Name the owner and the job
Record each agent, its purpose, identity, tools, data access, and accountable owner. Include agents supplied by vendors.
What can an agent do, and who gave it permission?
Give a digital assistant a job badge with access to specific rooms. Check what it does inside them, too.
An agent can mistake a hostile document for an instruction and use its permitted tools in a harmful way. Excessive access can make the damage worse.
Record each agent, its purpose, identity, tools, data access, and accountable owner. Include agents supplied by vendors.
Restrict tools, destinations, credentials, and permissions to the task. Treat instructions found in documents or websites as untrusted input.
Require approval for high-impact actions. Record tool calls and outcomes. Test whether revoking access actually stops a running agent.
AI platform + application owners + security
WHAT TO KEEP IN MINDA prompt filter or a written rule is not an access boundary. These controls apply to agents you operate or procure; they do not govern an attacker’s agents.
Names you may encounter in a buying conversation. Products often span several areas.
Every area depends on clear ownership, policy, and evidence.
See the governance foundation