microsoft/agent-governance-toolkitPublic

AI Agent Governance Toolkit — Policy enforcement, zero-trust identity, execution sandboxing, and reliability engineering for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10.

AI summary: A toolkit for enforcing policy, security, and sandboxing in autonomous AI agents.

Stars
5.7K
+100 today
Forks
983
Watchers
90
Open issues
46
Open PRs
115
Contributors
~122
Commits
2.3K
Branches
119

PythonMITCreated Mar 2, 2026Last push todayLatest release v4.1.0+228 stars this week+264 this month

Star history

since Mar 1, 2026
02K4KMar 2026Apr 2026Jun 2026Aug 2026
5.7K stars as of Aug 7, 2026, tracked back to Mar 1, 2026. Historical curve reconstructed from public GitHub event archives, calibrated to the current total.

Contribution activity

commits per day, last 52 weeks
AugSepOctNovDecJanFebMarAprMayJunJulMonWedFri2025-08-02: 0 commits2025-08-03: 0 commits2025-08-04: 0 commits2025-08-05: 0 commits2025-08-06: 0 commits2025-08-07: 0 commits2025-08-08: 0 commits2025-08-09: 0 commits2025-08-10: 0 commits2025-08-11: 0 commits2025-08-12: 0 commits2025-08-13: 0 commits2025-08-14: 0 commits2025-08-15: 0 commits2025-08-16: 0 commits2025-08-17: 0 commits2025-08-18: 0 commits2025-08-19: 0 commits2025-08-20: 0 commits2025-08-21: 0 commits2025-08-22: 0 commits2025-08-23: 0 commits2025-08-24: 0 commits2025-08-25: 0 commits2025-08-26: 0 commits2025-08-27: 0 commits2025-08-28: 0 commits2025-08-29: 0 commits2025-08-30: 0 commits2025-08-31: 0 commits2025-09-01: 0 commits2025-09-02: 0 commits2025-09-03: 0 commits2025-09-04: 0 commits2025-09-05: 0 commits2025-09-06: 0 commits2025-09-07: 0 commits2025-09-08: 0 commits2025-09-09: 0 commits2025-09-10: 0 commits2025-09-11: 0 commits2025-09-12: 0 commits2025-09-13: 0 commits2025-09-14: 0 commits2025-09-15: 0 commits2025-09-16: 0 commits2025-09-17: 0 commits2025-09-18: 0 commits2025-09-19: 0 commits2025-09-20: 0 commits2025-09-21: 0 commits2025-09-22: 0 commits2025-09-23: 0 commits2025-09-24: 0 commits2025-09-25: 0 commits2025-09-26: 0 commits2025-09-27: 0 commits2025-09-28: 0 commits2025-09-29: 0 commits2025-09-30: 0 commits2025-10-01: 0 commits2025-10-02: 0 commits2025-10-03: 0 commits2025-10-04: 0 commits2025-10-05: 0 commits2025-10-06: 0 commits2025-10-07: 0 commits2025-10-08: 0 commits2025-10-09: 0 commits2025-10-10: 0 commits2025-10-11: 0 commits2025-10-12: 0 commits2025-10-13: 0 commits2025-10-14: 0 commits2025-10-15: 0 commits2025-10-16: 0 commits2025-10-17: 0 commits2025-10-18: 0 commits2025-10-19: 0 commits2025-10-20: 0 commits2025-10-21: 0 commits2025-10-22: 0 commits2025-10-23: 0 commits2025-10-24: 0 commits2025-10-25: 0 commits2025-10-26: 0 commits2025-10-27: 0 commits2025-10-28: 0 commits2025-10-29: 0 commits2025-10-30: 0 commits2025-10-31: 0 commits2025-11-01: 0 commits2025-11-02: 0 commits2025-11-03: 0 commits2025-11-04: 0 commits2025-11-05: 0 