Agent Guard governance

Controls for review—not automatic compliance.

Agent Guard can provide local technical controls and evidence. Organizations remain responsible for model risk, authorization, legal basis, policy design, human oversight, vendor review, retention, and incident response.

本ページは製品の取り組みを説明するもので、認証や法的見解ではありません。

TopicProduct practiceEvidence and boundary
AuthorizationPer-origin grants and optional permissionsAccess is requested only for sites the user chooses to authorize.
Purpose and intentIntent contractsDefine allowed sites, actions, data categories, destinations, expiry, and budgets.
Human oversightApproval Gate and fresh-user-presence requirementsPause supported high-impact actions before commit and require explicit approval.
Data minimizationCategory-only persistent auditTransient raw values are not intentionally retained; exports use redacted metadata.
TraceabilityLocal event timeline, lineage, session diff, and hash chainingSupport review of policy input, decision, approval, action, and result.
Administrative controlManaged policy and signed policy packsAllow organizational defaults and constrained local overrides when deployed by administrators.
Fail-safe operationGuard Health, profiles, risk budgets, Panic LockExpose coverage state and provide bounded controls for supported actions.
User controlRevocable permissions, rules, history, and grantsUsers or administrators can remove access and clear local state.
Reference frameworks

How the product relates to common review questions

NIST AI RMF concepts

Intent, risk budgets, monitoring, traceability, human approval, and documented limitations can support governance workflows. Agent Guard is not NIST-certified.

ISO/IEC 42001 concepts

Local policies, responsibilities, evidence, change review, and controls may support an AI management system. Certification applies to an organization and audited management system—not this extension alone.

OWASP agentic risks

Prompt injection, excessive agency, tool misuse, sensitive-data exposure, and inadequate monitoring are relevant design concerns. Coverage depends on supported browser-visible channels.

Privacy laws

Category minimization and local storage can reduce exposure, but controllers and processors must separately determine lawful basis, notices, rights handling, retention, and vendor obligations.