Write one web policy per agent: which page types it may open, which domains it may never touch, and the few exceptions it needs.
Download the file and enforce it with the free Agent Egress Guard, or any gateway that reads an AI agent allow list.
Every agent needs a name, one owner and a review date.
Click to toggle. Leave all off to allow every read page type.
One page type on one domain, with an end date. Keep this list short.
Enforce it: agent-egress-guard policy check vendor-research.json URL
| Field | Effect on a request |
|---|---|
| deny_domains | Denied first, whatever the page. Use for competitors or sites your contracts forbid. |
| exceptions | Lets one normally denied page type through on one domain until the end date, optionally only with owner approval. |
| on_deny | "ask_owner" turns a denial into approval_required, so a person can decide. High-risk hosts are never routed to an owner. |
| allow_page_types | Read pages of other types are denied for this agent. Empty means every read type is allowed. |
| deny_page_types | Extra read page types this agent may not open, such as careers. |
| unclassified | "deny" blocks URLs no layer can classify, unless the domain is on allow_domains. |
| review_by, owner | Not enforced per request. Validation warns when the review is overdue or the owner is missing. |
The baseline always applies first: the high-risk host list, the page-type database, the URL rules and default-deny for unknown writes. The agent policy then tightens it, or opens one narrow exception.
No web tools, so no web policy is needed. Keep a register entry anyway.
Allow only the page types the workflow uses. Allow reads on unclassified pages only if the workflow needs them.
Allow read types by purpose, deny unclassified, and ask the owner on every denial.
Same as tier 3 but block instead of asking. Nobody is there to approve in real time.
AgentPolicy.load("policy.json").check(Guard(), url) returns allow, deny or approval_required.
agent-egress-guard policy validate and policy check for reviews and tests.
The format is plain JSON. Read it in any language and apply the same order of checks.
Add the page-type database with an API key for verified login, signup and checkout URLs on 40M+ domains. See pricing or the free sample.
Wiki edits, plugin installs, WebDAV folders and dataset uploads were all action pages or unknown writes. A tier 3 or 4 policy from this builder denies them. In our replay, page data plus egress rules would have stopped almost all of the incidents.
Check the incident-by-incident analysis