commits2025-11-06: 0 commits2025-11-07: 0 commits2025-11-09: 0 commits2025-11-10: 0 commits2025-11-11: 0 commits2025-11-12: 0 commits2025-11-13: 0 commits2025-11-14: 0 commits2025-11-15: 0 commits2025-11-16: 0 commits2025-11-17: 0 commits2025-11-18: 0 commits2025-11-19: 0 commits2025-11-20: 0 commits2025-11-21: 0 commits2025-11-22: 0 commits2025-11-23: 0 commits2025-11-24: 0 commits2025-11-25: 0 commits2025-11-26: 0 commits2025-11-27: 0 commits2025-11-28: 0 commits2025-11-29: 0 commits2025-11-30: 0 commits2025-12-01: 0 commits2025-12-02: 0 commits2025-12-03: 0 commits2025-12-04: 0 commits2025-12-05: 0 commits2025-12-06: 0 commits2025-12-07: 0 commits2025-12-08: 0 commits2025-12-09: 0 commits2025-12-10: 0 commits2025-12-11: 0 commits2025-12-12: 0 commits2025-12-13: 0 commits2025-12-14: 0 commits2025-12-15: 0 commits2025-12-16: 0 commits2025-12-17: 0 commits2025-12-18: 0 commits2025-12-19: 0 commits2025-12-20: 0 commits2025-12-21: 0 commits2025-12-22: 0 commits2025-12-23: 0 commits2025-12-24: 0 commits2025-12-25: 0 commits2025-12-26: 0 commits2025-12-27: 0 commits2025-12-28: 0 commits2025-12-29: 0 commits2025-12-30: 0 commits2025-12-31: 0 commits2026-01-01: 0 commits2026-01-02: 0 commits2026-01-03: 0 commits2026-01-04: 0 commits2026-01-05: 0 commits2026-01-06: 0 commits2026-01-07: 0 commits2026-01-08: 0 commits2026-01-09: 0 commits2026-01-10: 0 commits2026-01-11: 0 commits2026-01-12: 0 commits2026-01-13: 0 commits2026-01-14: 0 commits2026-01-15: 0 commits2026-01-16: 0 commits2026-01-17: 0 commits2026-01-18: 0 commits2026-01-19: 0 commits2026-01-20: 0 commits2026-01-21: 0 commits2026-01-22: 0 commits2026-01-23: 0 commits2026-01-24: 0 commits2026-01-25: 0 commits2026-01-26: 0 commits2026-01-27: 0 commits2026-01-28: 0 commits2026-01-29: 0 commits2026-01-30: 0 commits2026-01-31: 0 commits2026-02-01: 0 commits2026-02-02: 0 commits2026-02-03: 0 commits2026-02-04: 0 commits2026-02-05: 0 commits2026-02-06: 0 commits2026-02-07: 0 commits2026-02-08: 0 commits2026-02-09: 0 commits2026-02-10: 0 commits2026-02-11: 0 commits2026-02-12: 0 commits2026-02-13: 0 commits2026-02-14: 0 commits2026-02-15: 0 commits2026-02-16: 0 commits2026-02-17: 0 commits2026-02-18: 0 commits2026-02-19: 0 commits2026-02-20: 0 commits2026-02-21: 0 commits2026-02-22: 0 commits2026-02-23: 0 commits2026-02-24: 0 commits2026-02-25: 0 commits2026-02-26: 0 commits2026-02-27: 0 commits2026-02-28: 0 commits2026-03-01: 0 commits2026-03-02: 5 commits2026-03-03: 6 commits2026-03-04: 17 commits2026-03-05: 4 commits2026-03-06: 12 commits2026-03-07: 18 commits2026-03-08: 11 commits2026-03-09: 4 commits2026-03-10: 17 commits2026-03-11: 6 commits2026-03-12: 7 commits2026-03-13: 3 commits2026-03-14: 7 commits2026-03-15: 22 commits2026-03-16: 15 commits2026-03-17: 26 commits2026-03-18: 4 commits2026-03-19: 0 commits2026-03-20: 4 commits2026-03-21: 6 commits2026-03-22: 5 commits2026-03-23: 