product · shield
Shield
The guardrails. Author policies, watch them run against live traffic, route risky actions to a human.
Shield is in preview mode
Author and simulate guardrails today against your real audit data. Enforcement at your agent runtime ships once AGT integration goes live (Q4 2026). Until then, switching a policy to Enforce has no effect — your agents continue uninterrupted.
AGT enforces policy in-process in under a millisecond; we don't reinvent that engine. Shield is the surface on top: authoring without hand-written YAML, observe-before-enforce, decision history, and approvals routed to the channel your team already watches. Policies you author are exportable, version-controllable definitions aimed at AGT's PolicyEngine — the open-source engine built for OPA Rego and Cedar — and enforcement runs in your runtime, not ours.
what's inside
Five pieces.
authoring ui
Write, version, and test policies against historical events.
observe mode · at launch
Dry-run against live traffic; log what would have happened, block nothing.
enforce mode · q4 2026
Three outcomes per policy: allow, queue for approval, or block.
approval routing
In-app queue, signed-link email, Slack, ServiceNow, webhook. Webhooks are signed; handlers see tokens, never raw PII.
decision history
Every evaluation logged, replayable, exportable into Evidence Packs.
availability
What each tier gets
| Starter | Growth | Business | Enterprise | |
|---|---|---|---|---|
| AGT policy enforcement (via library) | ✓ | ✓ | ✓ | ✓ |
| Policy authoring UI · observe mode | — | — | ✓ | ✓ |
| Enforce mode (Q4 2026) | — | — | ✓ | ✓ |
| Approval routing (in-app + email) | — | ✓ | ✓ | ✓ |
| Approval routing (Slack · ServiceNow · webhook) | — | — | ✓ | ✓ |
Author policies. Route approvals.
Observe mode ships today. Enforce mode lands Q4 2026 after we've watched real policies meet real traffic.