Validator Expert
Current State
!gcloud config get-value project 2>/dev/null || echo 'no active project'
!gcloud auth list --filter=status:ACTIVE --format="value(account)" 2>/dev/null || echo 'not authenticated'
Overview
Validate production readiness of Vertex AI Agent Engine deployments by executing weighted checks across five categories: security (30 points), monitoring (20 points), performance (25 points), compliance (15 points), and best practices (10 points). This skill produces a 0-100% composite score with pass/fail per check and prioritized remediation recommendations.
Prerequisites
gcloud CLI authenticated with roles/aiplatform.viewer, roles/iam.securityReviewer, and roles/monitoring.viewer
- Access to the target Google Cloud project and Vertex AI Agent Engine deployment
- Cloud Monitoring API and Cloud Logging API enabled in the project
- Knowledge of the deployment's expected SLOs (latency targets, error rate thresholds)
- Read-only access to IAM policies, VPC-SC configurations, and service account bindings
Instructions
- Retrieve the deployment configuration using the Python SDK (
vertexai.Client().agent_engines.get(name)) or REST API (GET https://{LOCATION}-aiplatform.googleapis.com/v1/projects/{PROJECT}/locations/{LOCATION}/reasoningEngines/{ID}) and parse model, scaling, and feature settings
- Run the security validation suite (see security checklist):
- Check if Agent Identity is enabled (recommended over service accounts for 2025+ deployments)
- If using service accounts, verify IAM roles follow least-privilege (
roles/aiplatform.expressUser, not roles/aiplatform.admin)
- Confirm VPC Service Controls perimeter is active and correctly scoped
- Check encryption at rest (CMEK or Google-managed) and in-transit (TLS 1.3)
- Scan configuration files and environment variables for hardcoded secrets
- Validate Model Armor is enabled with
roles/modelarmor.user granted
- Check Memory Bank IAM Conditions for multi-tenant agents
- Run the monitoring validation suite:
- Verify Cloud Monitoring dashboards exist with required panels (request count, error rate, latency)
- Confirm alerting policies cover error rate spikes, latency SLO breaches, and cost thresholds
- Check token usage tracking is enabled with per-model granularity
- Validate structured logging with severity levels and correlation IDs
- Confirm latency SLOs are defined with p95 and p99 targets
- Run the performance validation suite:
- Verify auto-scaling is configured with appropriate min/max instance counts
- Check resource limits (CPU, memory) match expected workload profile
- Confirm caching strategy is implemented for repeated prompts or embeddings
- Validate Code Execution Sandbox TTL is set between 7-14 days
- Check Memory Bank retention policy (min 100 memories, auto-cleanup enabled)
- Run the compliance validation suite:
- Confirm audit logging is enabled for all admin and data access operations
- Verify data residency meets regional requirements
- Check privacy policies and data retention schedules
- Validate backup and disaster recovery configuration
- Calculate weighted scores per category and compute the overall production readiness percentage
- Generate a prioritized recommendation list sorted by score impact per remediation effort
Output
- Production readiness score: 0-100% with status (READY >= 85%, NEEDS WORK 70-84%, NOT READY < 70%)
- Per-category breakdown: security (x/30), monitoring (x/20), performance (x/25), compliance (x/15), best practices (x/10)
- Pass/fail table for each individual check with evidence notes
- Prioritized remediation plan: action items ranked by score improvement per effort
- Comparison to previous validation run (if available) showing score delta
Error Handling
| Error |
Cause |
Solution |
| Insufficient IAM permissions |
Viewer roles not granted on target project |
Request roles/aiplatform.viewer and roles/iam.securityReviewer from project admin |
| Agent deployment not found |
Incorrect agent ID or deployment deleted |
Verify agent ID with vertexai.Client().agent_engines.list() or REST GET .../reasoningEngines; confirm deployment region |
| Monitoring API returns no data |
API not enabled or agent has zero traffic |
Enable Monitoring API; generate synthetic traffic to populate baseline metrics |
| VPC-SC configuration inaccessible |
Organization policy restricts VPC-SC reads |
Request roles/accesscontextmanager.policyReader at organization level |
| Compliance check inconclusive |
Audit logs not enabled or retention too short |
Enable Data Access audit logs; set log retention to minimum 365 days |
Examples
Scenario 1: Pre-Launch Validation -- Validate a new ADK agent before production launch. Run all five validation categories. Target score: 85%+ overall, with security score at 28/30 minimum. Generate remediation plan for any failing checks.
