Read the acceptance channels back to the tier they imply, hold the evidence and its currency behind each requirement, and put the open gaps in front of the officer before they sign.
2Evidence gatheredRequirement evidence, scans, tests, third-party AOCs and the rationale behind each entry
3Pack draftedTier position, per-requirement evidence, open gaps and confidence
4Controls appliedEvidence-binding checks, eligibility-criterion checks, currency checks and confidence threshold
No human action required
Stages 1 to 4 run unaided, and nothing is attested at any of them — the agent is assembling, and the officer's lane opens at the confidence gate.
5DecisionBranches at the confidence threshold
High confidence
Goes to the executive officer to review.
Low confidence
Adds a QSA read first.
Officer approval
The pack is held with its open gaps, its evidence dates and the confidence.
Approve · Amend · Send to QSA
Approved — released to sign▼
6Compliance records updatedOnly where write access and approval policy allow it
7Outcome evaluatedEvidence coverage, gaps closed, acquirer acceptance and post-submission queries
Amendments
Officer amendments are counted in the evaluation.
What should not run autonomously
Human approval stays in control
Outside the boundary — human approval required8 items
Signing the attestation of compliance.
Determining that the entity is compliant.
Confirming the cardholder data environment scope.
Deciding which questionnaire the merchant may use.
Automation boundaryAgent acts unaided
✓Map acceptance channels to the criteria each questionnaire sets.
✓Carry each requirement with the evidence and date behind it.
✓Track scan, penetration-test and third-party AOC currency.
✓Report the requirements still open, and what each one is still missing.
The officer signs. After a breach, Washington's shield needs an assessment under a year old.
Marking a requirement not applicable.
Accepting a compensating control as adequate.
Submitting the pack to the acquirer.
Changes to tier, scope or approval rules.
Example output
One requirement, annotated
What the agent records is attached to the evidence it came from.
Attestation output · single requirementIllustrative example
Requirement
What the evidence shows
Currency
Source on file
Confidence
Disposition
PCI DSS v4.0.1 · 11.3.2
Quarterly ASV scan passing; the failing scan it replaced and the rescan are both on file
Within the quarter
ASV scan report
88%
Held for the executive officer
As receivedTaken from the scan reports and the change record as filed — nothing on this side is asserted by the agent.
Evidence usedASV scan reportRescan and remediationChange-record entry
Why this is heldThe officer is promising controls will be maintained, not only that they were.
ActionApproveAmendSend to QSA
What the score decidesBelow the configured threshold the pack adds a QSA read before it reaches the officer.
Value
Where AI adds value
The same four claims, placed at the point in the workflow where each one applies.
Where the value landsValue 01 – 04
Every acceptance channelFrom the payment stack
03Assembly
Build the pack from the evidence
Draw on the scans, tests, AOCs and change records on file. The Council's note of 30 January 2025 replaced SAQ A Requirements 6.4.3, 11.6.1 and 12.3.1 with an eligibility criterion, in force 31 March 2025.
01Approved path
The tier is a consequence
Which questionnaire you may use follows from how the channels actually accept cards, and that criterion is met only by an implementation record or a written processor confirmation covering the solution as deployed.
02Human review
Not the transaction, the environment
The payment-fraud agent scores one transaction and leaves declines above the threshold to the fraud analyst. This one works an annual attestation about an environment, and a checkout change is a scope event it has to be told about.
04Build an evidence trail
The channel, the requirement it pulls in and the officer who signed stay on the attestation.
Integrations
Typical integrations
Five system groups connect to the same agent. Which of them are in scope is decided in discovery.
Gateways and processorsStripe · Adyen Worldpay · Checkout.com
Commerce and checkoutShopify · BigCommerce Salesforce · custom checkout
Scanning and testingQualys · Tenable ASV portals · test reports
Agent
PCI attestation evidence
Reads the channels Assembles the pack Holds for the officer
Evidence and GRC storesVanta · Drata ServiceNow · Jira
The estate reads clean until you split it by channel
An estate-level scope-boundary figure can look settled while one acceptance channel holds most of the unevidenced requirements. Nestack reports the gap rate by channel, not only in total.
Slice performance — reported separately, not only in aggregateIllustrative example
Slice
Failure rate
Lift
Lift vs. threshold
Status
Embedded iframe checkout
6.6%
3.7×
Review
Acquired-brand checkouts
4.8%
2.7×
Review
Mail order and telephone order
3.0%
1.7×
Watch
Fully outsourced storefronts
1.5%
0.8×
Normal
Bar: unevidenced-requirement lift vs. fully-outsourced baseline · scale 0–4.0× · tick marks the 2.0× review threshold2 of 4 slices over threshold
Evidence-linked improvement
A cycle is not closed until it is a test
A cycle closes when the wrong tier is a regression case. That suite is what the next attestation packed is measured against.
