workflow

AI Guardrail Configuration & Agent Permission Review

Each monthly or release-triggered instance runs against the existing Control item for AI guardrail configuration and agent permission review (framework aiuc-1 + iso-42001 + eu-ai-act; frequency monthly and per release; control_owner AI Platform Security Lead) — the run enriches that Control's execution history and is its evidence of operation, never a duplicate. The decision-aware cycle confirms the in-scope agent population and baseline; reviews input defenses and endpoint limits, tool allow-lists, permissions and sandboxing, output filters and grounding, misuse refusals, secrets redaction, and secure-code-generation defaults; decides on agent permission scope and on guardrail drift with a remediation branch for each; and consolidates the results into a signed guardrail attestation with cycle metrics and owned actions, booking every residual gap as an Issue (source: management_identified) linked to the anchor Control. In scope: every production AI agent and inference endpoint, its guardrail configuration, tool-call and detection logs, and configuration artifacts. Out of scope: model development, pre-deployment evaluation, and vendor AI due diligence, which have their own workflows. The cycle hands off only to its next instance through the carry-forward Issues that the guardrail attestation step links to the anchor Control.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
controls
department
ai-governance
lineOfDefense
operate

Details

teams
  • ai-governance
  • it
domains
  • controls
standards
  • nist-ai-agent-identity
  • aiuc-1
  • iso-42001
  • eu-ai-act
sourceTemplateId
workflow-library:controls-ai-guardrail-configuration-agent-permission-review
releaseId
sha256:b02741cf77f111c9d5a16e847a45acf672e5b25cbe8a0511ebdabe8a4cf69f61
canonicalUrl
https://workflow-library.com/all/?w=controls-ai-guardrail-configuration-agent-permission-review
capabilities
    mappingStatus
    mapped
    lineOfDefense
    operate
    controls
    • UC-AI-18
    • UC-AI-19
    • UC-AI-20
    • UC-AI-22
    • UC-AI-23
    • UC-AI-25
    roleIntegrity
    activityCount
    0
    ermPhases
      lineRoles
        serviceModes
          warnings

            Source

            No record-specific source URL is provided.

            Download workflow template · Release: sha256:b02741cf77f111c9d5a16e847a45acf672e5b25cbe8a0511ebdabe8a4cf69f61

            Connections