workflow
AI Guardrail Configuration & Agent Permission Review
Each monthly or release-triggered instance runs against the existing Control item for AI guardrail configuration and agent permission review (framework aiuc-1 + iso-42001 + eu-ai-act; frequency monthly and per release; control_owner AI Platform Security Lead) — the run enriches that Control's execution history and is its evidence of operation, never a duplicate. The decision-aware cycle confirms the in-scope agent population and baseline; reviews input defenses and endpoint limits, tool allow-lists, permissions and sandboxing, output filters and grounding, misuse refusals, secrets redaction, and secure-code-generation defaults; decides on agent permission scope and on guardrail drift with a remediation branch for each; and consolidates the results into a signed guardrail attestation with cycle metrics and owned actions, booking every residual gap as an Issue (source: management_identified) linked to the anchor Control. In scope: every production AI agent and inference endpoint, its guardrail configuration, tool-call and detection logs, and configuration artifacts. Out of scope: model development, pre-deployment evaluation, and vendor AI due diligence, which have their own workflows. The cycle hands off only to its next instance through the carry-forward Issues that the guardrail attestation step links to the anchor Control.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- controls
- department
- ai-governance
- lineOfDefense
- operate
Details
- teams
- ai-governance
- it
- domains
- controls
- standards
- nist-ai-agent-identity
- aiuc-1
- iso-42001
- eu-ai-act
- sourceTemplateId
- workflow-library:controls-ai-guardrail-configuration-agent-permission-review
- releaseId
- sha256:b02741cf77f111c9d5a16e847a45acf672e5b25cbe8a0511ebdabe8a4cf69f61
- canonicalUrl
- https://workflow-library.com/all/?w=controls-ai-guardrail-configuration-agent-permission-review
- capabilities
- mappingStatus
- mapped
- lineOfDefense
- operate
- controls
- UC-AI-18
- UC-AI-19
- UC-AI-20
- UC-AI-22
- UC-AI-23
- UC-AI-25
- roleIntegrity
- activityCount
- 0
- ermPhases
- lineRoles
- serviceModes
- warnings
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:b02741cf77f111c9d5a16e847a45acf672e5b25cbe8a0511ebdabe8a4cf69f61
Connections
- AI Guardrail Configuration & Agent Permission Review operates UC-AI-22 — Prevent leakage of credentials and secrets through AI systems
- AI Guardrail Configuration & Agent Permission Review operates UC-AI-20 — Prevent harmful, out-of-scope, hallucinated, and over-exposed AI outputs
- AI Guardrail Configuration & Agent Permission Review operates UC-AI-25 — Guide code-generating systems toward secure patterns and safe dependencies
- AI Guardrail Configuration & Agent Permission Review operates UC-AI-23 — Prevent misuse of AI systems for cyber offense and catastrophic harm
- AI Guardrail Configuration & Agent Permission Review operates UC-AI-18 — Defend AI interfaces against adversarial input, injection, and endpoint abuse
- AI Guardrail Configuration & Agent Permission Review operates UC-AI-19 — Constrain agent actions and tool use to authorized scope