
Agent Governance Toolkit
ツールを方針で包み、呼び出しのたびに照合・記録し、規則に反すれば理由を付けて拒否する
Agent Governance Toolkitとは
エージェントが持つ権限は、渡した認証情報が持つ権限であって、本来許してよい範囲とはほとんど一致しません。表を読める鍵はたいてい表を消せます。このツールキットは、その差を呼び出しの地点で埋めます。規則はYAMLで書きます。破壊的な操作は拒否する、メール送信は指定した担当者の承認を必須にする、といった内容です。ツールの関数を包めば、呼び出しのたびに規則が評価され、監査記録に残り、規則に触れる場合は理由を添えて拒否されます。あわせて、ある操作をどのエージェントが行ったかを特定するための識別の仕組みと、自分のプロセスで動かしたくないツールのための隔離実行が用意されています。公開プレビュー段階で、パッケージ構成はすでに一度変わっています。
Agent Governance Toolkitで何ができますか?
- 既存のツールを2行で統制下に置く — 手元の関数を包み、方針ファイルを渡すだけです。呼び出し側のコードも、周りのエージェントフレームワークも変わりません。
- 規則をコードではなくファイルで書く — 方針は条件と結果を並べたYAMLです。エージェントに何を許すかを、エージェント自体を配置し直さずに確認・版管理・変更できます。
- 危険な操作だけ人を挟む — 指定した担当者の承認を得るまで処理を進めない規則を書けます。監査記録が残るだけの状態と、実際に止められる状態の違いはここです。
- どのエージェントが行ったかを残す — 操作は共有のサービスアカウントではなく個々のエージェントの識別子に結び付きます。後から監査記録で追跡できます。
- 理由を付けて拒否する — 遮断された呼び出しは、どの規則が止めたかを示す例外になります。黙って空の結果が返るのと違い、原因を追えます。
- Python以外からも使う — 同じ統制がTypeScriptと.NET向けにも公開され、Claude Code用のプラグインもあります。言語が混在した環境を1組の方針で覆えます。
Agent Governance Toolkitを選ぶ前に
- 公開プレビューとして提供されており、正式版までに非互換の変更があり得ると明記されています。版を固定し、更新前に変更履歴を確認してください。
- パッケージ構成はすでに一度整理されています。既定の導入では準拠確認のコマンドのみが入り、統制の本体は追加指定が必要で、旧来の読み込み経路は非推奨かつ移行は一方向です。
よくある質問
Agent Governance Toolkitは商用利用できますか?
Agent Governance ToolkitはMITライセンスで公開されています。OSI承認のオープンソースライセンスで、商用利用が認められています。
Agent Governance Toolkitはどの形で使えますか?
Agent Governance Toolkitはセルフホスト・ローカル実行の形で利用できます。
ドキュメント
microsoft/agent-governance-toolkit のREADMEより転載(MIT)。 原文を読む ↗
Agent Governance Toolkit
Ship agents to production without losing sleep
[!IMPORTANT] Public Preview — production-quality public preview releases. May have breaking changes before GA.
Policy enforcement, identity, sandboxing, and SRE for autonomous AI agents. One pip install, any framework.
The Problem
Your AI agents call tools, browse the web, query databases, and delegate to other agents. Once deployed, they make decisions autonomously. You need answers to three questions:
1. Is this action allowed? An agent with access to send_email and query_database should not be able to drop_table. OAuth scopes and IAM roles control which services an agent can reach, not what it does once connected.
2. Which agent did this? In a multi-agent system, five agents might share a single API key. When something goes wrong, “an agent did it” is not an incident response.
3. Can you prove what happened? Auditors and regulators need tamper-evident records of every decision: what policy was active, what the agent requested, and why it was allowed or denied.
