{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","download":{"releaseId":"sha256:b02741cf77f111c9d5a16e847a45acf672e5b25cbe8a0511ebdabe8a4cf69f61","slug":"controls-ai-guardrail-configuration-agent-permission-review","url":"/assets/agent_workflow-controls-ai-guardrail-configuration-agent-permission-review-1f84bb47.167731d707cd3a85.json"},"kind":"record","record":{"attributes":{"department":"ai-governance","domain":"controls","lineOfDefense":"operate"},"canonicalUrl":"https://workflow-library.com/all/?w=controls-ai-guardrail-configuration-agent-permission-review","description":"Each monthly or release-triggered instance runs against the existing Control item for AI guardrail configuration and agent permission review (framework aiuc-1 + iso-42001 + eu-ai-act; frequency monthly and per release; control_owner AI Platform Security Lead) — the run enriches that Control's execution history and is its evidence of operation, never a duplicate. The decision-aware cycle confirms the in-scope agent population and baseline; reviews input defenses and endpoint limits, tool allow-lists, permissions and sandboxing, output filters and grounding, misuse refusals, secrets redaction, and secure-code-generation defaults; decides on agent permission scope and on guardrail drift with a remediation branch for each; and consolidates the results into a signed guardrail attestation with cycle metrics and owned actions, booking every residual gap as an Issue (source: management_identified) linked to the anchor Control. In scope: every production AI agent and inference endpoint, its guardrail configuration, tool-call and detection logs, and configuration artifacts. Out of scope: model development, pre-deployment evaluation, and vendor AI due diligence, which have their own workflows. The cycle hands off only to its next instance through the carry-forward Issues that the guardrail attestation step links to the anchor Control.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=controls-ai-guardrail-configuration-agent-permission-review","capabilities":[],"controls":["UC-AI-18","UC-AI-19","UC-AI-20","UC-AI-22","UC-AI-23","UC-AI-25"],"domains":["controls"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:b02741cf77f111c9d5a16e847a45acf672e5b25cbe8a0511ebdabe8a4cf69f61","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:controls-ai-guardrail-configuration-agent-permission-review","standards":["nist-ai-agent-identity","aiuc-1","iso-42001","eu-ai-act"],"teams":["ai-governance","it"]},"id":"wf:C66","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AC66","slug":"controls-ai-guardrail-configuration-agent-permission-review","sourceIds":["aiuc-1","nist-ai-agent-identity","nist-ai-tevv-athlon"],"sourceUrl":null,"title":"AI Guardrail Configuration & Agent Permission Review","type":"workflow"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:029d8c79169be792280d624dfabf7a1ec75b52d06294e2823de1993b005400c3","properties":{},"sourceDetailPath":"/data/v1/records/wf-c66-26a4ed19.json","sourceId":"wf:C66","targetDetailPath":"/data/v1/records/uc-uc-ai-22-129d1e22.json","targetId":"uc:UC-AI-22","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:58858e6d493365797505b5dbbc04aef4191da40e2a28f8e44897a597242ed89d","properties":{},"sourceDetailPath":"/data/v1/records/wf-c66-26a4ed19.json","sourceId":"wf:C66","targetDetailPath":"/data/v1/records/uc-uc-ai-20-c0e507ce.json","targetId":"uc:UC-AI-20","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5dc3789e10cc1ea60882e166959040d5d271f5f4aa78e439993e91908cec1678","properties":{},"sourceDetailPath":"/data/v1/records/wf-c66-26a4ed19.json","sourceId":"wf:C66","targetDetailPath":"/data/v1/records/uc-uc-ai-25-21e48906.json","targetId":"uc:UC-AI-25","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b67363d1eab7d9334d77751d70370e4875459d72553bc43f9caec1bb61ce08e5","properties":{},"sourceDetailPath":"/data/v1/records/wf-c66-26a4ed19.json","sourceId":"wf:C66","targetDetailPath":"/data/v1/records/uc-uc-ai-23-ea85f10d.json","targetId":"uc:UC-AI-23","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:dd6e424d14cc32172c325fc0c83ce251db91de1d64582e194ee680e4e84c4f96","properties":{},"sourceDetailPath":"/data/v1/records/wf-c66-26a4ed19.json","sourceId":"wf:C66","targetDetailPath":"/data/v1/records/uc-uc-ai-18-f15ac93a.json","targetId":"uc:UC-AI-18","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f11caf1f1bb12d16344326dccd7d4afb8595b36f64912f7c5fe131c6fb44116e","properties":{},"sourceDetailPath":"/data/v1/records/wf-c66-26a4ed19.json","sourceId":"wf:C66","targetDetailPath":"/data/v1/records/uc-uc-ai-19-535f3660.json","targetId":"uc:UC-AI-19","type":"operates"}],"schemaVersion":1}
