Web3 execution agent requests contract approval through a connected tool.
AI agent observability + governance
Govern AI Agent Risk and Decisions
Monitor agent activity, risk signals, policy decisions, approvals, and audit evidence from one control plane built for AI agent governance.
Turn Activity into Decisions
AI agents operate across prompts, tools, data, permissions, and external systems. Security teams need a connected record of what the agent requested, which risks were detected, how policy responded, and who approved the outcome. Monitoring provides the activity record; AgentGuard connects it to policy, approval, audit, and remediation workflows.
Trace Every Request
Risk signals and policy evaluation stay inside the event sequence, so the final decision retains its context.
Excessive permission and unknown destination signals match policy v2.4.
The policy requires an explicit AI CISO decision before execution.
The reviewer denies the request. Reason and evidence enter the audit timeline.
Monitor Decision Signals
AI agent monitoring joins identity, requested action, risk, and governance state around the same event.
One connected decision record
Agent identity, owner, environment, integration path, and connected systems
Tool, command, file, data, network destination, permission, and affected asset
Approval status, exception, remediation owner, policy version, and verification state
Signals that affect execution
Requested scope and reachable systems
Detected signals, policy result, severity, reason, and enforcement outcome
Allowed, denied, escalated, approved, or unresolved
Versioned Policies
Create and distribute policy changes, show which version each environment uses, and retain the history needed to explain a decision. Each update keeps its owner, scope, version, deployment state, and effective time visible.
Route Risky Requests
A policy routes the request with its agent, action, affected resource, risk signals, and reason. The reviewer approves, denies, or grants an owned, expiring exception; reviewer, reason, timestamp, and outcome enter the audit timeline.
Web3 execution agent requests approval to call an unverified contract.
Investigate Decision Trails
Review requests, risk signals, policy versions, approval events, final outcomes, and relevant threat context together.
Review Risky Activity
Every consequential outcome can update policy and improve the next decision.
Observe
Capture the requested action.
Investigate
Review risk signals, context, and affected systems.
Decide
Approve a bounded request or deny the action.
Update Policy
Turn a reusable decision into a policy rule.
Verify
Verify the new policy against later activity and audit evidence.
Frequently Asked Questions
What does AgentGuard monitor?
The Govern page covers agent inventory, action requests, risk signals, policy decisions, approvals, audit evidence, and relevant threat context available through the connected AgentGuard workflow.
How does deny-first governance work?
High-risk activity is denied or held for an explicit decision when policy and context do not support automatic execution. The exact enforcement path depends on the connected integration.
Can teams track policy versions?
The Govern concept includes policy ownership, scope, version, distribution state, effective time, and the policy version used for each recorded decision.
Govern Agent Decisions
Connect agent activity, policy, approvals, audit evidence, and threat context in one control plane.