Prompt-level safety (“please follow the rules”) is not a control surface. It is a polite request to a stochastic system. OWASP LLM01:2025 states this explicitly: “it is unclear if there are fool-proof methods of prevention for prompt injection.” The published numbers back this up. Andriushchenko et al. (ICLR 2025) report 100% attack success rate on GPT-4o, GPT-3.5, Claude 3, and Llama-3 using adaptive attacks with logprob access and suffix optimization, evaluated against the JailbreakBench benchmark (Chao et al., NeurIPS 2024). Microsoft’s own AI Red Teaming Agent formalizes Attack Success Rate (ASR), the rate of policy violations under adversarial input, as the canonical metric for this class of failure. Lessons from Red Teaming 100 Generative AI Products reinforces the point: “mitigations do not eliminate risk entirely” and red teaming must be a continuous process because model-layer defenses are probabilistic by construction.
AGT does not try to win that fight inside the prompt. Every tool call, message send, and delegation is intercepted in deterministic application code before the model’s intent reaches the wire. Actions the AGT kernel denies are not “unlikely.” They are structurally impossible. That is the difference between asking an agent to behave and making it incapable of misbehaving.
Quick Start
Prerequisites: Python 3.11+
pip install "agent-governance-toolkit[full]"
Use the [full] extra for the quick-start imports below. The base
agent-governance-toolkit wheel installs the compliance CLI only; the governance
modules live in the consolidated core distribution. The agentmesh quick-start
import remains the current wrapper API. Importing agent_os emits a
DeprecationWarning because the old agent-os-kernel distribution is deprecated.
Use agent-governance-toolkit-core (or the [full] extra that includes it) as
the replacement distribution. Policy-engine host code uses the ACS SDK;
agt-policies provides the one-way v4-to-v5 migration command. The pre-ACS
agent_os.policies rule model is gone, and BREAKING_CHANGES.md lists its
replacements.
For Claude Code, add AGT as a plugin marketplace and install the governance plugin:
/plugin marketplace add microsoft/agent-governance-toolkit
/plugin install agt-governance@agent-governance-toolkit
Govern any tool function in two lines:
from agentmesh.governance import govern
safe_tool = govern(my_tool, policy="policy.yaml") # every call checked, logged, enforced
On every call, safe_tool evaluates the YAML policy, logs the decision to an
audit trail, and raises GovernanceDenied when the policy blocks the action.
# policy.yaml
apiVersion: governance.toolkit/v1
name: production-policy
default_action: allow
rules:
- name: block-destructive
condition: "action.type in ['drop', 'delete', 'truncate']"
action: deny
description: "Destructive operations require human approval"
- name: require-approval-for-send
condition: "action.type == 'send_email'"
action: require_approval
approvers: ["security-team"]
>>> safe_tool(action="read", table="users")
{'table': 'users', 'rows': 42}
>>> safe_tool(action="drop", table="users")
GovernanceDenied: Action denied by policy rule 'block-destructive':
Destructive operations require human approval
Or use the full AgentControl API for programmatic control:
from agent_control_specification import AgentControl
runtime = AgentControl.from_path(str("manifest.yaml"))
result = runtime.evaluate(
"input",
{
"envelope": {"agent_id": "example-agent"},
"input": {"body": {"action": "web_search", "params": {}}},
},
)
print(result.verdict)
runtime.close()
Run the complete ACS email-tool example.