14 commits2026-03-24: 25 commits2026-03-25: 18 commits2026-03-26: 10 commits2026-03-27: 14 commits2026-03-28: 10 commits2026-03-29: 9 commits2026-03-30: 23 commits2026-03-31: 39 commits2026-04-01: 19 commits2026-04-02: 14 commits2026-04-03: 17 commits2026-04-04: 23 commits2026-04-05: 12 commits2026-04-06: 11 commits2026-04-07: 32 commits2026-04-08: 8 commits2026-04-09: 6 commits2026-04-10: 4 commits2026-04-11: 22 commits2026-04-12: 9 commits2026-04-13: 9 commits2026-04-14: 28 commits2026-04-15: 8 commits2026-04-16: 21 commits2026-04-17: 9 commits2026-04-18: 0 commits2026-04-19: 4 commits2026-04-20: 41 commits2026-04-21: 49 commits2026-04-22: 38 commits2026-04-23: 20 commits2026-04-24: 16 commits2026-04-25: 20 commits2026-04-26: 38 commits2026-04-27: 33 commits2026-04-28: 19 commits2026-04-29: 23 commits2026-04-30: 15 commits2026-05-01: 16 commits2026-05-02: 3 commits2026-05-03: 4 commits2026-05-04: 11 commits2026-05-05: 28 commits2026-05-06: 23 commits2026-05-07: 19 commits2026-05-08: 15 commits2026-05-09: 29 commits2026-05-10: 88 commits2026-05-11: 138 commits2026-05-12: 113 commits2026-05-13: 11 commits2026-05-14: 8 commits2026-05-15: 10 commits2026-05-16: 33 commits2026-05-17: 36 commits2026-05-18: 18 commits2026-05-19: 18 commits2026-05-20: 15 commits2026-05-21: 15 commits2026-05-22: 50 commits2026-05-23: 9 commits2026-05-24: 21 commits2026-05-25: 8 commits2026-05-26: 4 commits2026-05-27: 15 commits2026-05-28: 8 commits2026-05-29: 32 commits2026-05-30: 12 commits2026-05-31: 9 commits2026-06-01: 27 commits2026-06-02: 10 commits2026-06-03: 2 commits2026-06-04: 44 commits2026-06-05: 8 commits2026-06-06: 0 commits2026-06-07: 0 commits2026-06-08: 3 commits2026-06-09: 39 commits2026-06-10: 22 commits2026-06-11: 27 commits2026-06-12: 20 commits2026-06-13: 3 commits2026-06-14: 9 commits2026-06-15: 25 commits2026-06-16: 38 commits2026-06-17: 18 commits2026-06-18: 4 commits2026-06-19: 0 commits2026-06-20: 0 commits2026-06-21: 0 commits2026-06-22: 3 commits2026-06-23: 26 commits2026-06-24: 11 commits2026-06-25: 4 commits2026-06-26: 0 commits2026-06-27: 0 commits2026-06-28: 0 commits2026-06-29: 0 commits2026-06-30: 19 commits2026-07-01: 6 commits2026-07-02: 4 commits2026-07-03: 0 commits2026-07-04: 0 commits2026-07-05: 0 commits2026-07-06: 0 commits2026-07-07: 10 commits2026-07-08: 13 commits2026-07-09: 2 commits2026-07-10: 9 commits2026-07-11: 2 commits2026-07-12: 0 commits2026-07-13: 0 commits2026-07-14: 1 commit2026-07-15: 15 commits2026-07-16: 3 commits2026-07-17: 2 commits2026-07-18: 0 commits2026-07-19: 0 commits2026-07-20: 10 commits2026-07-21: 23 commits2026-07-22: 0 commits2026-07-23: 1 commit2026-07-24: 7 commits2026-07-25: 0 commits2026-07-26: 0 commits2026-07-27: 0 commits2026-07-28: 1 commit2026-07-29: 0 commits2026-07-30: 0 commits2026-07-31: 0 commits2026-08-01: 0 commits
2,219 commits in the last yearLessMore

