{"id":22833,"date":"2007-02-10T12:44:27","date_gmt":"2007-02-10T12:44:27","guid":{"rendered":"https:\/\/scannn.com\/microsoft-agent-governance-toolkit-ai-agent-governance-toolkit-policy-enforcement-zero-trust-identity-execution-sandboxing-and-reliability-engineering-for-autonomous-ai-agents-covers-10\/"},"modified":"2007-02-10T12:44:27","modified_gmt":"2007-02-10T12:44:27","slug":"microsoft-agent-governance-toolkit-ai-agent-governance-toolkit-policy-enforcement-zero-trust-identity-execution-sandboxing-and-reliability-engineering-for-autonomous-ai-agents-covers-10","status":"publish","type":"post","link":"https:\/\/scannn.com\/lv\/microsoft-agent-governance-toolkit-ai-agent-governance-toolkit-policy-enforcement-zero-trust-identity-execution-sandboxing-and-reliability-engineering-for-autonomous-ai-agents-covers-10\/","title":{"rendered":"microsoft\/agent-governance-toolkit: AI Agent Governance Toolkit \u2014 Policy enforcement, zero-trust identity, execution sandboxing, and reliability engineering for autonomous AI agents. Covers 10\/10 OWASP Agentic Top 10. \u00b7 GitHub"},"content":{"rendered":"\n<div id=\"\">\n<p dir=\"auto\"> <a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/README.md\">English<\/a> | <a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/docs\/i18n\/README.ja.md\">\u65e5\u672c\u8a9e<\/a> | <a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/docs\/i18n\/README.zh-CN.md\">\u7b80\u4f53\u4e2d\u6587<\/a> | <a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/docs\/i18n\/README.ko.md\">\ud55c\uad6d\uc5b4<\/a><\/p>\n<p dir=\"auto\"><a target=\"_blank\" rel=\"noopener noreferrer\" href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/docs\/assets\/readme-banner.svg\"><\/a><\/p>\n<div class=\"markdown-heading\" dir=\"auto\">\n<h3 tabindex=\"-1\" class=\"heading-element\" dir=\"auto\">Ship agents to production without losing sleep<\/h3>\n<p><a id=\"user-content-ship-agents-to-production-without-losing-sleep\" class=\"anchor\" aria-label=\"Permalink: Ship agents to production without losing sleep\" href=\"#ship-agents-to-production-without-losing-sleep\"><svg data-component=\"Octicon\" class=\"octicon octicon-link\" viewbox=\"0 0 16 16\" version=\"1.1\" width=\"16\" height=\"16\" aria-hidden=\"true\"><path d=\"m7.775 3.275 1.25-1.25a3.5 3.5 0 1 1 4.95 4.95l-2.5 2.5a3.5 3.5 0 0 1-4.95 0 .751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018 1.998 1.998 0 0 0 2.83 0l2.5-2.5a2.002 2.002 0 0 0-2.83-2.83l-1.25 1.25a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042Zm-4.69 9.64a1.998 1.998 0 0 0 2.83 0l1.25-1.25a.751.751 0 0 1 1.042.018.751.751 0 0 1 .018 1.042l-1.25 1.25a3.5 3.5 0 1 1-4.95-4.95l2.5-2.5a3.5 3.5 0 0 1 4.95 0 .751.751 0 0 1-.018 1.042.751.751 0 0 1-1.042.018 1.998 1.998 0 0 0-2.83 0l-2.5 2.5a1.998 1.998 0 0 0 0 2.83Z\"\/><\/svg><\/a><\/div>\n<p align=\"center\" dir=\"auto\">\n  <a href=\"https:\/\/microsoft.github.io\/agent-governance-toolkit\" rel=\"nofollow\"><br \/>\n    <img decoding=\"async\" src=\"https:\/\/camo.githubusercontent.com\/7789781959d275542dad87babd727b7d9aba3e392b5ad6a50027c089b9b53f91\/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f2546302539462539332539365f46756c6c5f446f63756d656e746174696f6e2d6d6963726f736f66742e6769746875622e696f2532466167656e742d2d676f7665726e616e63652d2d746f6f6c6b69742d3030373844343f7374796c653d666f722d7468652d6261646765266c6f676f436f6c6f723d7768697465\" alt=\"Full Documentation\" height=\"40\" data-canonical-src=\"https:\/\/img.shields.io\/badge\/%F0%9F%93%96_Full_Documentation-microsoft.github.io%2Fagent--governance--toolkit-0078D4?style=for-the-badge&amp;logoColor=white\" style=\"max-width: 100%; height: auto; max-height: 40px;\"\/><br \/>\n  <\/a>\n<\/p>\n<p align=\"center\" dir=\"auto\">\n  <strong><br \/>\n     <a href=\"#quick-start\">Quick Start<\/a> \u00b7<br \/>\n     <a href=\"#specifications\">Specifications<\/a> \u00b7<br \/>\n     <a href=\"https:\/\/pypi.org\/project\/agent-governance-toolkit\/\" rel=\"nofollow\">PyPI<\/a> \u00b7<br \/>\n     <a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/CHANGELOG.md\">Changelog<\/a><br \/>\n  <\/strong>\n<\/p>\n<p dir=\"auto\"><a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/actions\/workflows\/ci.yml\"><img decoding=\"async\" src=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/actions\/workflows\/ci.yml\/badge.svg\" alt=\"CI\" style=\"max-width: 100%;\"\/><\/a><br \/>\n<a href=\"https:\/\/discord.gg\/7aVPCcVh\" rel=\"nofollow\"><img decoding=\"async\" src=\"https:\/\/camo.githubusercontent.com\/95ab272e47c859787ef2d1d3a932076271eb5af5368710e0c4b18f4975a6300b\/68747470733a2f2f646362616467652e6c696d65732e70696e6b2f6170692f7365727665722f37615650436356683f7374796c653d666c6174\" alt=\"Discord\" data-canonical-src=\"https:\/\/dcbadge.limes.pink\/api\/server\/7aVPCcVh?style=flat\" style=\"max-width: 100%;\"\/><\/a><br \/>\n<a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/LICENSE\"><img decoding=\"async\" src=\"https:\/\/camo.githubusercontent.com\/fdf2982b9f5d7489dcf44570e714e3a15fce6253e0cc6b5aa61a075aac2ff71b\/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f4c6963656e73652d4d49542d79656c6c6f772e737667\" alt=\"License: MIT\" data-canonical-src=\"https:\/\/img.shields.io\/badge\/License-MIT-yellow.svg\" style=\"max-width: 100%;\"\/><\/a><br \/>\n<a href=\"https:\/\/pypi.org\/project\/agent-governance-toolkit\/\" rel=\"nofollow\"><img decoding=\"async\" src=\"https:\/\/camo.githubusercontent.com\/b918bd81522bcde5aeaf2bc3a67bbbb8d4656a1a57eb9f9b1057ec42128f0c43\/68747470733a2f2f696d672e736869656c64732e696f2f707970692f762f6167656e742d676f7665726e616e63652d746f6f6c6b69743f6c6162656c3d50795049\" alt=\"PyPI version\" data-canonical-src=\"https:\/\/img.shields.io\/pypi\/v\/agent-governance-toolkit?label=PyPI\" style=\"max-width: 100%;\"\/><\/a><br \/>\n<a href=\"https:\/\/www.npmjs.com\/package\/@microsoft\/agent-governance-sdk\" rel=\"nofollow\"><img decoding=\"async\" src=\"https:\/\/camo.githubusercontent.com\/2bc674f30409028de4738694052b0e589b561e969e045472526a796463b91319\/68747470733a2f2f696d672e736869656c64732e696f2f6e706d2f762f2534306d6963726f736f66742f6167656e742d676f7665726e616e63652d73646b3f6c6162656c3d6e706d\" alt=\"npm\" data-canonical-src=\"https:\/\/img.shields.io\/npm\/v\/%40microsoft\/agent-governance-sdk?label=npm\" style=\"max-width: 100%;\"\/><\/a><br \/>\n<a href=\"https:\/\/www.nuget.org\/packages\/Microsoft.AgentGovernance\" rel=\"nofollow\"><img decoding=\"async\" src=\"https:\/\/camo.githubusercontent.com\/fddfbc73d27282e19cee3d229436247a863c316ff165b59907ca4f908349a2b4\/68747470733a2f2f696d672e736869656c64732e696f2f6e756765742f762f4d6963726f736f66742e4167656e74476f7665726e616e63653f6c6162656c3d4e75476574\" alt=\"NuGet\" data-canonical-src=\"https:\/\/img.shields.io\/nuget\/v\/Microsoft.AgentGovernance?label=NuGet\" style=\"max-width: 