TypeScript
import { PolicyEngine } from "@microsoft/agent-governance-sdk";
const engine = new PolicyEngine([
{ action: "web_search", effect: "allow" },
{ action: "shell_exec", effect: "deny" },
]);
engine.evaluate("web_search"); // "allow"
engine.evaluate("shell_exec"); // "deny"
.NET
using AgentGovernance;
using AgentGovernance.Extensions.ModelContextProtocol;
using AgentGovernance.Policy;
var kernel = new GovernanceKernel(new GovernanceOptions
{
PolicyPaths = new() { "policies/default.yaml" },
});
var result = kernel.EvaluateToolCall("did:mesh:agent-1", "web_search",
new() { ["query"] = "latest AI news" });
// MCP server integration
builder.Services.AddMcpServer()
.WithGovernance(options => options.PolicyPaths.Add("policies/mcp.yaml"));
Rust
use agent_governance::{AgentMeshClient, ClientOptions};
let client = AgentMeshClient::new("my-agent").unwrap();
let result = client.execute_with_governance("data.read", None);
assert!(result.allowed);
Go
import agentmesh "github.com/microsoft/agent-governance-toolkit/agent-governance-golang"
client, _ := agentmesh.NewClient("my-agent",
agentmesh.WithPolicyRules([]agentmesh.PolicyRule{
{Action: "data.read", Effect: agentmesh.Allow},
{Action: "*", Effect: agentmesh.Deny},
}),
)
result := client.ExecuteWithGovernance("data.read", nil)
CLI tools:
agt doctor # check installation
agt verify # OWASP compliance check
agt verify --evidence ./agt-evidence.json --strict # fail CI on weak evidence
agt red-team scan ./prompts/ --min-grade B # prompt injection audit
agt lint-policy policies/ # validate policy files
Full walkthrough: quickstart.md — zero to governed agents in 5 minutes. 🌍 Also in: 日本語 | 简体中文 | 한국어
How It Works
Agent ──► Policy Engine ──► Identity ──► Audit Log
(YAML/OPA/Cedar) (SPIFFE/DID/mTLS) (Tamper-evident)
│ │
├── Allowed ──► Tool executes │
└── Denied ──► GovernanceDenied │
▼
Decision Record
Every layer is optional. Start with govern() and add layers as your risk profile grows. Most teams run policy enforcement + audit logging and never need the full stack.
Packages
| Package | Description |
|---|---|
| Agent OS | Policy engine, agent lifecycle, governance gate |
| Agent Control Specification (README) | Stateless, deterministic, fail-closed policy decision runtime (Rust core) backing the AGT policy layer |
| Agent Mesh | Agent discovery, routing, and trust mesh |
| Agent Runtime | Execution sandboxing with four privilege rings |
| Agent SRE | Kill switch, SLO monitoring, chaos testing |
| Agent Compliance | OWASP verification, policy linting, integrity checks |
| Agent Marketplace | Plugin governance and trust scoring |
| Agent Lightning | RL training governance with violation penalties |
| Agent Hypervisor | Execution audit, delta engine, in-memory commitment tracking, command denylist enforcement |
Additional Capabilities
| Capability | Description |
|---|---|
| MCP Security Gateway | Tool poisoning detection, drift monitoring, typosquatting, hidden instruction scanning (Spec) |
| Shadow AI Discovery | Find unregistered agents across processes, configs, and repos (Discovery) |
| Governance Dashboard | Real-time fleet visibility for health, trust, and compliance (Dashboard) |
| PromptDefense Evaluator | 12-vector prompt injection audit (Evaluator) |
| Contributor Reputation | PR/issue author screening for social engineering. Reusable GitHub Action (Action) |
Install
| Language | Package | Command |
|---|---|---|
| Python | agent-governance-toolkit | pip install "agent-governance-toolkit[full]" |
| TypeScript | @microsoft/agent-governance-sdk | npm install @microsoft/agent-governance-sdk |
| Copilot CLI | @microsoft/agent-governance-copilot-cli | npx @microsoft/agent-governance-copilot-cli install |
| Claude Code | @microsoft/agent-governance-claude-code | claude --plugin-dir ./agent-governance-claude-code |
| OpenCode | @microsoft/agent-governance-opencode | npm install @microsoft/agent-governance-opencode |
| .NET | Microsoft.AgentGovernance | dotnet add package Microsoft.AgentGovernance |
| .NET MCP | Microsoft.AgentGovernance.Extensions.ModelContextProtocol | dotnet add package Microsoft.AgentGovernance.Extensions.ModelContextProtocol |
| Rust | agent-governance | cargo add agent-governance |
| Go | agent-governance-toolkit | go get github.com/microsoft/agent-governance-toolkit/agent-governance-golang |
All five language SDKs implement core governance (policy, identity, trust, audit). Python has the full stack. Copilot CLI and Claude Code are first-party developer surfaces built on the TypeScript SDK. See Language Package Matrix for detailed per-language coverage.
