next steps in the app - or assign the roadmap to your team.
Draft answers to the 5 most common enterprise AI security questions, based on this assessment. Review with legal before submitting to prospects.
One catalog row per assessed workflow - for your agent inventory, GRC tool, or vendor file. Included in the WGR JSON export.
| Agent name | Password Reset Agent · Vertex Global |
|---|---|
| Owner | Assign owner - see remediation roadmap |
| Business purpose | Triage password-reset and account-lockout incidents from ServiceNow, verify identity via Okta and Workday, apply risk-based policy, execute approved resets, and throttle volume when login failures spike enterprise-wide |
| Systems touched | ServiceNow, Okta, Workday, Snowflake, Splunk SIEM risk export, Custom / Proprietary |
| Data accessed | ServiceNow (read: Okta Users API read, Okta reset scoped app); Okta (read: Okta Users API read, Okta reset scoped app); Workday (read: Okta Users API read, Okta reset scoped app) |
| Tools/actions allowed | Ingest and classify reset request; Resolve user in Okta; Verify employment and account type; Load SIEM risk and login spike context; Apply reset policy and routing decision; Human gate for privileged and high-risk paths · Denied: Okta Super Admin; Bulk password reset without per-incident audit |
| Human approval points | - |
| Risk level | high |
| Go-live status | Not approved - remediate before production |
| Kill-switch owner | Security Operations Lead |
| Audit log location | TC Protect metadata audit log (when Live enabled) |
Registry v1.0 · Workflow wgr_sample_vertex-global · Updated 2026-07-07
Machine-readable governance contract for this workflow - for vendor risk, SOC 2, and internal audit file. Export Evidence Pack (HTML + WGR JSON + agent registry CSV) or Registry CSV from the report toolbar.
SOC2 · ISO 27001
Kill switch stops forward. Rollback undoes backward. Kill switch stops future runs; rollback undoes completed writes via compensating transactions.
Hybrid - ReBAC for data access + OPA/Cedar at orchestrator + TC Protect run gate · Primary engines: OpenFGA
Hybrid - ReBAC for data access + OPA/Cedar at orchestrator + TC Protect run gate. Primary: OpenFGA. Principal: hybrid. TC Diagnose specifies architecture; customer or TekCapitol deploys the PDP.