100%;\"\/><\/a><br \/>\n<a href=\"https:\/\/scorecard.dev\/viewer\/?uri=github.com\/microsoft\/agent-governance-toolkit\" rel=\"nofollow\"><img decoding=\"async\" src=\"https:\/\/camo.githubusercontent.com\/c1c0e8986b271786823bcce13bb32cc53a6017329ecfe88914dad6f9a3b020fe\/68747470733a2f2f6170692e73636f7265636172642e6465762f70726f6a656374732f6769746875622e636f6d2f6d6963726f736f66742f6167656e742d676f7665726e616e63652d746f6f6c6b69742f6261646765\" alt=\"OpenSSF Scorecard\" data-canonical-src=\"https:\/\/api.scorecard.dev\/projects\/github.com\/microsoft\/agent-governance-toolkit\/badge\" style=\"max-width: 100%;\"\/><\/a><br \/>\n<a href=\"https:\/\/www.bestpractices.dev\/projects\/12085\" rel=\"nofollow\"><img decoding=\"async\" src=\"https:\/\/camo.githubusercontent.com\/ec5210c0fb400416aaa0bb81b01581da2ff61da47f1c1630e6b34a6127fc8a35\/68747470733a2f2f7777772e626573747072616374696365732e6465762f70726f6a656374732f31323038352f6261646765\" alt=\"OpenSSF Best Practices\" data-canonical-src=\"https:\/\/www.bestpractices.dev\/projects\/12085\/badge\" style=\"max-width: 100%;\"\/><\/a><br \/>\n<a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/docs\/compliance\/owasp-agentic-top10-architecture.md\"><img decoding=\"async\" src=\"https:\/\/camo.githubusercontent.com\/aab863bb64bc5004f58e11b848314d476485259ab3bfac9b334c8b11cd350b61\/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f4f574153505f4167656e7469635f546f705f31302d313025324631305f436f76657265642d626c7565\" alt=\"OWASP Agentic Top 10\" data-canonical-src=\"https:\/\/img.shields.io\/badge\/OWASP_Agentic_Top_10-10%2F10_Covered-blue\" style=\"max-width: 100%;\"\/><\/a><br \/>\n<a href=\"https:\/\/aarm.dev\/builders\/agent-governance-toolkit-microsoft\" rel=\"nofollow\"><img decoding=\"async\" src=\"https:\/\/camo.githubusercontent.com\/09eaca53d3896357dc3792025a4ac36f4170abf4955a286d2bdfd8bad5860625\/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f4141524d2d457874656e6465645f2852312545322538302539335239292d627269676874677265656e\" alt=\"AARM Extended\" data-canonical-src=\"https:\/\/img.shields.io\/badge\/AARM-Extended_(R1%E2%80%93R9)-brightgreen\" style=\"max-width: 100%;\"\/><\/a><br \/>\n<a href=\"https:\/\/agentictrustframework.ai\/ecosystem\" rel=\"nofollow\"><img decoding=\"async\" src=\"https:\/\/camo.githubusercontent.com\/d2a87b3336b24f9aec0106db74b3164e55f621e0f1abb487e201bf852ceebf8d\/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f4154462d416c6c5f355f456c656d656e74732d627269676874677265656e\" alt=\"ATF\" data-canonical-src=\"https:\/\/img.shields.io\/badge\/ATF-All_5_Elements-brightgreen\" style=\"max-width: 100%;\"\/><\/a><\/p>\n<div class=\"markdown-alert markdown-alert-important\" dir=\"auto\">\n<p class=\"markdown-alert-title\" dir=\"auto\"><svg data-component=\"Octicon\" class=\"octicon octicon-report mr-2\" viewbox=\"0 0 16 16\" version=\"1.1\" width=\"16\" height=\"16\" aria-hidden=\"true\"><path d=\"M0 1.75C0 .784.784 0 1.75 0h12.5C15.216 0 16 .784 16 1.75v9.5A1.75 1.75 0 0 1 14.25 13H8.06l-2.573 2.573A1.458 1.458 0 0 1 3 14.543V13H1.75A1.75 1.75 0 0 1 0 11.25Zm1.75-.25a.25.25 0 0 0-.25.25v9.5c0 .138.112.25.25.25h2a.75.75 0 0 1 .75.75v2.19l2.72-2.72a.749.749 0 0 1 .53-.22h6.5a.25.25 0 0 0 .25-.25v-9.5a.25.25 0 0 0-.25-.25Zm7 2.25v2.5a.75.75 0 0 1-1.5 0v-2.5a.75.75 0 0 1 1.5 0ZM9 9a1 1 0 1 1-2 0 1 1 0 0 1 2 0Z\"\/><\/svg>Important<\/p>\n<p dir=\"auto\"><strong>Public Preview<\/strong> &#8212; production-quality public preview releases. May have breaking changes before GA.<\/p>\n<\/div>\n<p dir=\"auto\">Policy enforcement, identity, sandboxing, and SRE for autonomous AI agents. One <code>pip install<\/code>, any framework.<\/p>\n<hr\/>\n<p dir=\"auto\">Your AI agents call tools, browse the web, query databases, and delegate to other agents. Once deployed, they make decisions autonomously. You need answers to three questions:<\/p>\n<p dir=\"auto\"><strong>1. Is this action allowed?<\/strong> An agent with access to <code>send_email<\/code> and <code>query_database<\/code> should not be able to <code>drop_table<\/code>. OAuth scopes and IAM roles control which services an agent can reach, not what it does once connected.<\/p>\n<p dir=\"auto\"><strong>2. Which agent did this?<\/strong> In a multi-agent system, five agents might share a single API key. When something goes wrong, &#8220;an agent did it&#8221; is not an incident response.<\/p>\n<p dir=\"auto\"><strong>3. Can you prove what happened?<\/strong> Auditors and regulators need tamper-evident records of every decision: what policy was active, what the agent requested, and why it was allowed or denied.<\/p>\n<p dir=\"auto\">Prompt-level safety (&#8220;please follow the rules&#8221;) is not a control surface. It is a polite request to a stochastic system. <a href=\"https:\/\/genai.owasp.org\/llmrisk\/llm01-prompt-injection\/\" rel=\"nofollow\">OWASP LLM01:2025<\/a> states this explicitly: <em>&#8220;it is unclear if there are fool-proof methods of prevention for prompt injection.&#8221;<\/em> The published numbers back this up. <a href=\"https:\/\/arxiv.org\/abs\/2404.02151\" rel=\"nofollow\">Andriushchenko et al. (ICLR 2025)<\/a> report <strong>100% attack success rate<\/strong> on GPT-4o, GPT-3.5, Claude 3, and Llama-3 using adaptive attacks with logprob access and suffix optimization, evaluated against the <a href=\"https:\/\/arxiv.org\/abs\/2404.01318\" rel=\"nofollow\">JailbreakBench<\/a> benchmark (Chao et al., NeurIPS 2024). Microsoft&#8217;s own <a href=\"https:\/\/learn.microsoft.com\/azure\/ai-foundry\/concepts\/ai-red-teaming-agent\" rel=\"nofollow\">AI Red Teaming Agent<\/a> formalizes <strong>Attack Success Rate (ASR)<\/strong>, the rate of policy violations under adversarial input, as the canonical metric for this class of failure. <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2025\/01\/13\/3-takeaways-from-red-teaming-100-generative-ai-products\/\" rel=\"nofollow\"><em>Lessons from Red Teaming 100 Generative AI Products<\/em><\/a> reinforces the point: <em>&#8220;mitigations do not eliminate risk entirely&#8221;<\/em> and red teaming must be a continuous process because model-layer defenses are probabilistic by construction.<\/p>\n<p dir=\"auto\">AGT does not try to win that fight inside the prompt. Every tool call, message send, and delegation is intercepted in deterministic application code <em>before<\/em> the model&#8217;s intent reaches the wire. Actions the AGT kernel denies are not &#8220;unlikely.&#8221; They are <strong>structurally impossible<\/strong>. That is the difference between asking an agent to behave and making it incapable of misbehaving.