Agent Guard docs

Authorize narrowly. Define intent. Review coverage.

Agent Guard is most useful when the user or administrator defines the authorized site, intended task, sensitive-data categories, destinations, budgets, and approval expectations before the agent acts.

Quick start

From installation to an explainable first review

01

Install and open

Load the controlled-release build, open a normal HTTP or HTTPS page, and click the Agent Guard toolbar icon.

02

Authorize one site

Grant access only to the current origin required for the workflow. Avoid blanket authorization.

03

Check Guard Health

Confirm which channels are guarded, observed-only, or unsupported before relying on approval or blocking.

04

Create an intent contract

Specify allowed sites, actions, categories, destinations, expiry, risk budgets, and user-presence requirements.

05

Choose a profile

Use Observe, Balanced, Strict, or a carefully reviewed Custom profile.

06

Review approvals and audit

Inspect the action summary, mismatch, prompt-risk association, coverage caveat, approval scope, decision, and result.

Core concepts

Use consistent definitions when reading the interface and evidence

Guard Health

Current coverage status for supported page actions and channels, including degraded or unsupported paths.

Intent Contract

A bounded statement of what the user wants an agent to do, where, with which data categories, destinations, limits, and expiry.

Approval Gate

A pause before a supported high-risk commit, with minimized context and narrow approval choices.

Risk Budget

Quantitative limits for sends, external destinations, recipients, uploads, purchase amounts, irreversible actions, and account changes.

Data Lineage

A category-only graph linking source origin, sensitive category, supported action, and destination origin.

Injection Trace

A time/source association between prompt-risk signals and later actions; it does not assert causation.

Session Diff

Comparison of destinations, categories, actions, prompt signals, and coverage between local sessions.

Panic Lock

An emergency action that expires grants, cancels approvals, and blocks guardable high-risk actions within supported coverage.

Need help?

Include the product name, version, Chrome version, and minimal reproduction steps when contacting support.

Assistance