rdlb · insights July 29, 2026 · 3 min read

Procurement stopped asking about the model.

Enterprise vendor questionnaires now carry AI sections. The answers that clear them are architectural, and you cannot retrofit them after the deal is live.

RDLB Agentic insight header — enterprise security review of an agentic system, shown as a gate emblem with a magenta threshold on an ink ground.

There is a moment in every enterprise deal where the conversation leaves the room you were selling in. The champion is convinced. The budget exists. Then the questionnaire arrives, and a security team you have never met decides whether any of it happens.

That questionnaire changed. Standard vendor risk templates now carry dedicated AI sections — model provenance, subprocessor transparency, data handling, and alignment with frameworks like ISO 42001 and the NIST AI Risk Management Framework. The questions are no longer about whether the technology is impressive. They are about whether anyone can explain what it did last Tuesday.

The questions are architectural, not cosmetic.

Three of them do most of the damage. What can this system write to. Who approved this output. Can you produce the record.

Each one is answered by a design decision made long before the deal, or it is not answered at all. Connectors that are read-only by default answer the first: the system reads from the sources it needs and holds no write credentials, so the blast radius of a bad run is a bad draft, not a corrupted record. A human approval gate answers the second: nothing reaches a customer, a channel, or a system of record without a named person releasing it. Audit-grade logs answer the third: every run, every input, every approval, retrievable months later without archaeology.

None of that is a feature you add during a review. It is the shape of the system or it is not. Teams that bolt governance on after the fact spend the review writing documentation for behavior they cannot actually constrain, which is why so many otherwise strong deals stall in weeks four through nine. Our posture page states the boundary plainly, because stating it later is worthless.

Portability is a security answer too.

The less obvious question is what happens if the model underneath changes. Providers deprecate versions. Prices move. Terms shift. A brand system welded to one vendor inherits every one of those events as an operational incident, and a reviewer who has watched that happen once will ask about it.

Model-agnostic routing turns that from a risk into a setting. The briefs, the voice rules, the memory, and the approval workflow live in your system. The model is the interchangeable part. That is also what makes no lock-in a credible claim rather than a slogan: if the work product and the operating logic are yours, leaving is a migration, not a rebuild. The system page shows where those layers sit.

Answer it before you are asked.

The practical move is to run the review on yourself first. Write down what each connector can touch. Name the human who releases each class of output. Pull a log from ninety days ago and see how long it takes to reconstruct one decision end to end. If any of those takes more than an afternoon, procurement will find the same gap, and they will find it with less patience.

This is not overhead. It is the reason a system can run at volume without the founder personally underwriting every output. Thirteen agents, more than 44,000 runs in 63 days, under fifty dollars in model spend — that throughput is only sellable because each run is constrained, approved, and recorded. Governance is what makes speed legible to a buyer. The agents page shows the roster those controls apply to.

If a review is coming and you would rather not improvise the answers, book the 30-minute strategy blueprint call.

procurement · security review · governance

A 30-minute strategy blueprint call maps where a system takes over your highest-cost work.

Book the strategy blueprint call