<\/p>\n<hr\/>\n<p dir=\"auto\"><strong>Prerequisites:<\/strong> Python 3.10+<\/p>\n<div class=\"highlight highlight-source-shell notranslate position-relative overflow-auto\" dir=\"auto\" data-snippet-clipboard-copy-content=\"pip install agent-governance-toolkit[full]\">\n<pre>pip install agent-governance-toolkit[full]<\/pre>\n<\/div>\n<p dir=\"auto\">Use the <code>[full]<\/code> extra for the quick-start imports below. The base<br \/>\n<code>agent-governance-toolkit<\/code> wheel installs the compliance CLI only; the governance<br \/>\nmodules live in the consolidated core distribution. The <code>agentmesh<\/code> quick-start<br \/>\nimport remains the current wrapper API. The <code>agent_os<\/code> <code>PolicyEvaluator<\/code> example<br \/>\nbelow is legacy compatibility: importing <code>agent_os<\/code> currently emits a<br \/>\n<code>DeprecationWarning<\/code> because the old <code>agent-os-kernel<\/code> distribution is deprecated.<br \/>\nUse <code>agent-governance-toolkit-core<\/code> (or the <code>[full]<\/code> extra that includes it) as<br \/>\nthe replacement distribution, and prefer the AGT 5 <code>agt-policies<\/code>\/ACS APIs for<br \/>\nnew policy-engine host code.<\/p>\n<p dir=\"auto\">For Claude Code, add AGT as a plugin marketplace and install the governance plugin:<\/p>\n<div class=\"snippet-clipboard-content notranslate position-relative overflow-auto\" data-snippet-clipboard-copy-content=\"\/plugin marketplace add microsoft\/agent-governance-toolkit&#10;\/plugin install agt-governance@agent-governance-toolkit\">\n<pre lang=\"text\" class=\"notranslate\"><code>\/plugin marketplace add microsoft\/agent-governance-toolkit\n\/plugin install agt-governance@agent-governance-toolkit\n<\/code><\/pre>\n<\/div>\n<p dir=\"auto\">Govern any tool function in two lines:<\/p>\n<div class=\"highlight highlight-source-python notranslate position-relative overflow-auto\" dir=\"auto\" data-snippet-clipboard-copy-content=\"from agentmesh.governance import govern&#10;&#10;safe_tool = govern(my_tool, policy=&quot;policy.yaml&quot;)   # every call checked, logged, enforced\">\n<pre><span class=\"pl-k\">from<\/span> <span class=\"pl-s1\">agentmesh<\/span>.<span class=\"pl-s1\">governance<\/span> <span class=\"pl-k\">import<\/span> <span class=\"pl-s1\">govern<\/span>\n\n<span class=\"pl-s1\">safe_tool<\/span> <span class=\"pl-c1\">=<\/span> <span class=\"pl-en\">govern<\/span>(<span class=\"pl-s1\">my_tool<\/span>, <span class=\"pl-s1\">policy<\/span><span class=\"pl-c1\">=<\/span><span class=\"pl-s\">\"policy.yaml\"<\/span>)   <span class=\"pl-c\"># every call checked, logged, enforced<\/span><\/pre>\n<\/div>\n<p dir=\"auto\">That&#8217;s it. <code>safe_tool<\/code> evaluates your YAML policy on every call, logs the decision, and raises <code>GovernanceDenied<\/code> if the action is blocked.<\/p>\n<div class=\"highlight highlight-source-yaml notranslate position-relative overflow-auto\" dir=\"auto\" data-snippet-clipboard-copy-content=\"# policy.yaml&#10;apiVersion: governance.toolkit\/v1&#10;name: production-policy&#10;default_action: allow&#10;rules:&#10;  - name: block-destructive&#10;    condition: &quot;action.type in ['drop', 'delete', 'truncate']&quot;&#10;    action: deny&#10;    description: &quot;Destructive operations require human approval&quot;&#10;&#10;  - name: require-approval-for-send&#10;    condition: &quot;action.type == 'send_email'&quot;&#10;    action: require_approval&#10;    approvers: [&quot;security-team&quot;]\">\n<pre><span class=\"pl-c\"><span class=\"pl-c\">#<\/span> policy.yaml<\/span>\n<span class=\"pl-ent\">apiVersion<\/span>: <span class=\"pl-s\">governance.toolkit\/v1<\/span>\n<span class=\"pl-ent\">name<\/span>: <span class=\"pl-s\">production-policy<\/span>\n<span class=\"pl-ent\">default_action<\/span>: <span class=\"pl-s\">allow<\/span>\n<span class=\"pl-ent\">rules<\/span>:\n  - <span class=\"pl-ent\">name<\/span>: <span class=\"pl-s\">block-destructive<\/span>\n    <span class=\"pl-ent\">condition<\/span>: <span class=\"pl-s\"><span class=\"pl-pds\">\"<\/span>action.type in ['drop', 'delete', 'truncate']<span class=\"pl-pds\">\"<\/span><\/span>\n    <span class=\"pl-ent\">action<\/span>: <span class=\"pl-s\">deny<\/span>\n    <span class=\"pl-ent\">description<\/span>: <span class=\"pl-s\"><span class=\"pl-pds\">\"<\/span>Destructive operations require human approval<span class=\"pl-pds\">\"<\/span><\/span>\n\n  - <span class=\"pl-ent\">name<\/span>: <span class=\"pl-s\">require-approval-for-send<\/span>\n    <span class=\"pl-ent\">condition<\/span>: <span class=\"pl-s\"><span class=\"pl-pds\">\"<\/span>action.type == 'send_email'<span class=\"pl-pds\">\"<\/span><\/span>\n    <span class=\"pl-ent\">action<\/span>: <span class=\"pl-s\">require_approval<\/span>\n    <span class=\"pl-ent\">approvers<\/span>: <span class=\"pl-s\">[\"security-team\"]<\/span><\/pre>\n<\/div>\n<div class=\"highlight highlight-source-python notranslate position-relative overflow-auto\" dir=\"auto\" data-snippet-clipboard-copy-content=\"&gt;&gt;&gt; safe_tool(action=&quot;read&quot;, table=&quot;users&quot;)&#10;{'table': 'users', 'rows': 42}&#10;&#10;&gt;&gt;&gt; safe_tool(action=&quot;drop&quot;, table=&quot;users&quot;)&#10;GovernanceDenied: Action denied by policy rule 'block-destructive':&#10;  Destructive operations require human approval\">\n<pre><span class=\"pl-c1\">&gt;<\/span><span class=\"pl-c1\">&gt;&gt;<\/span> <span class=\"pl-en\">safe_tool<\/span>(<span class=\"pl-s1\">action<\/span><span class=\"pl-c1\">=<\/span><span class=\"pl-s\">\"read\"<\/span>, <span class=\"pl-s1\">table<\/span><span class=\"pl-c1\">=<\/span><span class=\"pl-s\">\"users\"<\/span>)\n{<span class=\"pl-s\">'table'<\/span>: <span class=\"pl-s\">'users'<\/span>, <span class=\"pl-s\">'rows'<\/span>: <span class=\"pl-c1\">42<\/span>}\n\n<span class=\"pl-c1\">&gt;<\/span><span class=\"pl-c1\">&gt;&gt;<\/span> <span class=\"pl-en\">safe_tool<\/span>(<span class=\"pl-s1\">action<\/span><span class=\"pl-c1\">=<\/span><span class=\"pl-s\">\"drop\"<\/span>, <span class=\"pl-s1\">table<\/span><span class=\"pl-c1\">=<\/span><span class=\"pl-s\">\"users\"<\/span>)\n<span class=\"pl-v\">GovernanceDenied<\/span>: <span class=\"pl-v\">Action<\/span> <span class=\"pl-s1\">denied<\/span> <span class=\"pl-s1\">by<\/span> <span class=\"pl-s1\">policy<\/span> <span class=\"pl-s1\">rule<\/span> <span class=\"pl-s\">'block-destructive'<\/span>:\n  <span class=\"pl-v\">Destructive<\/span> <span class=\"pl-s1\">operations<\/span> <span class=\"pl-s1\">require<\/span> <span class=\"pl-s1\">human<\/span> <span class=\"pl-smi\">approval<\/span><\/pre>\n<\/div>\n<p dir=\"auto\">Or use the full <code>PolicyEvaluator<\/code> API for programmatic control:<\/p>\n<details>\n<summary><b>PolicyEvaluator example<\/b><\/summary>\n<div class=\"highlight highlight-source-python notranslate position-relative overflow-auto\" dir=\"auto\" data-snippet-clipboard-copy-content=\"from agent_os.policies import (&#10;    PolicyEvaluator, PolicyDocument, PolicyRule,&#10;    PolicyCondition, PolicyAction, PolicyOperator, PolicyDefaults&#10;)&#10;&#10;evaluator = PolicyEvaluator(policies=[PolicyDocument(&#10;    name=&quot;my-policy&quot;, version=&quot;1.0&quot;,&#10;    defaults=PolicyDefaults(action=PolicyAction.ALLOW),&#10;    rules=[PolicyRule(&#10;        name=&quot;block-dangerous-tools&quot;,&#10;        condition=PolicyCondition(&#10;            field=&quot;tool_name&quot;,&#10;            operator=PolicyOperator.IN,&#10;            value=[&quot;execute_code&quot;, &quot;delete_file&quot;]&#10;        ),&#10;        action=PolicyAction.DENY, priority=100,&#10;    )],&#10;)])&#10;&#10;result = evaluator.evaluate({&quot;tool_name&quot;: &quot;web_search&quot;})    # Allowed&#10;result = evaluator.evaluate({&quot;tool_name&quot;: &quot;delete_file&quot;})   # Blocked\">\n<pre><span class=\"pl-k\">from<\/span> <span class=\"pl-s1\">agent_os<\/span>.