Scope and permission templates
One scope file per agent: allowed tools, data, limits, approvers, and a review date.
Scope, permissions, logging, and approvals for AI agents.
The same controls we apply to the AI agents on our own team. Each agent gets a written scope, minimum necessary permissions, a log of every action, and human approval for high-impact actions. Agents cannot change their own permissions. Any agent can be paused or switched off at once.
AI agents your security team can review and approve.
The problem it solves, what is included, how it works, the technical components, and how we adapt it with you.
Your download has started.
We also emailed the link to . It stays valid for 7 days.
Download didn't start? Get the PDF
Want to see how it would fit your data? Talk to us.
An agent that can send email, update records, or queue payments needs the same controls as a new employee with system access. Most agent projects add those controls late, if at all.
AI Agent Controls give each agent a written scope, check every action against it, and let you switch any agent off at once. They are the controls we apply to the agents on our own team.
Four parts, each adapted to your data, platforms, and controls. What we adapt for you is yours to keep.
One scope file per agent: allowed tools, data, limits, approvers, and a review date.
A hash-chained log of every action, block, and approval, copied to Azure Monitor or your SIEM.
High-impact actions wait for a named approver who is not the agent's owner.
Stop one agent or all agents at once, with action and spending limits per run and per day.
A stop file for this agent or all agents, an environment switch, or a paused scope.
A baseline list no scope can remove, such as changing its own permissions or disabling logging.
The tool must be listed and every data resource allowed. Denied always wins.
Actions and cost, per run and per day.
High-risk tools wait for a listed approver who is not the owner. No answer counts as a denial.
Success, failure, cost, and duration are recorded. Blocks go back to the model to explain.
Vendor-neutral Python and configuration, Azure first, with tests included from the start.
The agent checks invoices against purchase orders. The demo walks through every control.
Every event is in the audit log, and the hash chain verifies it is intact.
The permission matrix sets tools, data, limits, and approvers for each agent.
The guard goes around every tool the agent calls, under its own managed identity.
For every high-risk tool, none of them the agent's owner, in your approval system.
Run the procedure, fill in escalation contacts, and set a review date.
You keep the scope files, the guard, the audit trail, and the switch-off and escalation runbooks.
We state the limits up front, and we recommend tools based on fit. We do not resell platforms.
Get the 10-page PDF to share with your team, or tell us the decision you want to improve and we will tell you whether the AI Agent Controls fits.