Practical guides for the teams who find, govern and secure AI agents. Short sections, tables and templates, no filler.
Each guide shows where an AI agent allow list fits: checking the page type of every URL an agent tries to open.
You cannot secure agents you have not found. Start by finding them, recording them and scoring their risk.
The seven places agents hide and what to record for each.
DiscoveryTool types, how to test one, and a do-it-yourself method.
Template23 fields per agent, with a free CSV template and JSON Schema.
ToolA ten-question scoring tool and the controls each score needs.
Who each agent is, what it holds, and what it may do at the moment it asks.
Rules written as files, checked before every request, and organised into a framework you can grow.
One versioned file per agent, tested and enforced.
DownloadsSix ready-to-use policies with the reasoning.
Examples24 rules across six layers.
FrameworkLayers, lifecycle and a five-level maturity model.
EgressWhat it must block, and a free open-source one.
What goes wrong with agents, rated and paired with the control for each risk.
12 risks in six families, with a priority order.
AutonomyWhat changes when nobody watches.
Multi-agentTen risks when agents talk to agents.
BrowsersTwelve risks rated by likelihood and impact.
ContainmentFive ways agents get out, and how to stop it.
Controls for the agents most companies already have: browser agents, coding agents and chat assistants in agent mode.
What to do in the first hour, and what past cases teach.
Each tool is free to use. The policy files work with our open-source egress guard.
28 page types, including 8 action types, on 40M+ domains.