<span class=\"pl-s1\">policies<\/span> <span class=\"pl-k\">import<\/span> (\n    <span class=\"pl-v\">PolicyEvaluator<\/span>, <span class=\"pl-v\">PolicyDocument<\/span>, <span class=\"pl-v\">PolicyRule<\/span>,\n    <span class=\"pl-v\">PolicyCondition<\/span>, <span class=\"pl-v\">PolicyAction<\/span>, <span class=\"pl-v\">PolicyOperator<\/span>, <span class=\"pl-v\">PolicyDefaults<\/span>\n)\n\n<span class=\"pl-s1\">evaluator<\/span> <span class=\"pl-c1\">=<\/span> <span class=\"pl-en\">PolicyEvaluator<\/span>(<span class=\"pl-s1\">policies<\/span><span class=\"pl-c1\">=<\/span>[<span class=\"pl-en\">PolicyDocument<\/span>(\n    <span class=\"pl-s1\">name<\/span><span class=\"pl-c1\">=<\/span><span class=\"pl-s\">\"my-policy\"<\/span>, <span class=\"pl-s1\">version<\/span><span class=\"pl-c1\">=<\/span><span class=\"pl-s\">\"1.0\"<\/span>,\n    <span class=\"pl-s1\">defaults<\/span><span class=\"pl-c1\">=<\/span><span class=\"pl-en\">PolicyDefaults<\/span>(<span class=\"pl-s1\">action<\/span><span class=\"pl-c1\">=<\/span><span class=\"pl-v\">PolicyAction<\/span>.<span class=\"pl-c1\">ALLOW<\/span>),\n    <span class=\"pl-s1\">rules<\/span><span class=\"pl-c1\">=<\/span>[<span class=\"pl-en\">PolicyRule<\/span>(\n        <span class=\"pl-s1\">name<\/span><span class=\"pl-c1\">=<\/span><span class=\"pl-s\">\"block-dangerous-tools\"<\/span>,\n        <span class=\"pl-s1\">condition<\/span><span class=\"pl-c1\">=<\/span><span class=\"pl-en\">PolicyCondition<\/span>(\n            <span class=\"pl-s1\">field<\/span><span class=\"pl-c1\">=<\/span><span class=\"pl-s\">\"tool_name\"<\/span>,\n            <span class=\"pl-s1\">operator<\/span><span class=\"pl-c1\">=<\/span><span class=\"pl-v\">PolicyOperator<\/span>.<span class=\"pl-c1\">IN<\/span>,\n            <span class=\"pl-s1\">value<\/span><span class=\"pl-c1\">=<\/span>[<span class=\"pl-s\">\"execute_code\"<\/span>, <span class=\"pl-s\">\"delete_file\"<\/span>]\n        ),\n        <span class=\"pl-s1\">action<\/span><span class=\"pl-c1\">=<\/span><span class=\"pl-v\">PolicyAction<\/span>.<span class=\"pl-c1\">DENY<\/span>, <span class=\"pl-s1\">priority<\/span><span class=\"pl-c1\">=<\/span><span class=\"pl-c1\">100<\/span>,\n    )],\n)])\n\n<span class=\"pl-s1\">result<\/span> <span class=\"pl-c1\">=<\/span> <span class=\"pl-s1\">evaluator<\/span>.<span class=\"pl-c1\">evaluate<\/span>({<span class=\"pl-s\">\"tool_name\"<\/span>: <span class=\"pl-s\">\"web_search\"<\/span>})    <span class=\"pl-c\"># Allowed<\/span>\n<span class=\"pl-s1\">result<\/span> <span class=\"pl-c1\">=<\/span> <span class=\"pl-s1\">evaluator<\/span>.<span class=\"pl-c1\">evaluate<\/span>({<span class=\"pl-s\">\"tool_name\"<\/span>: <span class=\"pl-s\">\"delete_file\"<\/span>})   <span class=\"pl-c\"># Blocked<\/span><\/pre>\n<\/div>\n<\/details>\n<details>\n<summary><b>TypeScript \/ .NET \/ Rust \/ Go examples<\/b><\/summary>\n<p dir=\"auto\"><strong>TypeScript<\/strong><\/p>\n<div class=\"highlight highlight-source-ts notranslate position-relative overflow-auto\" dir=\"auto\" data-snippet-clipboard-copy-content=\"import { PolicyEngine } from &quot;@microsoft\/agent-governance-sdk&quot;;&#10;&#10;const engine = new PolicyEngine([&#10;  { action: &quot;web_search&quot;, effect: &quot;allow&quot; },&#10;  { action: &quot;shell_exec&quot;, effect: &quot;deny&quot; },&#10;]);&#10;engine.evaluate(&quot;web_search&quot;); \/\/ &quot;allow&quot;&#10;engine.evaluate(&quot;shell_exec&quot;); \/\/ &quot;deny&quot;\">\n<pre><span class=\"pl-k\">import<\/span> <span class=\"pl-kos\">{<\/span> <span class=\"pl-v\">PolicyEngine<\/span> <span class=\"pl-kos\">}<\/span> <span class=\"pl-k\">from<\/span> <span class=\"pl-s\">\"@microsoft\/agent-governance-sdk\"<\/span><span class=\"pl-kos\">;<\/span>\n\n<span class=\"pl-k\">const<\/span> <span class=\"pl-s1\">engine<\/span> <span class=\"pl-c1\">=<\/span> <span class=\"pl-k\">new<\/span> <span class=\"pl-v\">PolicyEngine<\/span><span class=\"pl-kos\">(<\/span><span class=\"pl-kos\">[<\/span>\n  <span class=\"pl-kos\">{<\/span> <span class=\"pl-c1\">action<\/span>: <span class=\"pl-s\">\"web_search\"<\/span><span class=\"pl-kos\">,<\/span> <span class=\"pl-c1\">effect<\/span>: <span class=\"pl-s\">\"allow\"<\/span> <span class=\"pl-kos\">}<\/span><span class=\"pl-kos\">,<\/span>\n  <span class=\"pl-kos\">{<\/span> <span class=\"pl-c1\">action<\/span>: <span class=\"pl-s\">\"shell_exec\"<\/span><span class=\"pl-kos\">,<\/span> <span class=\"pl-c1\">effect<\/span>: <span class=\"pl-s\">\"deny\"<\/span> <span class=\"pl-kos\">}<\/span><span class=\"pl-kos\">,<\/span>\n<span class=\"pl-kos\">]<\/span><span class=\"pl-kos\">)<\/span><span class=\"pl-kos\">;<\/span>\n<span class=\"pl-s1\">engine<\/span><span class=\"pl-kos\">.<\/span><span class=\"pl-en\">evaluate<\/span><span class=\"pl-kos\">(<\/span><span class=\"pl-s\">\"web_search\"<\/span><span class=\"pl-kos\">)<\/span><span class=\"pl-kos\">;<\/span> <span class=\"pl-c\">\/\/ \"allow\"<\/span>\n<span class=\"pl-s1\">engine<\/span><span class=\"pl-kos\">.<\/span><span class=\"pl-en\">evaluate<\/span><span class=\"pl-kos\">(<\/span><span class=\"pl-s\">\"shell_exec\"<\/span><span class=\"pl-kos\">)<\/span><span class=\"pl-kos\">;<\/span> <span class=\"pl-c\">\/\/ \"deny\"<\/span><\/pre>\n<\/div>\n<p dir=\"auto\"><strong>.NET<\/strong><\/p>\n<div class=\"highlight highlight-source-cs notranslate position-relative overflow-auto\" dir=\"auto\" data-snippet-clipboard-copy-content=\"using AgentGovernance;&#10;using AgentGovernance.Extensions.ModelContextProtocol;&#10;using AgentGovernance.Policy;&#10;&#10;var kernel = new GovernanceKernel(new GovernanceOptions&#10;{&#10;    PolicyPaths = new() { &quot;policies\/default.yaml&quot; },&#10;});&#10;var result = kernel.EvaluateToolCall(&quot;did:mesh:agent-1&quot;, &quot;web_search&quot;,&#10;    new() { [&quot;query&quot;] = &quot;latest AI news&quot; });&#10;&#10;\/\/ MCP server integration&#10;builder.Services.AddMcpServer()&#10;    .WithGovernance(options =&gt; options.PolicyPaths.Add(&quot;policies\/mcp.yaml&quot;));\">\n<pre><span class=\"pl-k\">using<\/span> <span class=\"pl-s1\">AgentGovernance<\/span><span class=\"pl-kos\">;<\/span>\n<span class=\"pl-k\">using<\/span> <span class=\"pl-s1\">AgentGovernance<\/span><span class=\"pl-kos\">.