For IT, security and MSP teams

Your AI policy.
Put it to the test.

Six synthetic scenarios. Twelve evidence checks. Rehearse where your policy should apply, then assign each evidence gap.

Start the crash test ↓
The evidence path
Account + device + routeExpected controlObserved evidenceor a named gap to investigate

A worksheet for your team. No scan, security rating or infrastructure validation.

Run a useful team exercise.

01 · Agree the expectation

Use your own approved policy. An allowed action in one account may be prohibited in another.

02 · Record the observation

Start with a tabletop discussion. Only record Pass or Fail after an authorized check with synthetic data.

03 · Assign the evidence gap

Download the full worksheet. Give unresolved checks an owner and a review date.

Keep this safe. Do not enter secrets, personal data, real customer files or account details. This worksheet makes no requests to AI services, accepts no uploads and uses no accounts. Separately authorized checks must stay within your approved test scope.

Everything stays in this tab. Refreshing clears your entries. Export before closing; the downloaded file contains the notes you enter.

AI Policy Crash Test

Which controls can you actually evidence?

All six scenarios are synthetic. Define your policy expectation, then record what you observed for the exact environment.

Pass: expected result observed in the recorded, authorized test scopeFail: expected control not observedUntested / unknown: evidence missingUnsupported: documented coverage exclusion

Your evidence checklist

These are your recorded statuses, not a security score or independently verified results. A pass applies only to the scope and observation you recorded.

    What this worksheet cannot establish

    No infrastructure is inspected. We do not verify your observations, provider retention, policy enforcement, identity attribution or Aona coverage. A browser result does not prove desktop or mobile protection. Passing one input does not prove all file types or obfuscated content are covered. Human output review remains a separate responsibility. Re-check after account, browser, agent, policy or vendor changes.

    Optional next step · Sponsored by Aona

    Bring one evidence gap to a 30-minute demo.

    Discuss your AI-use context with Aona and see relevant discovery, policy and sensitive-data controls. Ask which tools, accounts and input paths are supported, and agree what still needs a scoped validation.

    Open Aona’s demo booking page ↗

    This opens the existing Aona website only when you click. Worksheet answers are not attached. No form is submitted here. The meeting is a product demo, not a security audit or a certification of these checks.