Source: /pages/policy-catalog — c65 iteration: Config column dropped, policy rows expand instead (UxTableListExpandRow with rule, full framework mapping, and the config link inside)
Compliance frameworks
Active frameworks require policies — an unmet requirement is a gap that degrades posture.
8 policies mapped · 5 would need enabling
6 policies mapped · 2 would need enabling
6 policies mapped · 1 would need enabling
10 policies mapped · 4 would need enabling
2 policies mapped · 0 would need enabling
10 policies mapped · 4 would need enabling
8 policies mapped · 3 would need enabling
7 policies mapped · 4 would need enabling
5 policies mapped · 2 would need enabling
Security posture
68%
across active frameworks
Active frameworks
3 / 12
toggled globally, org-wide
Active policies
10 / 17
pre-defined, individually configured
Open gaps
6
required by an active framework, off
Policies
Activate with the toggle; expand a row for the definition and its config.
| Description | Active Compliance Frameworks Requiring this Policy | |
|---|---|---|
| Identity & Access2 of 3 active | ||
Agents must be registered and monitored before they run. | ||
Agents run under org-issued identity, not personal accounts or static keys. | ||
Agents may not execute with root or admin privileges. | ||
| Action & Autonomy2 of 4 active | ||
Consequential tool calls require a human approval before agents proceed. | ||
Agents may only invoke tools on the approved list. | ||
Agents may only connect to approved MCP servers. | 3 mapped frameworks — none active | |
Agent code execution is confined to a sandbox at or above the required level. | ||
| Data Protection3 of 4 active | ||
Secrets and credential files stay out of model context. | ||
Sensitive content is detected and redacted in prompts and responses. | ||
Agent traffic may only reach approved destinations. | ||
Connections below the TLS baseline are refused. | ||
| Input & Output Integrity0 of 3 active | ||
Inbound prompts are scanned for injection patterns — detect & contain. | ||
Agent output is checked before it reaches downstream tools. | ||
Models and tools must match pinned, verified sources. | ||
| Cost & Consumption3 of 3 active | ||
Fleet and per-agent spend stays under explicit ceilings. | ||
Agents respect provider quotas instead of burning through them. | ||
No agent operates below the minimum security-posture score. | ||
Need something narrower than these? The flexible engine is still there — custom controls →