Observed arrival · 2026-10-06
Scopehaven tests what AI agents can actually access
A permission-testing service for AI apps and agents that checks data access and tool actions, records evidence, and reruns checks after fixes.
○Open
⊠Login
$Paid
†Ads
✦Pretty
●Pro
◎Niche
◉Human
⚑Risk
ƒJS
- For
- Teams testing permissions in AI apps and agents
- Worth noticing
- Its demo suite maps checks to OWASP and CWE identifiers, while stating those mappings do not imply equivalence or coverage.
Field notes
Teams write down the user, data or tool, and action that should be allowed or blocked; Scopehaven says it runs both positive and negative checks, saves evidence, then reruns the same checks on a patched build. The homepage’s pilot figure—two failures in 14 cases—comes from an internal pilot with synthetic data. Its demo suite maps checks to OWASP and CWE identifiers, while explicitly disclaiming equivalence or coverage.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
○OpenPublic substance visible
⊠LoginAccess appeared gated
✦PrettyNotable craft visible
●ProPolished or operationally mature
◎NicheUnusually specific use
One card from the complete issue