Scenario 2: Post-Incident Security Audit -- After a permission escalation incident, re-validate security posture. Focus on IAM least-privilege, service account bindings, and VPC-SC perimeter integrity. Compare scores against the last passing validation.
Scenario 3: Quarterly Compliance Review -- Execute compliance and monitoring validation suites for SOC 2 audit preparation. Verify audit logging coverage, data residency compliance, and backup/DR configuration. Export results as evidence artifacts.
Resources
Validation checklists (read the relevant one during each validation step):
- Security checklist — IAM, VPC-SC, encryption, Model Armor (30% weight)
- Monitoring checklist — dashboards, alerts, SLOs, logging (20% weight)
- Performance & compliance checklist — auto-scaling, caching, audit logs, DR (40% weight)
Official Google Cloud documentation:
1---2name: validator-expert3description: Validate production readiness of Vertex AI Agent Engine deployments across security, monitoring, performance, compliance, and best practices. Generates weighted scores (0-100%) with actionable remediation plans. Use when asked to validate a deployment, run a production readiness check, audit security posture, or verify compliance for Vertex AI agents. Trigger with "validate deployment", "production readiness", "security audit", "compliance check", "is this agent ready for prod", "check my ADK agent", "review before deploy", or "production readiness check". Make sure to use this skill whenever validating ADK agents for Agent Engine.4license: MIT5---6# Validator Expert
7
8## Current State
9
10!`gcloud config get-value project 2>/dev/null || echo 'no active project'`
11!`gcloud auth list --filter=status:ACTIVE --format="value(account)" 2>/dev/null || echo 'not authenticated'`
12
13## Overview
14
15Validate production readiness of Vertex AI Agent Engine deployments by executing weighted checks across five categories: security (30 points), monitoring (20 points), performance (25 points), compliance (15 points), and best practices (10 points). This skill produces a 0-100% composite score with pass/fail per check and prioritized remediation recommendations.
16
17## Prerequisites
18
19- `gcloud` CLI authenticated with `roles/aiplatform.viewer`, `roles/iam.securityReviewer`, and `roles/monitoring.viewer`
20- Access to the target Google Cloud project and Vertex AI Agent Engine deployment
21- Cloud Monitoring API and Cloud Logging API enabled in the project
22- Knowledge of the deployment's expected SLOs (latency targets, error rate thresholds)
23- Read-only access to IAM policies, VPC-SC configurations, and service account bindings
24
25## Instructions
26
271. Retrieve the deployment configuration using the Python SDK (`vertexai.Client().agent_engines.get(name)`) or REST API (`GET https://{LOCATION}-aiplatform.googleapis.com/v1/projects/{PROJECT}/locations/{LOCATION}/reasoningEngines/{ID}`) and parse model, scaling, and feature settings
282. Run the security validation suite (see [security checklist](references/security-checklist.md)):
29 - Check if Agent Identity is enabled (recommended over service accounts for 2025+ deployments)
30 - If using service accounts, verify IAM roles follow least-privilege (`roles/aiplatform.expressUser`, not `roles/aiplatform.admin`)
31 - Confirm VPC Service Controls perimeter is active and correctly scoped
32 - Check encryption at rest (CMEK or Google-managed) and in-transit (TLS 1.3)
33 - Scan configuration files and environment variables for hardcoded secrets
34 - Validate Model Armor is enabled with `roles/modelarmor.user` granted
35 - Check Memory Bank IAM Conditions for multi-tenant agents
363. Run the monitoring validation suite:
37 - Verify Cloud Monitoring dashboards exist with required panels (request count, error rate, latency)
38 - Confirm alerting policies cover error rate spikes, latency SLO breaches, and cost thresholds
39 - Check token usage tracking is enabled with per-model granularity
