{"catalogRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","download":{"releaseId":"sha256:3a89e1b959ff36eb4d88a3c238a911a75a789053c93daa6a50a10dd3f0ca2a4f","slug":"controls-ai-guardrail-configuration-agent-permission-review","url":"/controls/assets/agent_workflow-controls-ai-guardrail-configuration-agent-permission-review-1f84bb47.d13a7276430e1c5f.json"},"kind":"record","record":{"attributes":{"department":"ai-governance","domain":"controls","lineOfDefense":"operate"},"canonicalUrl":"https://assureswarm.com/workflows/all/?w=controls-ai-guardrail-configuration-agent-permission-review","description":"Each monthly or release-triggered instance runs against the existing Control item for AI guardrail configuration and agent permission review (framework aiuc-1 + iso-42001 + eu-ai-act; frequency monthly and per release; control_owner AI Platform Security Lead) — the run enriches that Control's execution history and is its evidence of operation, never a duplicate. The decision-aware cycle confirms the in-scope agent population and baseline; reviews input defenses and endpoint limits, tool allow-lists, permissions and sandboxing, output filters and grounding, misuse refusals, secrets redaction, and secure-code-generation defaults; decides on agent permission scope and on guardrail drift with a remediation branch for each; and consolidates the results into a signed guardrail attestation with cycle metrics and owned actions, booking every residual gap as an Issue (source: management_identified) linked to the anchor Control. In scope: every production AI agent and inference endpoint, its guardrail configuration, tool-call and detection logs, and configuration artifacts. Out of scope: model development, pre-deployment evaluation, and vendor AI due diligence, which have their own workflows. The cycle hands off only to its next instance through the carry-forward Issues that the guardrail attestation step links to the anchor Control.","details":{"canonicalUrl":"https://assureswarm.com/workflows/all/?w=controls-ai-guardrail-configuration-agent-permission-review","capabilities":[],"controls":["UC-AI-18","UC-AI-19","UC-AI-20","UC-AI-22","UC-AI-23","UC-AI-25"],"domains":["controls"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:3a89e1b959ff36eb4d88a3c238a911a75a789053c93daa6a50a10dd3f0ca2a4f","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:controls-ai-guardrail-configuration-agent-permission-review","standards":["nist-ai-agent-identity","aiuc-1","iso-42001","eu-ai-act"],"teams":["ai-governance","it"]},"id":"wf:C66","mapUrl":"https://assureswarm.com/controls/?v=1&node=wf%3AC66","slug":"controls-ai-guardrail-configuration-agent-permission-review","sourceIds":["aiuc-1","nist-ai-agent-identity","nist-ai-tevv-athlon"],"sourceUrl":null,"title":"AI Guardrail Configuration & Agent Permission Review","type":"workflow"},"relationships":[{"expectedCatalogRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","id":"rel:029d8c79169be792280d624dfabf7a1ec75b52d06294e2823de1993b005400c3","properties":{},"sourceDetailPath":"/controls/data/v1/records/wf-c66-26a4ed19.json","sourceId":"wf:C66","targetDetailPath":"/controls/data/v1/records/uc-uc-ai-22-129d1e22.json","targetId":"uc:UC-AI-22","type":"operates"},{"expectedCatalogRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","id":"rel:58858e6d493365797505b5dbbc04aef4191da40e2a28f8e44897a597242ed89d","properties":{},"sourceDetailPath":"/controls/data/v1/records/wf-c66-26a4ed19.json","sourceId":"wf:C66","targetDetailPath":"/controls/data/v1/records/uc-uc-ai-20-c0e507ce.json","targetId":"uc:UC-AI-20","type":"operates"},{"expectedCatalogRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","id":"rel:5dc3789e10cc1ea60882e166959040d5d271f5f4aa78e439993e91908cec1678","properties":{},"sourceDetailPath":"/controls/data/v1/records/wf-c66-26a4ed19.json","sourceId":"wf:C66","targetDetailPath":"/controls/data/v1/records/uc-uc-ai-25-21e48906.json","targetId":"uc:UC-AI-25","type":"operates"},{"expectedCatalogRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","id":"rel:b67363d1eab7d9334d77751d70370e4875459d72553bc43f9caec1bb61ce08e5","properties":{},"sourceDetailPath":"/controls/data/v1/records/wf-c66-26a4ed19.json","sourceId":"wf:C66","targetDetailPath":"/controls/data/v1/records/uc-uc-ai-23-ea85f10d.json","targetId":"uc:UC-AI-23","type":"operates"},{"expectedCatalogRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","id":"rel:dd6e424d14cc32172c325fc0c83ce251db91de1d64582e194ee680e4e84c4f96","properties":{},"sourceDetailPath":"/controls/data/v1/records/wf-c66-26a4ed19.json","sourceId":"wf:C66","targetDetailPath":"/controls/data/v1/records/uc-uc-ai-18-f15ac93a.json","targetId":"uc:UC-AI-18","type":"operates"},{"expectedCatalogRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","id":"rel:f11caf1f1bb12d16344326dccd7d4afb8595b36f64912f7c5fe131c6fb44116e","properties":{},"sourceDetailPath":"/controls/data/v1/records/wf-c66-26a4ed19.json","sourceId":"wf:C66","targetDetailPath":"/controls/data/v1/records/uc-uc-ai-19-535f3660.json","targetId":"uc:UC-AI-19","type":"operates"}],"schemaVersion":1}