Improvement cycle · five stagesSwitchback — the path turns at Improve and returns at Learn
01Detect
The unevidenced-requirement rate rises in one channel.
02Diagnose
The one page that stopped being an iframe in a sprint nobody logged is read back through its change record until the cause narrows to one.
03Improve
The change goes out with a number, and the channels behind it travel with it.
04Verify
Nothing signs while one touched channel case is still red.
05Learn
It is kept for good, and the eligibility rules are amended in the same commit.
Learn → DetectThe return edge. The next detection runs against a suite this one made longer.
Typical build scope
Twelve workstreams across six weeks
The build scope read against the delivery timeline. Week structure follows the six-week plan — discovery, sources, pack assembly, evaluation, integration, then production validation and handover.
WorkstreamWeek 1Week 2Week 3Week 4Week 5Week 6
01Attestation scope discovery and boundary definition.
02Payment-stack and evidence-source review.
03Tier eligibility and scope-boundary rule mapping.
04Channel inventory and evidence intake.
05Pack assembly and evidence binding.
06Confidence scoring and open-gap routing.
07Officer approval workflow.
08GRC and scan-portal integration.
09Eligibility and scope cases.
10Guardrails and attestation controls.
11Channel-trail instrumentation.
12Deployment, documentation and Agent Care handover.
12 workstreams · 6 weeks · bar shows the weeks a workstream is active — several run in parallelFinal scope and sequence confirmed in discovery
Engagement tiers
What each tier includes
Rows are the capabilities named in each tier's scope. Higher tiers include everything below them.
Capability✓ in scope · — not at this tierPilotOne channel, one entityProductionProduction evidence systemsAdvancedMultiple entities / brands
Introduced at Pilot
Assembly to your channels and rules✓✓✓
Officer approval✓✓✓
Scope-boundary baseline✓✓✓
Introduced at Production
Reporting by channel—✓✓
Approval workflow in your systems—✓✓
Approved write-back—✓✓
Payment-stack integration—✓✓
Introduced at Advanced
Multi-questionnaire tier rules——✓
Multi-stage attestation approvals——✓
High channel count——✓
Multi-entity attestation controls——✓
Build priceFrom $5,000From $8,000Custom quote
Final build priceConfirmed after discovery based on integrations, workflow complexity, transaction volume, approval controls and deployment requirements.
Separate from buildBuild pricing is separate from recurring Agent Care, which covers managed monitoring, evaluations, incidents and verified improvements after launch.
What we need from you
What you bring, and what we build with it
Each input maps to a piece of build scope and a week in the delivery timeline.
You bringWe build with it
01Your acceptance channels and payment stack→Channel inventory and evidence-record intakeWeek 1
02Representative evidence from last year→Coverage baseline, evidence binding and gap handlingWeek 2
03Your tier, scope and eligibility rules→Tier eligibility and scope-boundary rule mappingWeek 1
04Access to relevant APIs, feeds or exports→Payment-stack and evidence-source review, then integration setupWeek 2
05Attestations you would not want tested→Tier-eligibility cases and failure testingWeek 4
06What no attestation may promise→Confidence scoring, gap routing, guardrails and approval controlsWeek 3
07A named executive officer to review packs→Officer approval workflow, then pilot and production validationWeeks 5–6
Nothing else is requiredDeployment, documentation and Agent Care handover are ours.
Delivery timeline
Four phases across six weeks
The plan runs on the weeks that were genuinely worked, so the pair sitting in week five is honest.
PhaseW1W2W3W4W5W6
DiscoveryW1
BuildW2 – W3
EvaluateW4 – W5
Pilot & LaunchW5 – W6
Week focusW1Attestation scope discovery, tier mapping and the automation boundaryW2Payment-stack integration and the evidence baselineW3Pack assembly, currency logic and approval controlsW4Evaluation suite, gap handling and failure-mode testingW5GRC integration, pilot requirements and targeted correctionsW6One attestation year run under the executive signer, then Agent Care handover
Reading the bandEach bar spans the weeks its own work is named in, and no more. The week 5 overlap is real.
At the end of W6Validation closes on live channels, and Agent Care picks up monitoring.
DurationSix-week plan shown · typical delivery 4–6 weeks depending on scope confirmed in discovery.
Next step · Retail AI agent
Build an attestation-evidence agent around the pack your officer signs.
It does not attest, determine compliance or confirm your scope, and Minnesota is not the PCI state it is widely called — § 325E.64 bans retained security codes and mandates no standard. Show us your channels and who signs, and we hand your officer the gaps.