Govern · guardrails

Policy Management

Guardrails that decide whether an agent intent is allowed, gated behind dual control, or denied. Edits apply to this simulation session only.

5 of 5 rules active

Active

5

enforced

Hard deny

1

block

Approval gates

2

dual-ctrl

Pending

5

queue

Evals / min

186

live

Queue age

2m 22s

live p50

Rules & simulation

Toggle enforcement, edit effects, and dry-run candidate intents against the rule set.

Read-only Agent OS
  • No shell execution
  • No cluster-admin
  • No secret reads
  • No database writes
  • No firewall changes
  • No autonomous remediation

Policy rules

Toggle enforcement or edit effect, scope and approvers

1 hard deny
IDRuleEffectScopeApproversLast editedEnforcedEdit
POL-001

Database restart requires DBA approval

Any db.restart intent must be approved by a named DBA before it can leave the planner.

require-approvalAll tenants / productionDBA On-call, Service Owner2026-07-28
POL-002

Firewall change requires network + security

Dual approval from Network Operations and Security Engineering for any firewall intent.

require-approvalAll tenantsNetwork Operations, Security Engineering2026-07-22
POL-003

Kubernetes delete blocked

All delete verbs (pod, deployment, node, namespace) are denied at the tool gateway.

denyAll tenants / all environmentsnone2026-06-30
POL-004

Metrics read allowed

Prometheus and metrics reads are permitted without approval for all registered agents.

allowAll tenantsnone2026-06-11
POL-005

Writes blocked during trading hours

Any write intent is denied between 07:00 and 17:30 CET on trading days.

time-windowtn-nordic / productionChange Manager2026-07-15

Policy simulator

Evaluate a candidate intent against the current rule set

Read-only Agent OS
Gateway decisionapproval required

Dual control by DBA On-call + Service Owner.

matched POL-001 · All tenants / production

Approval queue

Dual-control decisions raised by policy gates · live age 2m 22s

5 pending
Read-only Agent OS

Restart clinical read replica pg-clin-r2

Meridian Health Systems · Database Agent 01 · requested by ag-planner-01

Requires: DBA On-call + Service Owner

high

Add SSL-inspection exclusion for registry.corp.internal

Nordic Federated Bank · Network Agent 01 · requested by ag-supervisor-01

Requires: Network Operations + Security Engineering

medium

Enable net-diag-plus for tenant tn-atlas

Atlas Public Sector · Execution Agent 02 · requested by p.raman

Requires: Security Engineering

critical

Raise token budget for Supervisor Agent 01 to 6M

Nordic Federated Bank · Supervisor Agent 01 · requested by i.halvorsen

Requires: FinOps

low

Scale telemetry collectors in SCADA edge estate

Helios Energy Grid · Kubernetes Agent 02 · requested by ag-planner-02

Requires: Platform Engineering

medium