← Back to all projects

Agent Governance Toolkit

Wrap a tool in a written policy so that every call is checked, logged, and refused when the rules say no

OfficialMIT
Stars
6.1k
Forks
1.1k
Open issues
245
Last commit
25 Aug 2026

What is Agent Governance Toolkit?

The permissions an agent inherits are the ones its credentials carry, which is almost never the set of things it should be allowed to do: a key that can read a table can usually drop it. This toolkit closes that gap at the point of the call. You write the rules as a YAML file — deny anything destructive, require a named group's approval before an email goes out — wrap the tool function, and every call is evaluated, written to an audit trail, and refused with an explanation when a rule blocks it. Alongside that sit an identity scheme for attributing an action to a specific agent and a sandboxing layer for tools you would rather not run in your own process. It is a public preview, and the package layout has already moved once.

What can you do with Agent Governance Toolkit?

  • Govern an existing tool in two lines — Wrap the function you already have and hand it a policy file — the call site does not change, and neither does the agent framework around it.
  • Write the rules as a file, not as code — Policies are YAML with conditions and outcomes, so what an agent may do can be reviewed, versioned and changed without a deployment of the agent.
  • Require a person for the dangerous cases — A rule can demand approval from a named group before an action proceeds, which is the difference between an audit trail and an actual control.
  • Know which agent did what — Actions are attributed to a specific agent identity rather than to a shared service account, so an audit trail can answer the question afterwards.
  • Refuse with a reason — A blocked call raises an error naming the rule that stopped it, so the failure is debuggable instead of arriving as a silent empty result.
  • Reach it from more than Python — The same governance is published for TypeScript and .NET, and as a plugin for Claude Code, so a mixed estate is covered by one set of policies.

Before you choose Agent Governance Toolkit

  • It is published as a public preview and says breaking changes may come before general availability, so pin the version and read the changelog before upgrading.
  • The packaging has already been reorganised once: the base install carries only the compliance command, the governance modules need an extra, and one earlier import path is deprecated with a one-way migration.

Frequently asked questions

Is Agent Governance Toolkit free for commercial use?

Agent Governance Toolkit is released under the MIT licence — OSI-approved open source, which permits commercial use.

How can Agent Governance Toolkit be deployed?

Agent Governance Toolkit is available as Self-hosted / Runs locally.

Documentation

Reproduced from the microsoft/agent-governance-toolkit README, published under MIT. Read the original ↗

🌍 English | 日本語 | 简体中文 | 한국어

Agent Governance Toolkit

Agent Governance Toolkit

Ship agents to production without losing sleep

CI Discord OpenSSF Scorecard OpenSSF Best Practices

[!IMPORTANT] Public Preview — production-quality public preview releases. May have breaking changes before GA.

Policy enforcement, identity, sandboxing, and SRE for autonomous AI agents. One pip install, any framework.


The Problem

Your AI agents call tools, browse the web, query databases, and delegate to other agents. Once deployed, they make decisions autonomously. You need answers to three questions:

1. Is this action allowed? An agent with access to send_email and query_database should not be able to drop_table. OAuth scopes and IAM roles control which services an agent can reach, not what it does once connected.

2. Which agent did this? In a multi-agent system, five agents might share a single API key. When something goes wrong, “an agent did it” is not an incident response.

3. Can you prove what happened? Auditors and regulators need tamper-evident records of every decision: what policy was active, what the agent requested, and why it was allowed or denied.

Prompt-level safety (“please follow the rules”) is not a control surface. It is a polite request to a stochastic system. OWASP LLM01:2025 states this explicitly: “it is unclear if there are fool-proof methods of prevention for prompt injection.” The published numbers back this up. Andriushchenko et al. (ICLR 2025) report 100% attack success rate on GPT-4o, GPT-3.5, Claude 3, and Llama-3 using adaptive attacks with logprob access and suffix optimization, evaluated against the JailbreakBench benchmark (Chao et al., NeurIPS 2024). Microsoft’s own AI Red Teaming Agent formalizes Attack Success Rate (ASR), the rate of policy violations under adversarial input, as the canonical metric for this class of failure. Lessons from Red Teaming 100 Generative AI Products reinforces the point: “mitigations do not eliminate risk entirely” and red teaming must be a continuous process because model-layer defenses are probabilistic by construction.

