Skip to content
ConsoleProcurement

Supplier Risk Agent

ATC-AGT-0004218

ProductionProduction Certified

72

high risk

Identity

Who owns it, and what it is for

Declared purpose
Analyze supplier financial risk and raise alerts for procurement managers.
Business owner
Dominique Bexley · Procurement
Technical owner
Anders Kohl · Platform Engineering
Provider and model
Anthropic · claude-sonnet-4-5
Framework
LangChain
Environment
production
Data classes reached
Internal, Confidential, Financial data
Last activity
4 minutes ago

Risk

Why the score is 72

Every point is accounted for. Remove a factor and the score moves by exactly that much.

  • +20

    Data

    Reads confidential supplier financials

  • +12

    Action

    Can create records that trigger downstream workflow

  • +10

    Tool

    Calls an external credit API

  • +12

    Dependency

    One of three MCP servers changed permissions after approval

  • +8

    External exposure

    Reaches a third-party service outside the tenant

  • +10

    Compliance

    Access review overdue by 24 days

  • 72Total

Access

What it may do, action by action

Permissions are held at the level of the action, so reading a record and changing its banking details are separate grants that can be decided separately.

  • read_supplierQeluntra
    L0 ReadGranted
  • create_supplier_alertQeluntra
    L2 Execute, low riskGranted
  • modify_supplierQeluntra
    L3 SensitiveWithheld
  • change_bank_detailsQeluntra
    L4 CriticalWithheld
  • approve_purchase_orderQeluntra
    L4 CriticalWithheld

Dependencies

MCP servers it is bound to

  • Finance MCP

    Internal · Finance Platform

    approved
    read_ledgerread_invoice
  • Credit Data MCP

    Third party · unverified

    drifted
    lookup_credit_ratingexport_report

    Added export_report after approval. Reauthorization required.

  • Microsoft MCP

    Microsoft

    approved
    search_files

Execution identity

What it authenticates as

An agent does not reach anything by itself. It runs as a machine identity, and that identity is what actually holds the credential — so the agent's permissions are only ever a subset of what this can do.

Supply chain

Bill of materials

What this agent is assembled from. It is also the answer to the blast-radius question when one of these is compromised.

Model

claude-sonnet-4-5

Framework

LangChain

Tools

Supplier lookupCredit ratingAlert publisher

MCP servers

Finance MCPCredit Data MCPMicrosoft MCP

Databases

PostgreSQL · procurement

Packages

langchainhttpxpydantic

Runtime

Decisions taken on its behalf

Every governed action produces one of these, and each records the rule that decided it.

  • 14:02:11read_suppliersupplier:48120
    Allowed

    rule: procurement.read.suppliers

  • 14:02:14lookup_credit_ratingmcp:credit-data
    Allowed

    rule: mcp.approved-tools

  • 14:02:31create_supplier_alertsupplier:48120
    Allowed

    rule: procurement.write.alerts

  • 14:07:52change_bank_detailssupplier:48120
    Denied

    rule: purpose.scope · level-4

  • 14:08:03export_reportmcp:credit-data
    Held

    rule: mcp.drift.hold

Back to the fleet · The modules behind this view