AgentGuard

AI agent observability + governance

Govern AI Agent Risk and Decisions

Monitor agent activity, risk signals, policy decisions, approvals, and audit evidence from one control plane built for AI agent governance.

AgentGuard control plane3 approvals
OverviewAgentsDecisionsPoliciesAudit
Agents12
Blocked08
Policyv2.4
Code review agentObservedAllowed
Support agentElevated riskReview
Web3 execution agentCritical signalDenied
Research agentObservedAllowed
Why observability matters

Turn Activity into Decisions

AI agents operate across prompts, tools, data, permissions, and external systems. Security teams need a connected record of what the agent requested, which risks were detected, how policy responded, and who approved the outcome. Monitoring provides the activity record; AgentGuard connects it to policy, approval, audit, and remediation workflows.

AgentEnvironmentLatest decisionState
Web3 executionProductionDeny / v2.4Critical
Support workflowProductionReview / v2.4Pending
Code reviewStagingAllow / v2.4Observed
Research assistantSandboxAllow / v2.3Observed
End-to-end activity

Trace Every Request

Risk signals and policy evaluation stay inside the event sequence, so the final decision retains its context.

Agent requests an action

Web3 execution agent requests contract approval through a connected tool.

Runtime Guard evaluates risk

Excessive permission and unknown destination signals match policy v2.4.

Request enters approval

The policy requires an explicit AI CISO decision before execution.

Action denied and recorded

The reviewer denies the request. Reason and evidence enter the audit timeline.

Monitoring scope

Monitor Decision Signals

AI agent monitoring joins identity, requested action, risk, and governance state around the same event.

Event context

One connected decision record

Identity

Agent identity, owner, environment, integration path, and connected systems

Action

Tool, command, file, data, network destination, permission, and affected asset

Governance

Approval status, exception, remediation owner, policy version, and verification state

Decision context

Signals that affect execution

Permissions

Requested scope and reachable systems

Risk

Detected signals, policy result, severity, reason, and enforcement outcome

Outcome

Allowed, denied, escalated, approved, or unresolved

Policy distribution

Versioned Policies

Create and distribute policy changes, show which version each environment uses, and retain the history needed to explain a decision. Each update keeps its owner, scope, version, deployment state, and effective time visible.

v2.4 / CurrentDeny-first Web3 update · 14:20 UTC
v2.3MCP permission review · Jul 29
v2.2Secret access controls · Jul 24
Production agentsv2.4Synced
Staging agentsv2.4Synced
Sandbox agentsv2.3Update
Edge connectorv2.4Synced
Approval workflow

Route Risky Requests

A policy routes the request with its agent, action, affected resource, risk signals, and reason. The reviewer approves, denies, or grants an owned, expiring exception; reviewer, reason, timestamp, and outcome enter the audit timeline.

Pending approvals / 03
Production · 2m agoContract approval requestCritical
Production · 8m agoExternal data exportHigh
Staging · 11m agoNew MCP permissionMedium
Human decision required

Web3 execution agent requests approval to call an unverified contract.

Resource0x94...8A11
Risk signalUnknown destination + elevated permission
PolicyDeny-first Web3 / v2.4
ExceptionNone
Audit + intelligence

Investigate Decision Trails

Review requests, risk signals, policy versions, approval events, final outcomes, and relevant threat context together.

Agent requested contract approvalrequest
Risk signals matched policy v2.4evaluation
Approval assigned to AI CISOworkflow
Request denied with reviewer reasondecision
Focused policy review openedfollow-up
Deny-first loop

Review Risky Activity

Every consequential outcome can update policy and improve the next decision.

01

Observe

Capture the requested action.

02

Investigate

Review risk signals, context, and affected systems.

03

Decide

Approve a bounded request or deny the action.

04

Update Policy

Turn a reusable decision into a policy rule.

05

Verify

Verify the new policy against later activity and audit evidence.

FAQ

Frequently Asked Questions

What does AgentGuard monitor?

The Govern page covers agent inventory, action requests, risk signals, policy decisions, approvals, audit evidence, and relevant threat context available through the connected AgentGuard workflow.

How does deny-first governance work?

High-risk activity is denied or held for an explicit decision when policy and context do not support automatic execution. The exact enforcement path depends on the connected integration.

Can teams track policy versions?

The Govern concept includes policy ownership, scope, version, distribution state, effective time, and the policy version used for each recorded decision.

Govern Agent Decisions

Connect agent activity, policy, approvals, audit evidence, and threat context in one control plane.