Security Review as a Service, Worked: The Audit Engagement
The security series (S7) produced the hardening knowledge; the threat-to-review bridge (BR.9) translated it into an offer. Security review as a service is the worked engagement: the client’s stack gets the same threat-modeling, hardening, and audit treatment the kingdom gives its own fleet — with the evidence layer as the deliverable. This is what a security review engagement actually looks like.
The engagement structure
The review runs in phases, each with a deliverable. Phase one, threat model: the fleet’s surface is mapped — what agents exist, what they touch, what they hold (S7.4). Phase two, assessment: the narrow gate (S7.1), the credential handling (S7.5, S7.6), the trust chain (S7.3), and the perimeter (S7.8) are tested against the documented standard. Phase three, report: the findings are scored and prioritized, with the evidence — the actual checks, the actual logs — attached (S7.15). Phase four, remediation: the fixes are implemented with the client’s operators, using the recovery runbook (S7.11) where incidents are found.
The evidence as the deliverable
The security review’s deliverable is not the opinion; it is the evidence: the audit log that shows what was checked, the receipts that show what passed, and the findings that show what failed. The client can verify the review the same way the audit layer verifies agent actions (S7.7) — the review is itself an auditable artifact. That is the difference between a security review and a security theater: the theater gives an opinion; the service gives a record.
The economics and the flywheel
The review is priced by surface area — the number of agents, tools, and endpoints assessed — and it feeds the flywheel: every review produces findings that become content (S10-19 gap list), content that attracts clients, clients that need reviews. The security review as a service is the security series’ business form — the knowledge the S7 articles published, packaged as an engagement (EX-2), metered like everything else (S6.12), and verified by the same audit discipline (S7.15).
Grounded in the EX worked-example series, the BR.9 threat-to-review bridge, the S7 security series, and the S7.15 audit-as-product article. Seventh article in the Round D examples track.