AGT does not try to win that fight inside the prompt. Every tool call, message send, and delegation is intercepted in deterministic application code before the model’s intent reaches the wire. Actions the AGT kernel denies are not “unlikely.” They are structurally impossible. That is the difference between asking an agent to behave and making it incapable of misbehaving.


Quick Start

Prerequisites: Python 3.11+

pip install "agent-governance-toolkit[full]"

Use the [full] extra for the quick-start imports below. The base agent-governance-toolkit wheel installs the compliance CLI only; the governance modules live in the consolidated core distribution. The agentmesh quick-start import remains the current wrapper API. Importing agent_os emits a DeprecationWarning because the old agent-os-kernel distribution is deprecated. Use agent-governance-toolkit-core (or the [full] extra that includes it) as the replacement distribution. Policy-engine host code uses the ACS SDK; agt-policies provides the one-way v4-to-v5 migration command. The pre-ACS agent_os.policies rule model is gone, and BREAKING_CHANGES.md lists its replacements.

For Claude Code, add AGT as a plugin marketplace and install the governance plugin:

/plugin marketplace add microsoft/agent-governance-toolkit
/plugin install agt-governance@agent-governance-toolkit

Govern any tool function in two lines:

from agentmesh.governance import govern

safe_tool = govern(my_tool, policy="policy.yaml")   # every call checked, logged, enforced

On every call, safe_tool evaluates the YAML policy, logs the decision to an audit trail, and raises GovernanceDenied when the policy blocks the action.

# policy.yaml
apiVersion: governance.toolkit/v1
name: production-policy
default_action: allow
rules:
  - name: block-destructive
    condition: "action.type in ['drop', 'delete', 'truncate']"
    action: deny
    description: "Destructive operations require human approval"

  - name: require-approval-for-send
    condition: "action.type == 'send_email'"
    action: require_approval
    approvers: ["security-team"]
>>> safe_tool(action="read", table="users")
{'table': 'users', 'rows': 42}

>>> safe_tool(action="drop", table="users")
GovernanceDenied: Action denied by policy rule 'block-destructive':
  Destructive operations require human approval

Or use the full AgentControl API for programmatic control:

from agent_control_specification import AgentControl

runtime = AgentControl.from_path(str("manifest.yaml"))
result = runtime.evaluate(
    "input",
    {
        "envelope": {"agent_id": "example-agent"},
        "input": {"body": {"action": "web_search", "params": {}}},
    },
)
print(result.verdict)
runtime.close()

Run the complete ACS email-tool example.

TypeScript

import { PolicyEngine } from "@microsoft/agent-governance-sdk";

const engine = new PolicyEngine([
  { action: "web_search", effect: "allow" },
  { action: "shell_exec", effect: "deny" },
]);
engine.evaluate("web_search"); // "allow"
engine.evaluate("shell_exec"); // "deny"

.NET

using AgentGovernance;
using AgentGovernance.Extensions.ModelContextProtocol;
using AgentGovernance.Policy;

var kernel = new GovernanceKernel(new GovernanceOptions
{
    PolicyPaths = new() { "policies/default.yaml" },
});
var result = kernel.EvaluateToolCall("did:mesh:agent-1", "web_search",
    new() { ["query"] = "latest AI news" });

// MCP server integration
builder.Services.AddMcpServer()
    .WithGovernance(options => options.PolicyPaths.Add("policies/mcp.yaml"));

