Agentic Landmark · Operational instrument
The Operational Agent Readiness Index
A five-dimension scoring instrument that measures the risk an organization carries when it delegates real work to agents inside its own operations. The composite runs 0 to 100; higher means more exposure net of control. It is the supply-side twin of the Agent Readiness Index: where ARI asks whether outside agents can find and choose you, OARI asks whether inside agents can act on your systems safely. It is published here for the same reason ARI is, because a practice arguing for governed agent infrastructure should not run an opaque instrument.
Authorization Maturity
Whether the organization can express and enforce what an agent is allowed to do, per workflow, with scoped and revocable authority. Scored as a control, inversely: mature authorization lowers exposure. The strong case is authority drawn per workflow at three boundaries, what the agent may execute on its own, what needs human approval, and what must escalate, with each agent holding its own scoped and revocable credentials and authority changes made at config level and taking effect immediately. The weak case is all-or-nothing authority exercised through borrowed human or service accounts, where tightening scope after a near-miss is a code deploy rather than a setting. This is the dimension where the practice holds proof a framework-reading competitor cannot manufacture.
Blast Radius and Reversibility
How much a single wrong action costs, and whether it can be taken back. Scored as exposure, directly: a large, irreversible blast radius raises the score. The questions are the worst realistic outcome per workflow, where a wrong action is caught (before commit, after commit, or downstream next week), what can actually be rolled back, and whether per-action and cumulative ceilings force a human in before damage compounds. Recommendations that are wrong self-correct at the next query; actions that are wrong have already happened. This is the dimension with no demand-side analogue.
Operational Data Readiness
Whether the operational data an agent reads and writes is structured, current, and reconciled enough that an action taken on it is an action taken on reality. Scored as a control, inversely. This is the inward cousin of ARI's Structured Data Maturity: the same discipline pointed at ERP, WMS, OMS, and supplier and customer systems rather than at the public catalog. The weak case is the same fact conflicting across systems with no resolvable authority, data that is stale or batch-delayed, contracts that change silently, and workflows that fail open on bad input rather than halting and escalating.
Governance Maturity
Whether the organization can see, escalate, and stop agent action once it is live. Scored as a control, inversely. The strong case is escalation triggers defined in advance, a complete and tamper-evident audit trail, a named owner per agent who can intervene in real time, a tested agent-failure runbook, and reviews that can pull an agent from production. The weak case is escalation discovered only after failure, partial logs, accountability that is diffuse, a plan that is really just the general IT incident process, and set-and-forget deployment.
Workflow Suitability
Whether the workflows being delegated are genuinely agent-suitable, or whether the organization is pointing agents at judgment-heavy, high-variance work because that is where the enthusiasm is loudest. Scored as exposure, directly, as a mismatch: agents aimed at unsuitable work raise the score. The questions are the share of delegated work that is bounded and rules-expressible versus judgment-dependent, whether the acceptable-error tolerance is explicit and honest, and whether selection was driven by suitability analysis or by which demo landed best with leadership.
OARI = ((100 − AM) × 0.25) + (BR × 0.20) + ((100 − DR) × 0.20) + ((100 − GM) × 0.20) + (WS × 0.15)
All inputs score 0 to 100. The three control dimensions are inverse: a mature control lowers the composite. An Authorization Maturity of 80 contributes (100 − 80) × 0.25 = 5 points, not 20, because control that is working subtracts from exposure. The two exposure dimensions add directly. The frame is exposure net of control: what could go wrong, minus how well you have contained it.
The same subtotal logic applies here, with the proportions inverted. Blast Radius and Workflow Suitability are the operational weather: exposure set by the work an organization chose to delegate and by what a failure would cost, lowered by delegating differently rather than by governing better. They carry 35 percent. Authorization Maturity, Operational Data Readiness, and Governance Maturity are the roof, and they carry 65 percent.
That inversion is the finding. On the demand side most of a score is weather. Here most of it is roof, and a roof is built rather than inherited. Meridian, the same running brand read through the operational door, scores 62.05: 23.05 is exposure from the work it delegated and 39.00 is control it has not built yet. Nearly two thirds of the score is buildable.
The composite places an operation in one of four bands
Low
Controls match exposure. Deployments are authorized, bounded, governed, and observable. Focus: monitor, keep governance review light, and re-run the snapshot on each new deployment.
Emerging
Exposure is beginning to outrun controls in adjacent workflows. The window to formalize before scaling is open but narrowing. Focus: an authorization map on the workflows in flight, and closing the single lowest control dimension.
Significant
Controls are materially behind exposure and a failure is likely on the current trajectory. Delay compounds remediation cost. Focus: the full governance sprint, all three components, sequenced from the lowest control dimension up.
Critical
Exposure far exceeds control. Failure is imminent or already occurring. Focus: contain or halt scaling, an emergency bounded autonomy framework, and a sprint paired with a remediation retainer.
The five scored dimensions are not the whole instrument. Alongside them, the Assessment records a separate observability flag, Ready, Partial, or Blind, that asks the prior question: could you even see an agent misbehaving in production. It is never folded into the composite, because readiness to run agents safely and readiness to see what they are doing are different problems with different infrastructure. An operation can have mature authorization and still be Blind. The math above tells you what the score means; the Assessment, delivered inside the sprint, is what produces yours.
One competence, two instruments
OARI is not a second practice. It is the inward reading of the same competence. ARI scores whether an outside agent can accurately evaluate you on the way in; OARI scores whether an inside agent can safely act on your systems once you have handed it the work. The seam between them is structured data, read in two directions: ARI's Structured Data Maturity asks whether an outside agent can read you correctly, and OARI's Operational Data Readiness asks whether an inside agent can act without acting on a stale or conflicting version of the truth. Same discipline, two directions. A brand can be strong on one surface and exposed on the other, which is why the two scores do not collapse into one.
The free door-opener
Take the snapshot
Eight questions, an indicative band, and the single widest gap between your exposure and your controls. It runs in your browser, and nothing you enter is stored. It does not return a precise score, the instrument computes that, it returns where you sit and what to close first.