40 - Validate structured logging with severity levels and correlation IDs
41 - Confirm latency SLOs are defined with p95 and p99 targets
424. Run the performance validation suite:
43 - Verify auto-scaling is configured with appropriate min/max instance counts
44 - Check resource limits (CPU, memory) match expected workload profile
45 - Confirm caching strategy is implemented for repeated prompts or embeddings
46 - Validate Code Execution Sandbox TTL is set between 7-14 days
47 - Check Memory Bank retention policy (min 100 memories, auto-cleanup enabled)
485. Run the compliance validation suite:
49 - Confirm audit logging is enabled for all admin and data access operations
50 - Verify data residency meets regional requirements
51 - Check privacy policies and data retention schedules
52 - Validate backup and disaster recovery configuration
536. Calculate weighted scores per category and compute the overall production readiness percentage
547. Generate a prioritized recommendation list sorted by score impact per remediation effort
55
56## Output
57
58- Production readiness score: 0-100% with status (READY >= 85%, NEEDS WORK 70-84%, NOT READY < 70%)
59- Per-category breakdown: security (x/30), monitoring (x/20), performance (x/25), compliance (x/15), best practices (x/10)
60- Pass/fail table for each individual check with evidence notes
61- Prioritized remediation plan: action items ranked by score improvement per effort
62- Comparison to previous validation run (if available) showing score delta
63
64## Error Handling
65
66| Error | Cause | Solution |
67|-------|-------|----------|
68| Insufficient IAM permissions | Viewer roles not granted on target project | Request `roles/aiplatform.viewer` and `roles/iam.securityReviewer` from project admin |
69| Agent deployment not found | Incorrect agent ID or deployment deleted | Verify agent ID with `vertexai.Client().agent_engines.list()` or REST `GET .../reasoningEngines`; confirm deployment region |
70| Monitoring API returns no data | API not enabled or agent has zero traffic | Enable Monitoring API; generate synthetic traffic to populate baseline metrics |
71| VPC-SC configuration inaccessible | Organization policy restricts VPC-SC reads | Request `roles/accesscontextmanager.policyReader` at organization level |
72| Compliance check inconclusive | Audit logs not enabled or retention too short | Enable Data Access audit logs; set log retention to minimum 365 days |
73
74## Examples
75
76**Scenario 1: Pre-Launch Validation** -- Validate a new ADK agent before production launch. Run all five validation categories. Target score: 85%+ overall, with security score at 28/30 minimum. Generate remediation plan for any failing checks.
77
78**Scenario 2: Post-Incident Security Audit** -- After a permission escalation incident, re-validate security posture. Focus on IAM least-privilege, service account bindings, and VPC-SC perimeter integrity. Compare scores against the last passing validation.
79
80**Scenario 3: Quarterly Compliance Review** -- Execute compliance and monitoring validation suites for SOC 2 audit preparation. Verify audit logging coverage, data residency compliance, and backup/DR configuration. Export results as evidence artifacts.
81
82## Resources
83
84**Validation checklists** (read the relevant one during each validation step):
85
86- [Security checklist](references/security-checklist.md) — IAM, VPC-SC, encryption, Model Armor (30% weight)
87- [Monitoring checklist](references/monitoring-checklist.md) — dashboards, alerts, SLOs, logging (20% weight)
88- [Performance & compliance checklist](references/performance-compliance-checklist.md) — auto-scaling, caching, audit logs, DR (40% weight)
89
90**Official Google Cloud documentation:**
91
92- Vertex AI Security Best Practices
93- [Cloud Monitoring Alerting](https://cloud.google.com/monitoring/alerts)
94- [VPC Service Controls](https://cloud.google.com/vpc-service-controls/docs)
95- Model Armor
96- [Cloud Audit Logs](https://cloud.google.com/logging/docs/audit)