Signals and awards

derived from tracked data
  • Very active

    2,219 commits in 52 weeks

  • Community-driven

    ~122 contributors

  • Well documented

    High community health score

  • Permissive license

    MIT

  • Continuous integration

    Automated checks passing

What agent-governance-toolkit does

The Agent Governance Toolkit provides a robust framework for securing and managing autonomous AI agents in production environments. It addresses the critical risks associated with agentic systems, such as unintended actions and data leakage, by implementing strict policy enforcement engines and zero-trust identity models. The toolkit includes sandboxing mechanisms to isolate agent execution and provides comprehensive audit logging to ensure compliance with enterprise security standards, specifically covering the OWASP Agentic Top 10 vulnerabilities.

Security engineers, AI researchers, and enterprise IT teams deploying autonomous agents in production.

  • Policy enforcement engine: allows administrators to define strict boundaries on what APIs and data an agent can access.
  • Execution sandboxing: isolates agent processes to prevent malicious code execution or unintended system changes.
  • Zero-trust identity: ensures every agent action is authenticated and authorized against least-privilege principles.
  • Comprehensive auditing: logs all agent decisions, API calls, and state changes for compliance and debugging.
  • OWASP alignment: directly mitigates the top security risks identified in the OWASP Agentic Top 10 framework.

Where teams use it

Securing Enterprise AI Assistants

IT departments use the toolkit to ensure internal AI agents cannot accidentally delete databases or leak sensitive HR records.

Compliance Monitoring

Security teams deploy the auditing features to track and review the autonomous decisions made by financial trading agents.

Safe Agent Sandboxing

Developers use the sandboxing tools to safely test third-party or experimental agents without risking local system integrity.

Identity Management

Platform engineers integrate the zero-trust models to assign unique, scoped credentials to different agent instances.

Getting started: pip install agent-governance-toolkit

README

main branch

🌍 English | 日本語 | 简体中文 | 한국어

Agent Governance Toolkit

Agent Governance Toolkit

Ship agents to production without losing sleep

Full Documentation

🚀 Quick Start · 📋 Specifications · 📦 PyPI · 📝 Changelog

CI Discord License: MIT PyPI version npm NuGet OpenSSF Scorecard OpenSSF Best Practices OWASP Agentic Top 10 AARM Extended ATF

Important

Public Preview -- production-quality public preview releases. May have breaking changes before GA.

Policy enforcement, identity, sandboxing, and SRE for autonomous AI agents. One pip install, any framework.


The Problem

Your AI agents call tools, browse the web, query databases, and delegate to other agents. Once deployed, they make decisions autonomously. You need answers to three questions:

1. Is this action allowed? An agent with access to send_email and query_database should not be able to drop_table. OAuth scopes and IAM roles control which services an agent can reach, not what it does once connected.

2. Which agent did this? In a multi-agent system, five agents might share a single API key. When something goes wrong, "an agent did it" is not an incident response.

3. Can you prove what happened? Auditors and regulators need tamper-evident records of every decision: what policy was active, what the agent requested, and why it was allowed or denied.

Prompt-level safety ("please follow the rules") is not a control surface. It is a polite request to a stochastic system. OWASP LLM01:2025 states this explicitly: "it is unclear if there are fool-proof methods of prevention for prompt injection." The published numbers back this up. Andriushchenko et al. (ICLR 2025) report 100% attack success rate on GPT-4o, GPT-3.5, Claude 3, and Llama-3 using adaptive attacks with logprob access and suffix optimization, evaluated against the JailbreakBench benchmark (Chao et al., NeurIPS 2024). Microsoft's own AI Red Teaming Agent formalizes Attack Success Rate (ASR), the rate of policy violations under adversarial input, as the canonical metric for this class of failure. Lessons from Red Teaming 100 Generative AI Products reinforces the point: "mitigations do not eliminate risk entirely" and red teaming must be a continuous process because model-layer defenses are probabilistic by construction.

AGT does not try to win that fight inside the prompt. Every tool call, message send, and delegation is intercepted in deterministic application code before the model's intent reaches the wire. Actions the AGT kernel denies are not "unlikely." They are structurally impossible. That is the difference between asking an agent to behave and making it incapable of misbehaving.


Quick Start

Prerequisites: Python 3.10+

pip install agent-governance-toolkit[full]

Use the [full] extra for the quick-start imports below. The base agent-governance-toolkit wheel installs the compliance CLI only; the governance modules live in the consolidated core distribution. The agentmesh quick-start import remains the current wrapper API. The agent_os PolicyEvaluator example below is legacy compatibility: importing agent_os currently emits a DeprecationWarning because the old agent-os-kernel distribution is deprecated. Use agent-governance-toolkit-core (or the [full] extra that includes it) as the replacement distribution, and prefer the AGT 5 agt-policies/ACS APIs for new policy-engine host code.