<\/span><span class=\"pl-s1\">Extensions<\/span><span class=\"pl-kos\">.<\/span><span class=\"pl-s1\">ModelContextProtocol<\/span><span class=\"pl-kos\">;<\/span>\n<span class=\"pl-k\">using<\/span> <span class=\"pl-s1\">AgentGovernance<\/span><span class=\"pl-kos\">.<\/span><span class=\"pl-s1\">Policy<\/span><span class=\"pl-kos\">;<\/span>\n\n<span class=\"pl-k\">var<\/span> <span class=\"pl-s1\">kernel<\/span> <span class=\"pl-c1\">=<\/span> <span class=\"pl-k\">new<\/span> <span class=\"pl-smi\">GovernanceKernel<\/span><span class=\"pl-kos\">(<\/span><span class=\"pl-k\">new<\/span> <span class=\"pl-smi\">GovernanceOptions<\/span>\n<span class=\"pl-kos\">{<\/span>\n    <span class=\"pl-s1\">PolicyPaths<\/span> <span class=\"pl-c1\">=<\/span> <span class=\"pl-k\">new<\/span><span class=\"pl-kos\">(<\/span><span class=\"pl-kos\">)<\/span> <span class=\"pl-kos\">{<\/span> <span class=\"pl-s\">\"policies\/default.yaml\"<\/span> <span class=\"pl-kos\">}<\/span><span class=\"pl-kos\">,<\/span>\n<span class=\"pl-kos\">}<\/span><span class=\"pl-kos\">)<\/span><span class=\"pl-kos\">;<\/span>\n<span class=\"pl-k\">var<\/span> <span class=\"pl-s1\">result<\/span> <span class=\"pl-c1\">=<\/span> <span class=\"pl-s1\">kernel<\/span><span class=\"pl-kos\">.<\/span><span class=\"pl-en\">EvaluateToolCall<\/span><span class=\"pl-kos\">(<\/span><span class=\"pl-s\">\"did:mesh:agent-1\"<\/span><span class=\"pl-kos\">,<\/span> <span class=\"pl-s\">\"web_search\"<\/span><span class=\"pl-kos\">,<\/span>\n    <span class=\"pl-k\">new<\/span><span class=\"pl-kos\">(<\/span><span class=\"pl-kos\">)<\/span> <span class=\"pl-kos\">{<\/span> <span class=\"pl-kos\">[<\/span><span class=\"pl-s\">\"query\"<\/span><span class=\"pl-kos\">]<\/span> <span class=\"pl-c1\">=<\/span> <span class=\"pl-s\">\"latest AI news\"<\/span> <span class=\"pl-kos\">}<\/span><span class=\"pl-kos\">)<\/span><span class=\"pl-kos\">;<\/span>\n\n<span class=\"pl-c\">\/\/ MCP server integration<\/span>\n<span class=\"pl-s1\">builder<\/span><span class=\"pl-kos\">.<\/span><span class=\"pl-s1\">Services<\/span><span class=\"pl-kos\">.<\/span><span class=\"pl-en\">AddMcpServer<\/span><span class=\"pl-kos\">(<\/span><span class=\"pl-kos\">)<\/span>\n    <span class=\"pl-kos\">.<\/span><span class=\"pl-en\">WithGovernance<\/span><span class=\"pl-kos\">(<\/span>options <span class=\"pl-c1\">=&gt;<\/span> <span class=\"pl-s1\">options<\/span><span class=\"pl-kos\">.<\/span><span class=\"pl-s1\">PolicyPaths<\/span><span class=\"pl-kos\">.<\/span><span class=\"pl-en\">Add<\/span><span class=\"pl-kos\">(<\/span><span class=\"pl-s\">\"policies\/mcp.yaml\"<\/span><span class=\"pl-kos\">)<\/span><span class=\"pl-kos\">)<\/span><span class=\"pl-kos\">;<\/span><\/pre>\n<\/div>\n<p dir=\"auto\"><strong>Rust<\/strong><\/p>\n<div class=\"highlight highlight-source-rust notranslate position-relative overflow-auto\" dir=\"auto\" data-snippet-clipboard-copy-content=\"use agent_governance::{AgentMeshClient, ClientOptions};&#10;&#10;let client = AgentMeshClient::new(&quot;my-agent&quot;).unwrap();&#10;let result = client.execute_with_governance(&quot;data.read&quot;, None);&#10;assert!(result.allowed);\">\n<pre><span class=\"pl-k\">use<\/span> agent_governance<span class=\"pl-kos\">::<\/span><span class=\"pl-kos\">{<\/span><span class=\"pl-v\">AgentMeshClient<\/span><span class=\"pl-kos\">,<\/span> <span class=\"pl-v\">ClientOptions<\/span><span class=\"pl-kos\">}<\/span><span class=\"pl-kos\">;<\/span>\n\n<span class=\"pl-k\">let<\/span> client = <span class=\"pl-smi\">AgentMeshClient<\/span><span class=\"pl-kos\">::<\/span><span class=\"pl-en\">new<\/span><span class=\"pl-kos\">(<\/span><span class=\"pl-s\">\"my-agent\"<\/span><span class=\"pl-kos\">)<\/span><span class=\"pl-kos\">.<\/span><span class=\"pl-en\">unwrap<\/span><span class=\"pl-kos\">(<\/span><span class=\"pl-kos\">)<\/span><span class=\"pl-kos\">;<\/span>\n<span class=\"pl-k\">let<\/span> result = client<span class=\"pl-kos\">.<\/span><span class=\"pl-en\">execute_with_governance<\/span><span class=\"pl-kos\">(<\/span><span class=\"pl-s\">\"data.read\"<\/span><span class=\"pl-kos\">,<\/span> <span class=\"pl-v\">None<\/span><span class=\"pl-kos\">)<\/span><span class=\"pl-kos\">;<\/span>\n<span class=\"pl-en\">assert<\/span><span class=\"pl-en\">!<\/span><span class=\"pl-kos\">(<\/span>result<span class=\"pl-kos\">.<\/span>allowed<span class=\"pl-kos\">)<\/span><span class=\"pl-kos\">;<\/span><\/pre>\n<\/div>\n<p dir=\"auto\"><strong>Go<\/strong><\/p>\n<div class=\"highlight highlight-source-go notranslate position-relative overflow-auto\" dir=\"auto\" data-snippet-clipboard-copy-content=\"import agentmesh &quot;github.com\/microsoft\/agent-governance-toolkit\/agent-governance-golang&quot;&#10;&#10;client, _ := agentmesh.NewClient(&quot;my-agent&quot;,&#10;    agentmesh.WithPolicyRules([]agentmesh.PolicyRule{&#10;        {Action: &quot;data.read&quot;, Effect: agentmesh.Allow},&#10;        {Action: &quot;*&quot;, Effect: agentmesh.Deny},&#10;    }),&#10;)&#10;result := client.ExecuteWithGovernance(&quot;data.read&quot;, nil)\">\n<pre><span class=\"pl-k\">import<\/span> agentmesh <span class=\"pl-s\">\"github.com\/microsoft\/agent-governance-toolkit\/agent-governance-golang\"<\/span>\n\n<span class=\"pl-s1\">client<\/span>, <span class=\"pl-s1\">_<\/span> <span class=\"pl-c1\">:=<\/span> <span class=\"pl-s1\">agentmesh<\/span>.<span class=\"pl-c1\">NewClient<\/span>(<span class=\"pl-s\">\"my-agent\"<\/span>,\n    <span class=\"pl-s1\">agentmesh<\/span>.<span class=\"pl-c1\">WithPolicyRules<\/span>([]agentmesh.<span class=\"pl-smi\">PolicyRule<\/span>{\n        {<span class=\"pl-s1\">Action<\/span>: <span class=\"pl-s\">\"data.read\"<\/span>, <span class=\"pl-s1\">Effect<\/span>: <span class=\"pl-s1\">agentmesh<\/span>.<span class=\"pl-c1\">Allow<\/span>},\n        {<span class=\"pl-s1\">Action<\/span>: <span class=\"pl-s\">\"*\"<\/span>, <span class=\"pl-s1\">Effect<\/span>: <span class=\"pl-s1\">agentmesh<\/span>.<span class=\"pl-c1\">Deny<\/span>},\n    }),\n)\n<span class=\"pl-s1\">result<\/span> <span class=\"pl-c1\">:=<\/span> <span class=\"pl-s1\">client<\/span>.