Per-origin authorization
Host access is requested for a site only after the user authorizes that origin. Grants and optional permissions can be revoked.
Agent Guard combines explicit site authorization, intent contracts, policy evaluation, approval gates, risk budgets, minimized audit records, and coverage reporting. It does not claim to mediate every browser or server channel.
Host access is requested for a site only after the user authorizes that origin. Grants and optional permissions can be revoked.
Supported actions are compared with explicit sites, destinations, data categories, action types, expiry, budgets, and fresh-user-presence requirements.
Guardable high-risk commits can be paused for a summary, intent mismatch, prompt-risk association, coverage warning, and narrow approval scope.
Persistent records use minimized labels, categories, redacted URLs, amount buckets, decisions, and chained event hashes—not raw form contents.
Enterprise deployments can use chrome.storage.managed policy and signed imported policy packs, subject to administrator governance.
Guard Health distinguishes guarded, observed-only, and unsupported channels and includes a no-network self-test.
Agent Guard can associate bounded prompt-risk signals with later supported actions, but it does not claim causation or complete detection.
Policy can classify categories and govern supported destinations; unsupported or server-side channels remain outside coverage.
Intent contracts, profiles, rules, risk budgets, and approvals constrain supported browser-visible actions.
Page-world evidence is untrusted. The service worker revalidates schemas, rate-limits input, and binds decisions to Chrome sender identity.
Chained SHA-256 event hashes can reveal local audit alteration but do not replace an external trusted timestamp or enterprise SIEM.
Panic Lock can expire grants, cancel approvals, and block guardable high-risk actions; it cannot stop unsupported browser or server channels.
Report product-specific vulnerabilities to [email protected]. Include the Agent Guard version, authorized test origin, Guard Health state, safe reproduction steps, expected policy outcome, actual outcome, and minimized evidence. Never include real credentials, messages, payment details, or third-party data.
Contact security