For Claude Code, add AGT as a plugin marketplace and install the governance plugin:

/plugin marketplace add microsoft/agent-governance-toolkit
/plugin install agt-governance@agent-governance-toolkit

Govern any tool function in two lines:

from agentmesh.governance import govern

safe_tool = govern(my_tool, policy="policy.yaml")   # every call checked, logged, enforced

That's it. safe_tool evaluates your YAML policy on every call, logs the decision, and raises GovernanceDenied if the action is blocked.

# policy.yaml
apiVersion: governance.toolkit/v1
name: production-policy
default_action: allow
rules:
  - name: block-destructive
    condition: "action.type in ['drop', 'delete', 'truncate']"
    action: deny
    description: "Destructive operations require human approval"

  - name: require-approval-for-send
    condition: "action.type == 'send_email'"
    action: require_approval
    approvers: ["security-team"]
>>> safe_tool(action="read", table="users")
{'table': 'users', 'rows': 42}

>>> safe_tool(action="drop", table="users")
GovernanceDenied: Action denied by policy rule 'block-destructive':
  Destructive operations require human approval

Or use the full PolicyEvaluator API for programmatic control:

PolicyEvaluator example
from agent_os.policies import (
    PolicyEvaluator, PolicyDocument, PolicyRule,
    PolicyCondition, PolicyAction, PolicyOperator, PolicyDefaults
)

evaluator = PolicyEvaluator(policies=[PolicyDocument(
    name="my-policy", version="1.0",
    defaults=PolicyDefaults(action=PolicyAction.ALLOW),
    rules=[PolicyRule(
        name="block-dangerous-tools",
        condition=PolicyCondition(
            field="tool_name",
            operator=PolicyOperator.IN,
            value=["execute_code", "delete_file"]
        ),
        action=PolicyAction.DENY, priority=100,
    )],
)])

result = evaluator.evaluate({"tool_name": "web_search"})    # Allowed
result = evaluator.evaluate({"tool_name": "delete_file"})   # Blocked
TypeScript / .NET / Rust / Go examples

TypeScript

import { PolicyEngine } from "@microsoft/agent-governance-sdk";

const engine = new PolicyEngine([
  { action: "web_search", effect: "allow" },
  { action: "shell_exec", effect: "deny" },
]);
engine.evaluate("web_search"); // "allow"
engine.evaluate("shell_exec"); // "deny"

.NET

using AgentGovernance;
using AgentGovernance.Extensions.ModelContextProtocol;
using AgentGovernance.Policy;

var kernel = new GovernanceKernel(new GovernanceOptions
{
    PolicyPaths = new() { "policies/default.yaml" },
});
var result = kernel.EvaluateToolCall("did:mesh:agent-1", "web_search",
    new() { ["query"] = "latest AI news" });

// MCP server integration
builder.Services.AddMcpServer()
    .WithGovernance(options => options.PolicyPaths.Add("policies/mcp.yaml"));

Rust

use agent_governance::{AgentMeshClient, ClientOptions};

let client = AgentMeshClient::new("my-agent").unwrap();
let result = client.execute_with_governance("data.read", None);
assert!(result.allowed);

Go

import agentmesh "github.com/microsoft/agent-governance-toolkit/agent-governance-golang"

client, _ := agentmesh.NewClient("my-agent",
    agentmesh.WithPolicyRules([]agentmesh.PolicyRule{
        {Action: "data.read", Effect: agentmesh.Allow},
        {Action: "*", Effect: agentmesh.Deny},
    }),
)
result := client.ExecuteWithGovernance("data.read", nil)

CLI tools:

agt doctor                                        # check installation
agt verify                                        # OWASP compliance check
agt verify --evidence ./agt-evidence.json --strict # fail CI on weak evidence
agt red-team scan ./prompts/ --min-grade B         # prompt injection audit
agt lint-policy policies/                          # validate policy files

Full walkthrough: quickstart.md -- zero to governed agents in 5 minutes. 🌍 Also in: 日本語 | 简体中文 | 한국어


How It Works

Agent ──► Policy Engine ──► Identity ──► Audit Log
            (YAML/OPA/Cedar)  (SPIFFE/DID/mTLS)  (Tamper-evident)
                 │                                      │
                 ├── Allowed ──► Tool executes           │
                 └── Denied  ──► GovernanceDenied        │
                                                        ▼
                                                 Decision Record

Every layer is optional. Start with govern() and add layers as your risk profile grows. Most teams run policy enforcement + audit logging and never need the full stack.