As of v4.1.0, 45 packages have been consolidated into 5 top-level distributions:
| Distribution | PyPI | What’s included |
|---|---|---|
agent-governance-toolkit-core | agent-governance-toolkit-core | Policy engine, capability model, audit, MCP gateway, zero-trust identity, trust scoring, A2A/MCP/IATP bridges |
agent-governance-toolkit-runtime | agent-governance-toolkit-runtime | Privilege rings, saga orchestration, termination control, execution plan validation, command denylist enforcement |
agent-governance-toolkit-sre | agent-governance-toolkit-sre | SLOs, error budgets, chaos engineering, circuit breakers |
agent-governance-toolkit-cli | agent-governance-toolkit-cli | agt CLI, OWASP verification, integrity checks, policy linting |
agent-governance-toolkit[full] | agent-governance-toolkit | Meta-package installing all of the above |
Previous package names (agent-os-kernel, agentmesh-platform, agentmesh-runtime, agent-sre, agent-discovery, agent-hypervisor, agentmesh-marketplace, agentmesh-lightning) remain installable as stub packages that redirect to the consolidated distributions.
Prerequisites
- Python: 3.10+
- Node.js: 18+ / npm 9+ (TypeScript SDK)
- .NET: 8+
- Go: 1.25+
- Rust: 1.70+
- Optional:
AZURE_CLIENT_ID,AZURE_TENANT_ID,AZURE_CLIENT_SECRETfor Azure-integrated features
Framework Support
| Framework | Integration |
|---|---|
| Microsoft Agent Framework | Native Middleware |
| Semantic Kernel | Native (.NET + Python) |
| AutoGen | Adapter |
| LangGraph / LangChain | Adapter |
| CrewAI | Adapter |
| OpenAI Agents SDK | Middleware |
| Claude Code | Governance plugin package |
| Google ADK | Adapter |
| LlamaIndex | Middleware |
| Haystack | Pipeline |
| Mastra | Adapter |
| Dify | Plugin |
| Azure AI Foundry | Deployment Guide |
| GitHub Copilot CLI | Governance installer |
Full list: Framework Integrations · Quickstart Examples
Examples
| Example | Framework | What it demonstrates |
|---|---|---|
| acs-email-tool | Framework-neutral ACS host | Snapshot, verdict, transform, deny, and host enforcement |
| acs-atr-annotator | ACS custom policy | Independent threat-rule annotations with fail-closed decisions |
| openai-agents-governed | OpenAI Agents SDK | Policy-gated tool calls with trust tiers |
| crewai-governed | CrewAI | Multi-agent governance with role-based policies |
| smolagents-governed | HuggingFace smolagents | Lightweight agent governance |
| maf-integration | MAF | Microsoft Agent Framework integration |
| mcp-trust-verified-server | MCP | Trust-verified MCP server implementation |
| governance-dashboard | Streamlit | Real-time fleet visibility dashboard |
Specifications
Every major component has a formal RFC 2119 specification with conformance tests. These specs define the behavioral contract: what implementations MUST, SHOULD, and MAY do.
| Specification | Scope | Tests |
|---|---|---|
| Agent OS Policy Engine | Native runtime integration and fail-closed semantics | — |
| Agent Control Specification | Stateless intervention-point policy runtime, verdicts, transform, fail-closed | — |
| AgentMesh Identity and Trust | Credentials, trust scoring, delegation chains | 135 |
| Agent Hypervisor Execution Control | Privilege rings, saga orchestration, kill switch | 80 |
| AgentMesh Trust and Coordination | Peer trust negotiation, mesh-wide policy | 62 |
| Agent SRE Governance | SLOs, error budgets, chaos, circuit breakers | 111 |
| MCP Security Gateway | Tool poisoning, drift detection, hidden instructions | 127 |
| Agent Lightning Fast-Path | RL training governance, violation penalties | 100 |
| Framework Adapter Contract | Native framework mediation contract | — |
| Audit and Compliance | Merkle audit, compliance mapping, Decision BOM | 157 |
| AgentMesh Wire Protocol | Message format, routing, serialization | — |
992 conformance tests ensure code stays aligned to specs. 29 Architecture Decision Records document why.
このREADMEは一部を省略しています。全文はGitHubにあります。 原文を読む ↗