<span class=\"pl-c1\">ExecuteWithGovernance<\/span>(<span class=\"pl-s\">\"data.read\"<\/span>, <span class=\"pl-c1\">nil<\/span>)<\/pre>\n<\/div>\n<\/details>\n<p dir=\"auto\">CLI tools:<\/p>\n<div class=\"highlight highlight-source-shell notranslate position-relative overflow-auto\" dir=\"auto\" data-snippet-clipboard-copy-content=\"agt doctor                                        # check installation&#10;agt verify                                        # OWASP compliance check&#10;agt verify --evidence .\/agt-evidence.json --strict # fail CI on weak evidence&#10;agt red-team scan .\/prompts\/ --min-grade B         # prompt injection audit&#10;agt lint-policy policies\/                          # validate policy files\">\n<pre>agt doctor                                        <span class=\"pl-c\"><span class=\"pl-c\">#<\/span> check installation<\/span>\nagt verify                                        <span class=\"pl-c\"><span class=\"pl-c\">#<\/span> OWASP compliance check<\/span>\nagt verify --evidence .\/agt-evidence.json --strict <span class=\"pl-c\"><span class=\"pl-c\">#<\/span> fail CI on weak evidence<\/span>\nagt red-team scan .\/prompts\/ --min-grade B         <span class=\"pl-c\"><span class=\"pl-c\">#<\/span> prompt injection audit<\/span>\nagt lint-policy policies\/                          <span class=\"pl-c\"><span class=\"pl-c\">#<\/span> validate policy files<\/span><\/pre>\n<\/div>\n<p dir=\"auto\">Full walkthrough: <a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/docs\/quickstart.md\">quickstart.md<\/a> &#8212; zero to governed agents in 5 minutes.<br \/>\n Also in: <a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/docs\/i18n\/quickstart.ja.md\">\u65e5\u672c\u8a9e<\/a> | <a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/docs\/i18n\/quickstart.zh-CN.md\">\u7b80\u4f53\u4e2d\u6587<\/a> | <a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/docs\/i18n\/quickstart.ko.md\">\ud55c\uad6d\uc5b4<\/a><\/p>\n<hr\/>\n<div class=\"snippet-clipboard-content notranslate position-relative overflow-auto\" data-snippet-clipboard-copy-content=\"Agent \u2500\u2500\u25ba Policy Engine \u2500\u2500\u25ba Identity \u2500\u2500\u25ba Audit Log&#10;            (YAML\/OPA\/Cedar)  (SPIFFE\/DID\/mTLS)  (Tamper-evident)&#10;                 \u2502                                      \u2502&#10;                 \u251c\u2500\u2500 Allowed \u2500\u2500\u25ba Tool executes           \u2502&#10;                 \u2514\u2500\u2500 Denied  \u2500\u2500\u25ba GovernanceDenied        \u2502&#10;                                                        \u25bc&#10;                                                 Decision Record\">\n<pre class=\"notranslate\"><code>Agent \u2500\u2500\u25ba Policy Engine \u2500\u2500\u25ba Identity \u2500\u2500\u25ba Audit Log\n            (YAML\/OPA\/Cedar)  (SPIFFE\/DID\/mTLS)  (Tamper-evident)\n                 \u2502                                      \u2502\n                 \u251c\u2500\u2500 Allowed \u2500\u2500\u25ba Tool executes           \u2502\n                 \u2514\u2500\u2500 Denied  \u2500\u2500\u25ba GovernanceDenied        \u2502\n                                                        \u25bc\n                                                 Decision Record\n<\/code><\/pre>\n<\/div>\n<p dir=\"auto\">Every layer is optional. Start with <code>govern()<\/code> and add layers as your risk profile grows. Most teams run policy enforcement + audit logging and never need the full stack.<\/p>\n<hr\/>\n<p><markdown-accessiblity-table><\/p>\n<table>\n<thead>\n<tr>\n<th>Package<\/th>\n<th>Description<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/agent-governance-python\/agent-os\"><strong>Agent OS<\/strong><\/a><\/td>\n<td>Policy engine, agent lifecycle, governance gate<\/td>\n<\/tr>\n<tr>\n<td><a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/policy-engine\"><strong>Agent Control Specification<\/strong><\/a> (<a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/policy-engine\/README.md\">README<\/a>)<\/td>\n<td>Stateless, deterministic, fail-closed policy decision runtime (Rust core) backing the AGT policy layer<\/td>\n<\/tr>\n<tr>\n<td><a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/agent-governance-python\/agent-mesh\"><strong>Agent Mesh<\/strong><\/a><\/td>\n<td>Agent discovery, routing, and trust mesh<\/td>\n<\/tr>\n<tr>\n<td><a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/agent-governance-python\/agent-runtime\"><strong>Agent Runtime<\/strong><\/a><\/td>\n<td>Execution sandboxing with four privilege rings<\/td>\n<\/tr>\n<tr>\n<td><a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/agent-governance-python\/agent-sre\"><strong>Agent SRE<\/strong><\/a><\/td>\n<td>Kill switch, SLO monitoring, chaos testing<\/td>\n<\/tr>\n<tr>\n<td><a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/agent-governance-python\/agent-compliance\"><strong>Agent Compliance<\/strong><\/a><\/td>\n<td>OWASP verification, policy linting, integrity checks<\/td>\n<\/tr>\n<tr>\n<td><a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/agent-governance-python\/agent-marketplace\"><strong>Agent Marketplace<\/strong><\/a><\/td>\n<td>Plugin governance and trust scoring<\/td>\n<\/tr>\n<tr>\n<td><a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/agent-governance-python\/agent-lightning\"><strong>Agent Lightning<\/strong><\/a><\/td>\n<td>RL training governance with violation penalties<\/td>\n<\/tr>\n<tr>\n<td><a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/agent-governance-python\/agent-hypervisor\"><strong>Agent Hypervisor<\/strong><\/a><\/td>\n<td>Execution audit, delta engine, in-memory commitment tracking, command denylist enforcement<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><\/markdown-accessiblity-table><\/p>\n<p><markdown-accessiblity-table><\/p>\n<table>\n<thead>\n<tr>\n<th>Capability<\/th>\n<th>Description<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><strong>MCP Security Gateway<\/strong><\/td>\n<td>Tool poisoning detection, drift monitoring, typosquatting, hidden instruction scanning (<a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/docs\/specs\/MCP-SECURITY-GATEWAY-1.0.md\">Spec<\/a>)<\/td>\n<\/tr>\n<tr>\n<td><strong>Shadow AI Discovery<\/strong><\/td>\n<td>Find unregistered agents across processes, configs, and repos (<a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/agent-governance-python\/agent-discovery\">Discovery<\/a>)<\/td>\n<\/tr>\n<tr>\n<td><strong>Governance Dashboard<\/strong><\/td>\n<td>Real-time fleet visibility for health, trust, and compliance (<a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/examples\/demos\/governance-dashboard\">Dashboard<\/a>)<\/td>\n<\/tr>\n<tr>\n<td><strong>PromptDefense Evaluator<\/strong><\/td>\n<td>12-vector prompt injection audit (<a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/agent-governance-python\/agent-compliance\/src\/agent_compliance\/prompt_defense.py\">Evaluator<\/a>)<\/td>\n<\/tr>\n<tr>\n<td><strong>Contributor Reputation<\/strong><\/td>\n<td>PR\/issue author screening for social engineering. Reusable GitHub Action (<a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/.github\/actions\/contributor-check\">Action<\/a>)<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><\/markdown-accessiblity-table><\/p>\n<hr\/>\n<p><markdown-accessiblity-table\/><\/p>\n<p dir=\"auto\">All five language SDKs implement core governance (policy, identity, trust, audit). Python has the full stack. Copilot CLI and Claude Code are first-party developer surfaces built on the TypeScript SDK.