Statement of Work
AI Agent Governance & Access Dashboard
Prepared by Starks Enterprise — starksenterprise.com · Irving "Gene" Starks Jr. · [email protected] · (980) 355-9706
Purpose & Overview
Starks Enterprise will build and deploy a governance dashboard that inventories Client's AI agents (copilots, internal bots, automation agents), maps their identity and access permissions, logs their actions, and flags anomalous or out-of-policy agent behavior.
Scope of Work
Discovery of all AI agents/copilots in use and their associated identities (Entra ID, service principals, API keys)
Mapping of each agent's data, system, and tool access
Deployment of an activity-logging layer for agent actions
Policy configuration for acceptable agent scope and anomaly thresholds
Governance dashboard with role-based views (security, compliance, business owners)
Alerting configuration for policy violations or anomalous agent activity
Deliverables
Agent identity and access inventory
Deployed governance dashboard
Configured anomaly-detection alerting
Agent governance policy document
Admin training session
Timeline
| Phase | Activities | Duration |
|---|---|---|
| Phase 1 | Agent & identity discovery | 1-2 weeks |
| Phase 2 | Access mapping & logging deployment | 2 weeks |
| Phase 3 | Dashboard build & policy configuration | 2 weeks |
| Phase 4 | UAT, training, go-live | 1 week |
Pricing & Payment Terms
| Item | Timing | Fee |
|---|---|---|
| Discovery, build & deployment (one-time) | Due at kickoff (50%) / go-live (50%) | $15,000 - $25,000 |
| Ongoing monitoring & dashboard hosting | Monthly, in advance | $1,000 - $2,500/mo |
| Additional agent platform integration (per platform) | One-time | $3,000 - $6,000 |
Invoices are due net 15. Monthly fee begins the month following go-live.
Client Responsibilities & Assumptions
Client will provide timely access to relevant systems, personnel, and documentation needed for discovery.
Client will designate a single point of contact for the duration of the engagement.
Cloud infrastructure costs (hosting, compute, storage) are billed separately to Client unless otherwise stated.
All work is performed remotely unless on-site work is explicitly scoped and priced separately.
Pricing assumes a single production environment and a single tenant/client instance unless stated otherwise.
Client will provide administrative access to identity provider (e.g., Entra ID) for agent discovery.
Out of Scope
Development or modification of Client's underlying AI agents themselves
Governance of agents hosted entirely outside Client's identity provider (case-by-case)
Legal or regulatory advisory on AI usage policy
Acceptance Criteria
All discovered agents represented in the governance dashboard
Logging and alerting verified against at least one test policy violation
Client sign-off on dashboard functionality and reporting
Term & Termination
This SOW is effective upon signature by both parties and remains in effect through delivery and acceptance of all deliverables, or until terminated by either party with 30 days' written notice. Fees for work performed and expenses incurred prior to termination are non-refundable. This SOW is governed by, and incorporated into, the Master Services Agreement between Starks Enterprise and Client.