Action Governance

Control the action before it becomes an outcome.

Every AI agent action that touches money, infrastructure, or sensitive data is evaluated by Guard before it executes. Allow, approve, or block — with a signed record of why.

Three stories. One engine.

The same Guard policy engine handles the full range of consequential business actions. The decision, the rule, and the reason are the same data structure across all three.

Story 1

Refund over the cap

A support agent attempts to process a $840 refund for customer C-8911. The refund-cap policy blocks it. A smaller refund ($120) on the same account proceeds immediately.

BLOCK
Guard
Agentcodex / release-agent
Actionprocess_refund
Resourcecustomer C-8911
Policyrefund-cap
ReasonRefunds over $500 require human approval per FIN-07.
ALLOW
Guard
Agentcodex / release-agent
Actionprocess_refund
Resourcecustomer C-8911
Policyrefund-cap
ReasonRefund of $120 is within the $500 automatic approval limit.
Story 2

Production deployment outside change window

A deploy agent attempts to push to production at 14:32 UTC — outside the approved change window. Guard routes to Slack for human approval rather than blocking outright.

REQUIRES APPROVAL
Guard
Agentclaude-code / deploy-agent
Actiondeploy_production
Resourcepayments-api
Policyproduction-change-v4
ReasonProduction deployment outside approved change window
Story 3

Secret read in production environment

An agent attempts to read a production secret during a scheduled task. Guard blocks the action — secret access from automated agents requires an explicit exemption.

BLOCK
Guard
Agentcursor-agent-17
Actionread_env
Resourceorders-db
Policyno-production-network-change
ReasonProduction secret reads by automated agents are not permitted without an approved exemption.

Policy at the action, not at the report.

Action governance is not an audit log you review after the fact. Guard runs at the moment the agent calls the action — before money moves, before the deployment lands, before the secret is read. The decision is made then, with a receipt that proves it.

Govern the action, not the aftermath.

Action Governance — Control what AI agents do | Conduct | ConductAI