Rust

use agent_governance::{AgentMeshClient, ClientOptions};

let client = AgentMeshClient::new("my-agent").unwrap();
let result = client.execute_with_governance("data.read", None);
assert!(result.allowed);

Go

import agentmesh "github.com/microsoft/agent-governance-toolkit/agent-governance-golang"

client, _ := agentmesh.NewClient("my-agent",
    agentmesh.WithPolicyRules([]agentmesh.PolicyRule{
        {Action: "data.read", Effect: agentmesh.Allow},
        {Action: "*", Effect: agentmesh.Deny},
    }),
)
result := client.ExecuteWithGovernance("data.read", nil)

CLI tools:

agt doctor                                        # check installation
agt verify                                        # OWASP compliance check
agt verify --evidence ./agt-evidence.json --strict # fail CI on weak evidence
agt red-team scan ./prompts/ --min-grade B         # prompt injection audit
agt lint-policy policies/                          # validate policy files

Full walkthrough: quickstart.md — zero to governed agents in 5 minutes. 🌍 Also in: 日本語 | 简体中文 | 한국어


How It Works

Agent ──► Policy Engine ──► Identity ──► Audit Log
            (YAML/OPA/Cedar)  (SPIFFE/DID/mTLS)  (Tamper-evident)
                 │                                      │
                 ├── Allowed ──► Tool executes           │
                 └── Denied  ──► GovernanceDenied        │
                                                        ▼
                                                 Decision Record

Every layer is optional. Start with govern() and add layers as your risk profile grows. Most teams run policy enforcement + audit logging and never need the full stack.


Packages

PackageDescription
Agent OSPolicy engine, agent lifecycle, governance gate
Agent Control Specification (README)Stateless, deterministic, fail-closed policy decision runtime (Rust core) backing the AGT policy layer
Agent MeshAgent discovery, routing, and trust mesh
Agent RuntimeExecution sandboxing with four privilege rings
Agent SREKill switch, SLO monitoring, chaos testing
Agent ComplianceOWASP verification, policy linting, integrity checks
Agent MarketplacePlugin governance and trust scoring
Agent LightningRL training governance with violation penalties
Agent HypervisorExecution audit, delta engine, in-memory commitment tracking, command denylist enforcement

Additional Capabilities

CapabilityDescription
MCP Security GatewayTool poisoning detection, drift monitoring, typosquatting, hidden instruction scanning (Spec)
Shadow AI DiscoveryFind unregistered agents across processes, configs, and repos (Discovery)
Governance DashboardReal-time fleet visibility for health, trust, and compliance (Dashboard)
PromptDefense Evaluator12-vector prompt injection audit (Evaluator)
Contributor ReputationPR/issue author screening for social engineering. Reusable GitHub Action (Action)

Install

LanguagePackageCommand
Pythonagent-governance-toolkitpip install "agent-governance-toolkit[full]"
TypeScript@microsoft/agent-governance-sdknpm install @microsoft/agent-governance-sdk
Copilot CLI@microsoft/agent-governance-copilot-clinpx @microsoft/agent-governance-copilot-cli install
Claude Code@microsoft/agent-governance-claude-codeclaude --plugin-dir ./agent-governance-claude-code
OpenCode@microsoft/agent-governance-opencodenpm install @microsoft/agent-governance-opencode
.NETMicrosoft.AgentGovernancedotnet add package Microsoft.AgentGovernance
.NET MCPMicrosoft.AgentGovernance.Extensions.ModelContextProtocoldotnet add package Microsoft.AgentGovernance.Extensions.ModelContextProtocol
Rustagent-governancecargo add agent-governance
Goagent-governance-toolkitgo get github.com/microsoft/agent-governance-toolkit/agent-governance-golang

All five language SDKs implement core governance (policy, identity, trust, audit). Python has the full stack. Copilot CLI and Claude Code are first-party developer surfaces built on the TypeScript SDK. See Language Package Matrix for detailed per-language coverage.

