# 20 questions to ask an AI agent vendor before you sign

> Use these twenty questions to compare the implementation you would actually receive. Ask for evidence, identify unresolved requirements and include the people who will operate and review the workflow.

Published 2026-09-02 · Updated 2026-09-08 · Genaima AI

## Data and residency

**Questions 1–4**

| Question | Evidence to request |
| --- | --- |
| 1. Where is our information stored and processed? | A data-flow description covering files, indexes, model calls, logs and backups, with the relevant regions. |
| 2. What retention and training terms apply? | The selected services, account settings, contractual terms and any exceptions for prompts and outputs. |
| 3. Which third parties receive information? | The providers and integrations involved, the purpose of each transfer and the records included. |
| 4. Which security requirements can you demonstrate? | Evidence for your specific requirements, with a clear distinction between implemented controls and planned work. |

## Permissions and actions

**Questions 5–8**

| Question | Evidence to request |
| --- | --- |
| 5. What can the workflow read and write? | An operation list for each source and destination, including sensitive reads and downstream effects. |
| 6. How is access restricted? | The service-account scopes and how the interface prevents a user from seeing another client's or team's records. |
| 7. Can we begin with draft preparation only? | A configuration or design that allows evaluation without sending messages or changing operational records. |
| 8. Which operations can run without a new approval? | The prior authorisation, boundaries, limits and monitoring that permit each operation. |

## Approvals and audit

**Questions 9–12**

| Question | Evidence to request |
| --- | --- |
| 9. Who defines and enforces the approval policy? | The agreed authority matrix and application checks, including the response to an unauthorised reviewer. |
| 10. What exactly does a reviewer approve? | The output version, destination, relevant record state and handling of rejection or expiry. |
| 11. What happens on failure or retry? | A demonstration of duplicate prevention, partial failure handling and how an operator can stop the workflow. |
| 12. Which records can we inspect afterwards? | The source references, decisions and action results retained, their access policy and export options. |

Test the action path as well as the interface. A button labelled Approve does not establish that a tool call cannot bypass it. Include a rejected action, changed data and a duplicate request in the evaluation sample.

## Models and portability

**Questions 13–15**

| Question | Evidence to request |
| --- | --- |
| 13. Why are these models appropriate for the task? | Evaluation on representative inputs, including incorrect or unsupported outputs and the team's acceptance criteria. |
| 14. How can important output claims be checked? | The relevant source references, calculation method and behaviour when evidence is missing or contradictory. |
| 15. What happens if a provider or model changes? | The compatibility checks, regression evaluation and responsibility for adapting prompts, tools or outputs. |

Support for several models can be useful, but switching providers is not automatically free of implementation work. Ask which behaviour has been tested and what would need to be repeated after a change.

## Operation and observability

**Questions 16–18**

| Question | Evidence to request |
| --- | --- |
| 16. Who maintains the workflow and its connections? | Named responsibility for credentials, source-format changes, failed runs and escalation. |
| 17. How do we monitor usage and operating effort? | The available provider usage, service limits and human review or support effort needed to evaluate the full task. |
| 18. How will the team operate it after handover? | Run instructions, failure recovery, training and an agreed path for support. |

## Exit and portability

**Questions 19–20**

| Question | Evidence to request |
| --- | --- |
| 19. What can we retain or export at the end? | The agreed treatment of data, configuration, application code and run records, including formats and responsibilities. |
| 20. How can we stop using the workflow safely? | The process for disabling actions, revoking access, recovering pending work and handling retained copies. |

A system that uses existing records can still create dependencies through its queues, indexes and integrations. Review the practical handover rather than accepting a broad promise of no lock-in.

## How to use these questions with Genaima

Genaima is the AI autopilot for decision-dense businesses. We use the workflow discussion to identify required sources, outputs, controls and operating responsibilities. A general page cannot confirm every answer for your systems; unresolved requirements should be recorded before implementation.

The [security page](https://genaima.ai/security) describes the data and control questions we assess. [How a workflow runs](https://genaima.ai/how-it-works) explains the build and evaluation process. The [partner page](https://genaima.ai/partner) covers scope and handover. Bring a representative task so these questions can produce concrete decisions.

## Common questions

### Who should take part in the evaluation?

The workflow owner and reviewer, with IT, security, finance or other specialists where their responsibilities are involved. Their actual requirements should shape the test.

### Which answers should stop a project?

Treat an unmet mandatory requirement as a reason to stop or change the design. A missing access boundary, uncertain authority or unsupported data-handling arrangement should not be bypassed by a successful demo.

### Does the checklist apply to a chat interface?

Yes, where relevant. Read-only systems still need data and output controls; systems that can act also need authority, failure and action-record checks.

- [Launch your autopilot](https://genaima.ai/contact) — Tell us the workflow and the requirements your team needs answered before proceeding.

## Related

- [Security & governance](https://genaima.ai/security)
- [FAQ](https://genaima.ai/faq)
- [Risk-classifying AI agent actions](https://genaima.ai/insights/risk-classify-ai-agent-actions)
- [Glean alternative](https://genaima.ai/compare/glean-alternative)

---

- Canonical page: https://genaima.ai/insights/questions-to-ask-ai-agent-vendors
- More: [Home](https://genaima.ai/) · [About Genaima](https://genaima.ai/about) · [Contact Genaima](https://genaima.ai/contact) · [How a workflow runs](https://genaima.ai/how-it-works) · [The AI operating layer](https://genaima.ai/ai-operating-layer) · [Security & governance](https://genaima.ai/security) · [FAQ](https://genaima.ai/faq) · [Implementation partner](https://genaima.ai/partner) · [Solutions](https://genaima.ai/solutions) · [Industries](https://genaima.ai/industries) · [Compare](https://genaima.ai/compare) · [Insights](https://genaima.ai/insights) · [Glossary](https://genaima.ai/glossary) · [Tech stack & tools](https://genaima.ai/tech-stack) · [Resources](https://genaima.ai/resources) · [Pricing & scope](https://genaima.ai/pricing) · [Selected work](https://genaima.ai/work) · [llms.txt](https://genaima.ai/llms.txt)
- Contact: hello@genaima.ai
