Appendix A · Research instrument v0.1
Prove Gap Report Survey
52 fields · 12-14 minutes · Target n 150-300 · Typeform / Qualtrics build
Full quantitative instrument for The Prove Gap Report (Q3 2026).
Section 5 (S5A-S5H) matches the public PMM self-assessment widget .
Field IDs are export column headers for analysis.
Consent block (welcome screen):
This survey supports the Aevesa-sponsored Prove Gap Report. Responses are used in aggregate and may be quoted anonymously.
Not legal advice; no EU AI Act conformity assessment. Aevesa is disclosed as sponsor on the published report.
Sections
S0 Screening (4)
S1 Profile (5)
S2 Agent maturity (4)
S3 Stack layers (6)
S4 Policy vs proof Likert (5)
S5 PMM core (8)
S6 Stall points (4)
S7 Evidence (3)
S8 Regulatory pressure (4)
S9 Tooling map (3)
S10 Incidents (2)
S11 HITL (3)
S12 Architecture (3)
SZ Opt-in (4)
Section 0 - Screening
Terminate if S0A = none, or unqualified role/size combo.
ID Prompt Response
S0AOrganization’s use of AI agents Chat only · Planning · Pilots w/ tools · Production w/ tools · None (terminate)
S0BYour role Security · Compliance/Legal · Platform · Audit · Procurement · Executive · Other
S0COrganization size <500 · 500-4,999 · 5,000-19,999 · 20,000+
S0DRegulated industry? Yes · No
Section 1 - Respondent profile
ID Prompt Response
S1APrimary industry Financial · Healthcare · Tech · Manufacturing · Retail · Public · Services · Other
S1BHQ region NA · EU/UK · APAC · MEA · LATAM
S1CDeployment contexts (multi) Customer-facing · Employee · IT/ops · Dev/coding · Back-office · R&D
S1DInfluence on production decisions Final approver · Strong influencer · Contributor · Observer
S1EAgent workload count (optional) Integer or Unknown
Section 2 - Agent maturity
Feeds Chapter 1; validates 14% sign-off hypothesis via S2C.
ID Prompt Response
S2AFurthest stage any workload reached Ideation · Policy only · Non-prod pilot · Limited prod · Broad prod w/ write
S2BFormal agent inventory? No · Informal · Yes, quarterly+
S2CFull security/compliance sign-off (Likert 1-5) Validates ~14% approval stat
S2DBlocked or rolled back after pilot? No · One · Multiple · N/A
Section 3 - Stack self-assessment
Multi-select per layer. Derived: STACK_LAYER_COUNT.
ID Layer Options (multi-select)
S3ADocument Policy · Risk register · Architecture diagrams · Vendor DD · None
S3BRoute LLM gateway · API mgmt · MCP routing · Direct API only · None
S3CClassify AI-SPM · Guardrails · DLP · Classification tags · None
S3DEnforce Model guardrails · Pre-exec intercept · Policy engine · HITL gate · None
S3EProve Vendor logs · SIEM · Decision records · Tamper-evident receipts · Prove product · None
S3FVerify Security offline test · Audit offline test · Third-party portal · Runbook · None
Section 4 - Policy vs proof
Likert 1-5. Derived: CONFIDENCE_GAP = S4A minus mean(S4B,S4C,S4D). Validates 82% confidence hypothesis via S4A.
ID Statement
S4AExecutive leadership is confident our agent policies protect against harmful actions.
S4BWe can prove what each production agent did, under which policy version, at decision time.
S4CRuntime enforcement exists on high-risk tool paths before side effects.
S4DAn external reviewer could verify our agent evidence without vendor logins.
S4EOur observability stack satisfies internal audit for agent workloads.
Section 5 - PMM core
Same questions as the PMM widget . Calculates PMM_LEVEL 0-5 and PROVE_GAP flag.
ID Widget Prompt
S5Aq1 Autonomous agents at your organization (0-3)
S5Bq2 Governance documentation maturity (0-2)
S5Cq3 Route layer: traffic direction (0-2)
S5Dq4 Classify layer: inventory and protection (0-2)
S5Eq5 Runtime enforcement on high-risk paths (0-3)
S5Fq6 Proof artifacts for decisions (0-3)
S5Gq7 Offline verification without vendor login (0-2)
S5Hq8 Ongoing assurance / drift monitoring (0-2)
PMM gates: Level 4 requires S5F≥2 and S5G≥1; Level 5 requires S5F≥3, S5G≥2, S5H≥1. See outline Chapter 3 and Appendix C rubric.
Section 6 - Production stall points
Feeds Chapter 4. S6B ranks top 3 from S6A selections.
ID Prompt
S6AFactors that stalled sign-off (multi): Security · Legal · Compliance · Audit · Procurement · Budget · Integration · Alignment · No stall · Other
S6BRank top 3 stall factors
S6CLongest single review cycle: <4wk · 1-3mo · 3-6mo · 6mo+ · N/A
S6DHidden buyers drive more delays than engineering (Likert 1-5)
Section 7 - Evidence expectations
ID Prompt
S7AEvidence requested for sign-off (multi): Policy PDFs · Architecture · Pentest · SIEM · SOC2 · Screenshots · Crypto receipts · Offline demo · Third-party verifier · None
S7BEvidence rejected as insufficient
S7CCould audit re-verify a decision 90 days later?
Section 8 - Regulatory and board pressure
ID Prompt
S8APressures apply (multi): EU AI Act · US sector · UK/other · Board AI risk · Insurance · Customer clauses · None
S8BArt. 12-style logging influences architecture (Likert 1-5)
S8CArt. 14-style oversight influences approval flows (Likert 1-5)
S8DLegal asked for proof of what agent did (not just policy)
Section 9 - Tooling map
ID Prompt
S9ATool categories in stack (multi): Gateway · Guardrails · AI-SPM · GRC · Observability · SIEM · IAM · Prove layer · DIY · None
S9BWhat is missing from architecture diagram? (open, optional)
S9CPrimary governance integration: Gateway webhook · Sidecar/PEP · Post-hoc export · Manual only · Not defined
Section 10 - Incidents
ID Prompt
S10AAgent security/compliance incident in last 12 months
S10BIncident type if applicable (multi, optional)
Section 11 - Human oversight (HITL)
ID Prompt
S11AWhere human approval lives: None · Email/chat · Ticketing · Slack w/ partial log · Crypto-bound receipt
S11BCan identify approver, timestamp, policy version months later (Likert)
S11CDENY decisions recorded with same rigor as approvals
Section 12 - Architecture completeness
ID Prompt
S12AArchitecture diagram includes distinct Prove/Evidence layer?
S12BRoute + Classify alone will satisfy production sign-off (Likert)
S12CTime to add offline-verifiable proof to one prod path
Section Z - Opt-in
ID Prompt
SZ1Contact with aggregated benchmark results?
SZ2Work email (if opt-in)
SZ345-minute research interview? (optional)
SZ4Anonymous quote attribution? (optional)
Participate in the research
Survey launch Q3 2026 with waitlist first access. Try the 8-question PMM preview now, or join the report waitlist.
PMM self-assessment
Join waitlist