AI Agent Allowlist
Home Page-Types Database Agent Guardrails 2026 Incidents API Docs Pricing
Resources
Use Cases (15) Industries & Buyers (12) Learn: Core Concepts (12) Implementation Guides (15) Comparisons (8) Schema & Data Reference (6) FAQ Glossary
Why It Matters
2026 Agent Incidents Category Targeting Database Refreshes Contact Customer Login
Download Free Sample
free tool, runs in your browser, nothing is sent anywhere

AI Agent Policy Builder

Write one web policy per agent: which page types it may open, which domains it may never touch, and the few exceptions it needs.

Download the file and enforce it with the free Agent Egress Guard, or any gateway that reads an AI agent allow list.

1. The agent

Every agent needs a name, one owner and a review date.

2. Read pages it may open

Click to toggle. Leave all off to allow every read page type.

3. Domains and unknown sites

4. Exceptions

One page type on one domain, with an end date. Keep this list short.

Your policy file


          

Enforce it: agent-egress-guard policy check vendor-research.json URL

How the file is enforced

What each field does at request time

FieldEffect on a request
deny_domainsDenied first, whatever the page. Use for competitors or sites your contracts forbid.
exceptionsLets one normally denied page type through on one domain until the end date, optionally only with owner approval.
on_deny"ask_owner" turns a denial into approval_required, so a person can decide. High-risk hosts are never routed to an owner.
allow_page_typesRead pages of other types are denied for this agent. Empty means every read type is allowed.
deny_page_typesExtra read page types this agent may not open, such as careers.
unclassified"deny" blocks URLs no layer can classify, unless the domain is on allow_domains.
review_by, ownerNot enforced per request. Validation warns when the review is overdue or the owner is missing.

The baseline always applies first: the high-risk host list, the page-type database, the URL rules and default-deny for unknown writes. The agent policy then tightens it, or opens one narrow exception.

Good defaults

Starting points by agency tier

Tier 1: answers only

No web tools, so no web policy is needed. Keep a register entry anyway.

Tier 2: fixed workflow

Allow only the page types the workflow uses. Allow reads on unclassified pages only if the workflow needs them.

Tier 3: plans with approval

Allow read types by purpose, deny unclassified, and ask the owner on every denial.

Tier 4: acts on its own

Same as tier 3 but block instead of asking. Nobody is there to approve in real time.

Enforcing it

Three ways to use the file

In Python

AgentPolicy.load("policy.json").check(Guard(), url) returns allow, deny or approval_required.

From the command line

agent-egress-guard policy validate and policy check for reviews and tests.

In your own gateway

The format is plain JSON. Read it in any language and apply the same order of checks.

Add the page-type database with an API key for verified login, signup and checkout URLs on 40M+ domains. See pricing or the free sample.

Would this policy have stopped the 2026 agent incidents?

Wiki edits, plugin installs, WebDAV folders and dataset uploads were all action pages or unknown writes. A tier 3 or 4 policy from this builder denies them. In our replay, page data plus egress rules would have stopped almost all of the incidents.

Check the incident-by-incident analysis
FAQ

Policy builder questions

Is anything I type sent to a server?
No. The builder runs entirely in your browser. The policy only leaves your machine when you copy or download it.
Why can't I allow checkout or signup as a page type?
Action pages should never be open for every site. Grant them through an exception for one domain with an end date, so the permission stays narrow and reviewable.
What enforces the file?
The free Agent Egress Guard (version 0.2.0 or later) reads it directly. The format is plain JSON, so any gateway or proxy can apply it too.
Does it know which URLs are login or checkout pages?
The free edition recognises common login, signup and password reset URL patterns. Verified page URLs for 40M+ domains come from the page-type database, added with an API key.