<br \/>\nSee <strong><a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/docs\/PACKAGE-FEATURE-MATRIX.md\">Language Package Matrix<\/a><\/strong> for detailed per-language coverage.<\/p>\n<details>\n<summary><b>Python distributions (v4.1.0 \u2014 consolidated)<\/b><\/summary>\n<p dir=\"auto\">As of v4.1.0, 45 packages have been consolidated into 5 top-level distributions:<\/p>\n<p><markdown-accessiblity-table><\/p>\n<table>\n<thead>\n<tr>\n<th>Distribution<\/th>\n<th>PyPI<\/th>\n<th>What&#8217;s included<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><code>agent-governance-toolkit-core<\/code><\/td>\n<td><a href=\"https:\/\/pypi.org\/project\/agent-governance-toolkit-core\/\" rel=\"nofollow\"><code>agent-governance-toolkit-core<\/code><\/a><\/td>\n<td>Policy engine, capability model, audit, MCP gateway, zero-trust identity, trust scoring, A2A\/MCP\/IATP bridges<\/td>\n<\/tr>\n<tr>\n<td><code>agent-governance-toolkit-runtime<\/code><\/td>\n<td><a href=\"https:\/\/pypi.org\/project\/agent-governance-toolkit-runtime\/\" rel=\"nofollow\"><code>agent-governance-toolkit-runtime<\/code><\/a><\/td>\n<td>Privilege rings, saga orchestration, termination control, execution plan validation, command denylist enforcement<\/td>\n<\/tr>\n<tr>\n<td><code>agent-governance-toolkit-sre<\/code><\/td>\n<td><a href=\"https:\/\/pypi.org\/project\/agent-governance-toolkit-sre\/\" rel=\"nofollow\"><code>agent-governance-toolkit-sre<\/code><\/a><\/td>\n<td>SLOs, error budgets, chaos engineering, circuit breakers<\/td>\n<\/tr>\n<tr>\n<td><code>agent-governance-toolkit-cli<\/code><\/td>\n<td><a href=\"https:\/\/pypi.org\/project\/agent-governance-toolkit-cli\/\" rel=\"nofollow\"><code>agent-governance-toolkit-cli<\/code><\/a><\/td>\n<td><code>agt<\/code> CLI, OWASP verification, integrity checks, policy linting<\/td>\n<\/tr>\n<tr>\n<td><code>agent-governance-toolkit[full]<\/code><\/td>\n<td><a href=\"https:\/\/pypi.org\/project\/agent-governance-toolkit\/\" rel=\"nofollow\"><code>agent-governance-toolkit<\/code><\/a><\/td>\n<td>Meta-package installing all of the above<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><\/markdown-accessiblity-table><\/p>\n<p dir=\"auto\">Previous package names (<code>agent-os-kernel<\/code>, <code>agentmesh-platform<\/code>, <code>agentmesh-runtime<\/code>, <code>agent-sre<\/code>, <code>agent-discovery<\/code>, <code>agent-hypervisor<\/code>, <code>agentmesh-marketplace<\/code>, <code>agentmesh-lightning<\/code>) remain installable as stub packages that redirect to the consolidated distributions.<\/p>\n<\/details>\n<ul dir=\"auto\">\n<li><strong>Python<\/strong>: 3.10+<\/li>\n<li><strong>Node.js<\/strong>: 18+ \/ npm 9+ (TypeScript SDK)<\/li>\n<li><strong>.NET<\/strong>: 8+<\/li>\n<li><strong>Go<\/strong>: 1.25+<\/li>\n<li><strong>Rust<\/strong>: 1.70+<\/li>\n<li><strong>Optional<\/strong>: <code>AZURE_CLIENT_ID<\/code>, <code>AZURE_TENANT_ID<\/code>, <code>AZURE_CLIENT_SECRET<\/code> for Azure-integrated features<\/li>\n<\/ul>\n<hr\/>\n<p><markdown-accessiblity-table\/><\/p>\n<p dir=\"auto\">Full list: <a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/agent-governance-python\/agentmesh-integrations\">Framework Integrations<\/a> \u00b7 <a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/examples\/quickstart\">Quickstart Examples<\/a><\/p>\n<hr\/>\n<p><markdown-accessiblity-table\/><\/p>\n<hr\/>\n<p dir=\"auto\">Every major component has a formal RFC 2119 specification with conformance tests. These specs define the behavioral contract: what implementations MUST, SHOULD, and MAY do.<\/p>\n<p><markdown-accessiblity-table><\/p>\n<table>\n<thead>\n<tr>\n<th>Specification<\/th>\n<th>Scope<\/th>\n<th>Tests<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/docs\/specs\/AGENT-OS-POLICY-ENGINE-1.0.md\">Agent OS Policy Engine<\/a><\/td>\n<td>Policy evaluation, rule merging, fail-closed semantics<\/td>\n<td>68<\/td>\n<\/tr>\n<tr>\n<td><a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/policy-engine\/spec\/SPECIFICATION.md\">Agent Control Specification<\/a><\/td>\n<td>Stateless intervention-point policy runtime, verdicts, transform, fail-closed<\/td>\n<td>&#8212;<\/td>\n<\/tr>\n<tr>\n<td><a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/docs\/specs\/AGENTMESH-IDENTITY-TRUST-1.0.md\">AgentMesh Identity and Trust<\/a><\/td>\n<td>Credentials, trust scoring, delegation chains<\/td>\n<td>135<\/td>\n<\/tr>\n<tr>\n<td><a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/docs\/specs\/AGENT-HYPERVISOR-EXECUTION-CONTROL-1.0.md\">Agent Hypervisor Execution Control<\/a><\/td>\n<td>Privilege rings, saga orchestration, kill switch<\/td>\n<td>80<\/td>\n<\/tr>\n<tr>\n<td><a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/docs\/specs\/AGENTMESH-TRUST-COORDINATION-1.0.md\">AgentMesh Trust and Coordination<\/a><\/td>\n<td>Peer trust negotiation, mesh-wide policy<\/td>\n<td>62<\/td>\n<\/tr>\n<tr>\n<td><a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/docs\/specs\/AGENT-SRE-GOVERNANCE-1.0.md\">Agent SRE Governance<\/a><\/td>\n<td>SLOs, error budgets, chaos, circuit breakers<\/td>\n<td>111<\/td>\n<\/tr>\n<tr>\n<td><a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/docs\/specs\/MCP-SECURITY-GATEWAY-1.0.md\">MCP Security Gateway<\/a><\/td>\n<td>Tool poisoning, drift detection, hidden instructions<\/td>\n<td>127<\/td>\n<\/tr>\n<tr>\n<td><a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/docs\/specs\/AGENT-LIGHTNING-FAST-PATH-1.0.md\">Agent Lightning Fast-Path<\/a><\/td>\n<td>RL training governance, violation penalties<\/td>\n<td>100<\/td>\n<\/tr>\n<tr>\n<td><a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/docs\/specs\/FRAMEWORK-ADAPTER-CONTRACT-1.0.md\">Framework Adapter Contract<\/a><\/td>\n<td>10 adapter integrations, interceptor chain<\/td>\n<td>152<\/td>\n<\/tr>\n<tr>\n<td><a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/docs\/specs\/AUDIT-COMPLIANCE-1.0.md\">Audit and Compliance<\/a><\/td>\n<td>Merkle audit, compliance mapping, Decision BOM<\/td>\n<td>157<\/td>\n<\/tr>\n<tr>\n<td><a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/docs\/specs\/AGENTMESH-WIRE-1.0.md\">AgentMesh Wire Protocol<\/a><\/td>\n<td>Message format, routing, serialization<\/td>\n<td>&#8212;<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><\/markdown-accessiblity-table><\/p>\n<p dir=\"auto\"><strong>992 conformance tests<\/strong> ensure code stays aligned to specs. <a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/docs\/adr\">29 Architecture Decision Records<\/a> document why.