AI Agent Governance Policy
Master governance policy covering agent deployment approval, decision authority levels, monitoring requirements, and incident escalation procedures.
Agent Autonomy Levels Policy
Defines four autonomy tiers (supervised, semi-autonomous, autonomous, restricted) with decision thresholds, review requirements, and override procedures for each tier.
Agent Data Access Policy
Governs what data agents may read, write, and retain. Includes PII handling rules, data minimisation requirements, and retention schedules for agent-generated outputs.
AI Agent Acceptable Use Policy
Defines permitted and prohibited use cases for AI agents across the organisation. Includes department-specific carve-outs and a rapid exception request process.
AI Agent Pre-Deployment Audit
27-point checklist for launching a new AI agent into production. Covers data access review, escalation path testing, confidence threshold validation, and rollback plan verification.
Quarterly Agent Governance Review
Structured quarterly review template covering override rate trends, INTERRUPT frequency by agent, decision drift indicators, and retraining trigger evaluation.
ISMS Agent Integration Audit
ISO 27001 Annex A controls checklist for AI agent integration into information security management systems. Maps directly to control domains A.8, A.9, A.12.
NIST AI RMF Readiness Assessment
Self-assessment checklist mapping Agent OS governance events to NIST AI RMF Core Functions: Govern, Map, Measure, Manage. Produces a readiness score across 4 dimensions.
INTERRUPT Escalation Matrix
Defines who receives INTERRUPT events by severity level (low/medium/high/critical), SLA for response, what happens on timeout, and how the outcome is documented.
Confidence Threshold Policy
Defines mandatory INTERRUPT thresholds by agent type and action category. Includes rationale for each threshold, override procedure for temporary adjustment, and review schedule.
Human-in-the-Loop Decision Authority
Role-based INTERRUPT response authority matrix. Maps decision types to minimum seniority level required to approve, deny, or redirect. Includes delegation procedures for OOO scenarios.
Override Pattern Review Process
Weekly override analysis workflow — how to identify systematic patterns in OVERRIDE events, classify root causes (prompt/data/threshold/policy), and trigger retraining or policy updates.
Critical Override Escalation Procedure
Immediate response procedure for severity:critical OVERRIDE events. Who is notified, what investigation is required within 24h, and how findings feed into the corrective action register.
Agent Runaway Action Playbook
Step-by-step response to an agent taking unintended high-volume or high-impact actions (e.g. sending 10,000 emails, bulk-deleting records). Includes immediate containment, stakeholder notification, and post-incident review.
Agent Data Exfiltration Response
Incident response for suspected unauthorised data access by an agent. Evidence preservation, access revocation sequence, breach notification assessment, and regulatory reporting checklist.
Agent Bias / Discrimination Incident
Response playbook for discovering systematic discriminatory outputs from an AI agent. Investigation methodology, stakeholder communication templates, and remediation documentation.
AI Vendor Governance Assessment
Security and governance questionnaire for evaluating AI agent vendors. 35 questions covering data handling, audit trail quality, override capabilities, SLA commitments, and incident response SLAs.