Source: /pages/policy-catalog-v2 — c65 iteration: the config controls live directly in the expand row (shape components inline; no separate config pages needed to configure)
Compliance frameworks
Active frameworks require policies — an unmet requirement is a gap that degrades posture.
Control Policies
Activate with the toggle; expand a row to configure in place.
| Description | Active Compliance Frameworks Requiring this Policy | |
|---|---|---|
| Identity & Access2 of 3 active | ||
Agents must be registered and monitored before they run. | ||
Agents run under org-issued identity, not personal accounts or static keys. | ||
Agents may not execute with root or admin privileges. | ||
| Action & Autonomy2 of 4 active | ||
Consequential tool calls require a human approval before agents proceed. | ||
Agents may only invoke tools on the approved list. | ||
Agents may only connect to approved MCP servers. | 3 mapped frameworks — none active | |
Agent code execution is confined to a sandbox at or above the required level. | ||
| Data Protection3 of 4 active | ||
Secrets and credential files stay out of model context. | ||
Sensitive content is detected and redacted in prompts and responses. | ||
Agent traffic may only reach approved destinations. | ||
Connections below the TLS baseline are refused. | ||
| Input & Output Integrity0 of 3 active | ||
Inbound prompts are scanned for injection patterns — detect & contain. | ||
Agent output is checked before it reaches downstream tools. | ||
Models and tools must match pinned, verified sources. | ||
| Cost & Consumption3 of 3 active | ||
Fleet and per-agent spend stays under explicit ceilings. | ||
Agents respect provider quotas instead of burning through them. | ||
No agent operates below the minimum security-posture score. | ||
Need something narrower than these? The flexible engine is still there — custom controls →