AI GUARD

More capable agents.
Less unbounded access.

A proposed control layer between an AI agent and its tools. Identity, scoped permissions, data boundaries and explicit approval—not a request that the model simply behave.

Product preview

Designed around evidence.
Capabilities in development.

A POLICY SANDBOX

Try the boundary.
It holds.

Read an invoice, request an export or attempt a payment. The demonstration checks a fixed policy before it shows a result.

Real enforcement will require every relevant call to pass through an authorised gateway. A bypassed gateway cannot protect that action.

AI PASSPORTOG–AI–0008

Invoice Agent

SERVICE IDENTITY / FINANCE
Scoped
Responsible ownerFinance operations
Authorised purposeInvoice processing
Default accessRead-only
EscalationHuman approval
Read invoice recordsALLOW
Export customer databaseDENY
Change permissionsDENY
Release a paymentAPPROVAL
TRY A TOOL CALL / LOCAL POLICY SIMULATION
ALLOWED · invoice.read
Within this agent’s explicitly approved scope.
ILLUSTRATIVE POLICY / NOT A LIVE AGENT

Permission is not a prompt.

An accountable identity

Every agent should have an owner, an authorised purpose and separately revocable credentials.

Planned capability

A constrained tool boundary

Validate the caller, exact operation, destination and resource. A tool name alone is not an access policy.

Planned capability

A human escalation path

High-impact actions require approval tied to the actual request. The model cannot grant itself more authority.

Planned capability

What this does not promise.

Can you perfectly detect prompt injection?

No. The planned defence is layered: source-aware context, constrained tools, permissions, data controls, monitoring and human approval. No prompt classifier is presented as a perfect guarantee.

Can an SDK wrapper secure an otherwise unrestricted agent?

Not on its own. Enforcement needs to be placed where the agent cannot bypass it, with direct credentials and network paths restricted accordingly.

Which models and agent frameworks are supported?

Model independence is a design goal, not a claim of tested support today. Specific gateways, authentication methods and tool protocols will be listed as validated integrations become available.

A CLEARER PICTURE STARTS HERE

Less noise.
More control.

Your organisation is already connected.
Be part of building the layer that understands it.

Request early accessPRODUCT IN DEVELOPMENT / NO PAYMENT REQUIRED
GUARDIAN / SIMULATED APPROVAL

Contain this demo session?

This changes the demonstration only. In the planned product, this action would require an authorised connector, a matching policy and approval tied to the exact action.

Target
session.demo-4821
Action
Temporary session restriction
Control
15-minute expiry + audit record