As of v4.1.0, 45 packages have been consolidated into 5 top-level distributions:

DistributionPyPIWhat’s included
agent-governance-toolkit-coreagent-governance-toolkit-corePolicy engine, capability model, audit, MCP gateway, zero-trust identity, trust scoring, A2A/MCP/IATP bridges
agent-governance-toolkit-runtimeagent-governance-toolkit-runtimePrivilege rings, saga orchestration, termination control, execution plan validation, command denylist enforcement
agent-governance-toolkit-sreagent-governance-toolkit-sreSLOs, error budgets, chaos engineering, circuit breakers
agent-governance-toolkit-cliagent-governance-toolkit-cliagt CLI, OWASP verification, integrity checks, policy linting
agent-governance-toolkit[full]agent-governance-toolkitMeta-package installing all of the above

Previous package names (agent-os-kernel, agentmesh-platform, agentmesh-runtime, agent-sre, agent-discovery, agent-hypervisor, agentmesh-marketplace, agentmesh-lightning) remain installable as stub packages that redirect to the consolidated distributions.

Prerequisites

  • Python: 3.10+
  • Node.js: 18+ / npm 9+ (TypeScript SDK)
  • .NET: 8+
  • Go: 1.25+
  • Rust: 1.70+
  • Optional: AZURE_CLIENT_ID, AZURE_TENANT_ID, AZURE_CLIENT_SECRET for Azure-integrated features

Framework Support

FrameworkIntegration
Microsoft Agent FrameworkNative Middleware
Semantic KernelNative (.NET + Python)
AutoGenAdapter
LangGraph / LangChainAdapter
CrewAIAdapter
OpenAI Agents SDKMiddleware
Claude CodeGovernance plugin package
Google ADKAdapter
LlamaIndexMiddleware
HaystackPipeline
MastraAdapter
DifyPlugin
Azure AI FoundryDeployment Guide
GitHub Copilot CLIGovernance installer

Full list: Framework Integrations · Quickstart Examples


Examples

ExampleFrameworkWhat it demonstrates
acs-email-toolFramework-neutral ACS hostSnapshot, verdict, transform, deny, and host enforcement
acs-atr-annotatorACS custom policyIndependent threat-rule annotations with fail-closed decisions
openai-agents-governedOpenAI Agents SDKPolicy-gated tool calls with trust tiers
crewai-governedCrewAIMulti-agent governance with role-based policies
smolagents-governedHuggingFace smolagentsLightweight agent governance
maf-integrationMAFMicrosoft Agent Framework integration
mcp-trust-verified-serverMCPTrust-verified MCP server implementation
governance-dashboardStreamlitReal-time fleet visibility dashboard

Specifications

Every major component has a formal RFC 2119 specification with conformance tests. These specs define the behavioral contract: what implementations MUST, SHOULD, and MAY do.

SpecificationScopeTests
Agent OS Policy EngineNative runtime integration and fail-closed semantics—
Agent Control SpecificationStateless intervention-point policy runtime, verdicts, transform, fail-closed—
AgentMesh Identity and TrustCredentials, trust scoring, delegation chains135
Agent Hypervisor Execution ControlPrivilege rings, saga orchestration, kill switch80
AgentMesh Trust and CoordinationPeer trust negotiation, mesh-wide policy62
Agent SRE GovernanceSLOs, error budgets, chaos, circuit breakers111
MCP Security GatewayTool poisoning, drift detection, hidden instructions127
Agent Lightning Fast-PathRL training governance, violation penalties100
Framework Adapter ContractNative framework mediation contract—
Audit and ComplianceMerkle audit, compliance mapping, Decision BOM157
AgentMesh Wire ProtocolMessage format, routing, serialization—

992 conformance tests ensure code stays aligned to specs. 29 Architecture Decision Records document why.


This README has been shortened. The full version is on GitHub. Read the original ↗

Agent Governance Toolkit
Ask AI
GitHub