Resource library
Field notes on governing what agents do.
Short, practical writing for the people who have to make autonomous agents explainable: security and GRC owners, privacy counsel, and the platform engineers who ship the agents.
More from the library
Writing agent policy engineers can enforce
Most AI use policies cannot be executed. Here is the shape of one that can.
Read more Practitioner guideAgents should not hold credentials
A token in the context window is a token in the transcript, the logs, and eventually the incident report.
Read more Control mapAudit trails for autonomous agents
What a decision record needs to contain to still be worth something a year from now.
Read more Practitioner guideFail closed by construction
Availability and containment are in tension. Most agent stacks resolve it in the wrong direction, quietly.
Read more Field noteThe tool call is the control point
Agents do not cause harm by thinking. They cause it by calling something. Govern the call, not the conversation.
Read morePut it into practice
Run your own agent traffic through an approved policy.
Observation mode gives you the inventory and the gap analysis before you change a single agent’s behaviour.