Packages

Package Description
Agent OS Policy engine, agent lifecycle, governance gate
Agent Control Specification (README) Stateless, deterministic, fail-closed policy decision runtime (Rust core) backing the AGT policy layer
Agent Mesh Agent discovery, routing, and trust mesh
Agent Runtime Execution sandboxing with four privilege rings
Agent SRE Kill switch, SLO monitoring, chaos testing
Agent Compliance OWASP verification, policy linting, integrity checks
Agent Marketplace Plugin governance and trust scoring
Agent Lightning RL training governance with violation penalties
Agent Hypervisor Execution audit, delta engine, in-memory commitment tracking, command denylist enforcement

Additional Capabilities

Capability Description
MCP Security Gateway Tool poisoning detection, drift monitoring, typosquatting, hidden instruction scanning (Spec)
Shadow AI Discovery Find unregistered agents across processes, configs, and repos (Discovery)
Governance Dashboard Real-time fleet visibility for health, trust, and compliance (Dashboard)
PromptDefense Evaluator 12-vector prompt injection audit (Evaluator)
Contributor Reputation PR/issue author screening for social engineering. Reusable GitHub Action (Action)

Install

Language Package Command
Python agent-governance-toolkit pip install agent-governance-toolkit[full]
TypeScript @microsoft/agent-governance-sdk npm install @microsoft/agent-governance-sdk
Copilot CLI @microsoft/agent-governance-copilot-cli npx @microsoft/agent-governance-copilot-cli install
Claude Code @microsoft/agent-governance-claude-code claude --plugin-dir ./agent-governance-claude-code
OpenCode @microsoft/agent-governance-opencode npm install @microsoft/agent-governance-opencode
.NET Microsoft.AgentGovernance dotnet add package Microsoft.AgentGovernance
.NET MCP Microsoft.AgentGovernance.Extensions.ModelContextProtocol dotnet add package Microsoft.AgentGovernance.Extensions.ModelContextProtocol
Rust agent-governance cargo add agent-governance
Go agent-governance-toolkit go get github.com/microsoft/agent-governance-toolkit/agent-governance-golang

All five language SDKs implement core governance (policy, identity, trust, audit). Python has the full stack. Copilot CLI and Claude Code are first-party developer surfaces built on the TypeScript SDK. See Language Package Matrix for detailed per-language coverage.

Python distributions (v4.1.0 — consolidated)

As of v4.1.0, 45 packages have been consolidated into 5 top-level distributions:

Distribution PyPI What's included
agent-governance-toolkit-core agent-governance-toolkit-core Policy engine, capability model, audit, MCP gateway, zero-trust identity, trust scoring, A2A/MCP/IATP bridges
agent-governance-toolkit-runtime agent-governance-toolkit-runtime Privilege rings, saga orchestration, termination control, execution plan validation, command denylist enforcement
agent-governance-toolkit-sre agent-governance-toolkit-sre SLOs, error budgets, chaos engineering, circuit breakers
agent-governance-toolkit-cli agent-governance-toolkit-cli agt CLI, OWASP verification, integrity checks, policy linting
agent-governance-toolkit[full] agent-governance-toolkit Meta-package installing all of the above

Previous package names (agent-os-kernel, agentmesh-platform, agentmesh-runtime, agent-sre, agent-discovery, agent-hypervisor, agentmesh-marketplace, agentmesh-lightning) remain installable as stub packages that redirect to the consolidated distributions.