<\/p>\n<hr\/>\n<p><markdown-accessiblity-table><\/p>\n<table>\n<thead>\n<tr>\n<th>Standard<\/th>\n<th>Coverage<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/docs\/compliance\/owasp-agentic-top10-architecture.md\">OWASP Agentic AI Top 10<\/a><\/td>\n<td>All ASI risk categories mapped with deterministic controls<\/td>\n<\/tr>\n<tr>\n<td><a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/docs\/compliance\/nist-ai-rmf-alignment.md\">NIST AI RMF 1.0<\/a><\/td>\n<td>Full GOVERN, MAP, MEASURE, MANAGE alignment<\/td>\n<\/tr>\n<tr>\n<td><a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/docs\/compliance\">EU AI Act<\/a><\/td>\n<td>Compliance mapping with automated evidence<\/td>\n<\/tr>\n<tr>\n<td><a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/docs\/compliance\/soc2-mapping.md\">SOC 2<\/a><\/td>\n<td>Control mapping with audit trail export<\/td>\n<\/tr>\n<tr>\n<td><a href=\"https:\/\/aarm.dev\/builders\/agent-governance-toolkit-microsoft\" rel=\"nofollow\">AARM Extended<\/a><\/td>\n<td>All R1\u2013R9 requirements satisfied; verified Jun 14, 2026<\/td>\n<\/tr>\n<tr>\n<td><a href=\"https:\/\/agentictrustframework.ai\/ecosystem\" rel=\"nofollow\">ATF<\/a><\/td>\n<td>All five elements mapped: Agent Mesh (identity), Agent OS (policy), Agent Compliance (governance), Agent Runtime (sandboxing), Agent SRE (incident response)<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><\/markdown-accessiblity-table><\/p>\n<hr\/>\n<p dir=\"auto\">AGT enforces governance at the application middleware layer, not at the OS kernel level. The policy engine and agents share the same process boundary.<\/p>\n<p dir=\"auto\"><strong>Production recommendation:<\/strong> Run each agent in a separate container for OS-level isolation. See <a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/docs\/ARCHITECTURE.md\">Architecture: Security Boundaries<\/a>.<\/p>\n<p><markdown-accessiblity-table><\/p>\n<table>\n<thead>\n<tr>\n<th>Tool<\/th>\n<th>Coverage<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>CodeQL<\/td>\n<td>Python + TypeScript SAST<\/td>\n<\/tr>\n<tr>\n<td>Gitleaks<\/td>\n<td>Secret scanning on PR\/push\/weekly<\/td>\n<\/tr>\n<tr>\n<td>ClusterFuzzLite<\/td>\n<td>7 fuzz targets (policy, injection, MCP, sandbox, trust)<\/td>\n<\/tr>\n<tr>\n<td>Dependabot<\/td>\n<td>13 ecosystems<\/td>\n<\/tr>\n<tr>\n<td>OpenSSF Scorecard<\/td>\n<td>Weekly scoring + SARIF upload<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><\/markdown-accessiblity-table><\/p>\n<p dir=\"auto\">See <a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/docs\/LIMITATIONS.md\">Known Limitations<\/a> for honest design boundaries and recommended layered defense.<\/p>\n<hr\/>\n<p><markdown-accessiblity-table\/><\/p>\n<hr\/>\n<p dir=\"auto\"><a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/CONTRIBUTING.md\">Contributing Guide<\/a> \u00b7 <a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/docs\/COMMUNITY.md\">Community<\/a> \u00b7 <a href=\"https:\/\/discord.gg\/7aVPCcVh\" rel=\"nofollow\">Discord<\/a> \u00b7 <a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/SECURITY.md\">Security Policy<\/a> \u00b7 <a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/CHANGELOG.md\">Changelog<\/a><\/p>\n<p dir=\"auto\"><strong>Using AGT?<\/strong> Add your organization to <a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/docs\/ADOPTERS.md\">ADOPTERS.md<\/a>.<\/p>\n<p><markdown-accessiblity-table\/><\/p>\n<p dir=\"auto\">If you use the Agent Governance Toolkit to build applications that operate with third-party agent frameworks or services, you do so at your own risk. We recommend reviewing all data being shared with third-party services and being cognizant of third-party practices for retention and location of data.<\/p>\n<p dir=\"auto\">The only official sources for the Agent Governance Toolkit are:<\/p>\n<p><markdown-accessiblity-table\/><\/p>\n<p dir=\"auto\">The project team does not maintain or endorse any third-party websites,<br \/>\npackages, or documentation sites claiming to be official. If you encounter a<br \/>\nsuspicious site or package using the Agent Governance Toolkit name, please<br \/>\nreport it through the channels described in <a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/SECURITY.md\">SECURITY.md<\/a>.<\/p>\n<p dir=\"auto\">This project is licensed under the <a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit\/blob\/main\/LICENSE\">MIT License<\/a>.<\/p>\n<p dir=\"auto\">This project may contain trademarks or logos for projects, products, or services. Authorized use of Microsoft<br \/>\ntrademarks or logos is subject to and must follow<br \/>\n<a href=\"https:\/\/www.microsoft.com\/en-us\/legal\/intellectualproperty\/trademarks\/usage\/general\" rel=\"nofollow\">Microsoft&#8217;s Trademark &amp; Brand Guidelines<\/a>.<br \/>\nUse of Microsoft trademarks or logos in modified versions of this project must not cause confusion or imply Microsoft sponsorship.<br \/>\nAny use of third-party trademarks or logos are subject to those third-party&#8217;s policies.<\/p>\n<\/div>\n<p><a href=\"https:\/\/github.com\/microsoft\/agent-governance-toolkit?utm_source=tldrdevops\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>English | \u65e5\u672c\u8a9e | \u7b80\u4f53\u4e2d\u6587 | \ud55c\uad6d\uc5b4 Ship agents to production without losing sleep Quick Start \u00b7 Specifications \u00b7 PyPI \u00b7 Changelog Important Public Preview &#8212; production-quality public preview releases. May have breaking changes before GA. Policy enforcement, identity, sandboxing, and SRE for autonomous AI agents. One pip install, any framework. Your AI agents call [&hellip;]<\/p>\n","protected":false},"author":16,"featured_media":22834,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[143],"tags":[],"class_list":["post-22833","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ai"],"_links":{"self":[{"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/posts\/22833","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/users\/16"}],"replies":[{"embeddable":true,"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/comments?post=22833"}],"version-history":[{"count":0,"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/posts\/22833\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/media\/22834"}],"wp:attachment":[{"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/media?parent=22833"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/categories?post=22833"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/tags?post=22833"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}