Governance
The Governance workspace contains controls that shape how agents operate. Depending on your deployment and role, it includes protection profiles, execution controls, exceptions, and attestation records.
Safe operating pattern
- Start with the smallest practical scope: one agent or a non-production group.
- Review the control's intended behavior and any warnings before enabling enforcement.
- Use exceptions only when they have a clear owner, reason, and bounded duration.
- Monitor the matching activity, sessions, and alerts after each expansion.
- Retain evidence for audits and post-change review.
Use a policy when you need a reusable runtime rule. Use an exception when an approved, time-bounded deviation is necessary. Avoid using exceptions as a permanent replacement for a correctly scoped policy.
Governance workflows
| Surface | Use it to | Evidence to review |
|---|---|---|
| Protection profiles | Set guardrails for a selected agent population. | Scope, response mode, validation warnings, and linked policies. |
| Execution | Review execution controls and their affected agents. | Assignment scope, sessions, and policy decisions. |
| Approvals | Review and act on requests that require an authorized operator. | Request owner, rationale, expiry, and audit history. |
| Attestation | Inspect attestation claims and their status. | Claim issuer, expiry, and agent identity. |
| Canary tokens and detection | Review detection signals and contained activity. | Detector evidence, related session, and response action. |
| Config drift and rollout | Compare expected controls with observed state before promotion. | Differences, selected agents, rollout stage, and validation output. |
| Playbooks and directives | Define bounded operator responses. | Trigger scope, approval state, and resulting audit event. |
Before a change
Confirm that you have an Admin or Security Analyst role, the tenant is correct, and the selected agents match the intended blast radius. Make the smallest scope change first. After saving, inspect the resulting policy or governance record, then monitor Activity, Sessions, and Alerts for unexpected outcomes. Use the audit history to retain the actor, timestamp, and reason.
See Author and roll out a policy for rollout guidance and Policies overview for enforcement concepts.