Prerequisites

  • Python: 3.10+
  • Node.js: 18+ / npm 9+ (TypeScript SDK)
  • .NET: 8+
  • Go: 1.25+
  • Rust: 1.70+
  • Optional: AZURE_CLIENT_ID, AZURE_TENANT_ID, AZURE_CLIENT_SECRET for Azure-integrated features

Framework Support

Framework Integration
Microsoft Agent Framework Native Middleware
Semantic Kernel Native (.NET + Python)
AutoGen Adapter
LangGraph / LangChain Adapter
CrewAI Adapter
OpenAI Agents SDK Middleware
Claude Code Governance plugin package
Google ADK Adapter
LlamaIndex Middleware
Haystack Pipeline
Mastra Adapter
Dify Plugin
Azure AI Foundry Deployment Guide
GitHub Copilot CLI Governance installer

Full list: Framework Integrations · Quickstart Examples


Examples

Example Framework What it demonstrates
openai-agents-governed OpenAI Agents SDK Policy-gated tool calls with trust tiers
crewai-governed CrewAI Multi-agent governance with role-based policies
smolagents-governed HuggingFace smolagents Lightweight agent governance
maf-integration MAF Microsoft Agent Framework integration
mcp-trust-verified-server MCP Trust-verified MCP server implementation
cedarling-governed Cedar/Cedarling Janssen Cedarling policy engine integration
governance-dashboard Streamlit Real-time fleet visibility dashboard

Specifications

Every major component has a formal RFC 2119 specification with conformance tests. These specs define the behavioral contract: what implementations MUST, SHOULD, and MAY do.

Specification Scope Tests
Agent OS Policy Engine Policy evaluation, rule merging, fail-closed semantics 68
Agent Control Specification Stateless intervention-point policy runtime, verdicts, transform, fail-closed --
AgentMesh Identity and Trust Credentials, trust scoring, delegation chains 135
Agent Hypervisor Execution Control Privilege rings, saga orchestration, kill switch 80
AgentMesh Trust and Coordination Peer trust negotiation, mesh-wide policy 62
Agent SRE Governance SLOs, error budgets, chaos, circuit breakers 111
MCP Security Gateway Tool poisoning, drift detection, hidden instructions 127
Agent Lightning Fast-Path RL training governance, violation penalties 100
Framework Adapter Contract 10 adapter integrations, interceptor chain 152
Audit and Compliance Merkle audit, compliance mapping, Decision BOM 157
AgentMesh Wire Protocol Message format, routing, serialization --

992 conformance tests ensure code stays aligned to specs. 29 Architecture Decision Records document why.


Standards Compliance

Standard Coverage
OWASP Agentic AI Top 10 All ASI risk categories mapped with deterministic controls
NIST AI RMF 1.0 Full GOVERN, MAP, MEASURE, MANAGE alignment
EU AI Act Compliance mapping with automated evidence
SOC 2 Control mapping with audit trail export
AARM Extended All R1–R9 requirements satisfied; verified Jun 14, 2026
ATF All five elements mapped: Agent Mesh (identity), Agent OS (policy), Agent Compliance (governance), Agent Runtime (sandboxing), Agent SRE (incident response)

Security

AGT enforces governance at the application middleware layer, not at the OS kernel level. The policy engine and agents share the same process boundary.

Production recommendation: Run each agent in a separate container for OS-level isolation. See Architecture: Security Boundaries.

Tool Coverage
CodeQL Python + TypeScript SAST
Gitleaks Secret scanning on PR/push/weekly
ClusterFuzzLite 7 fuzz targets (policy, injection, MCP, sandbox, trust)
Dependabot 13 ecosystems
OpenSSF Scorecard Weekly scoring + SARIF upload

See Known Limitations for honest design boundaries and recommended layered defense.


Documentation

Category Links
Getting Started Quick Start · Tutorials (60+) · FAQ
Architecture System Design · Threat Model · ADRs (29)
Specifications All Specs (10 formal specs, 992 conformance tests)
API Reference Agent OS · AgentMesh · Agent SRE
Compliance OWASP · EU AI Act · NIST AI RMF · SOC 2 · AARM Extended · ATF
Deployment Azure · AWS · GCP · Docker Compose
Extensions VS Code · Framework Integrations

Contributing

Contributing Guide · Community · Discord · Security Policy · Changelog

Using AGT? Add your organization to ADOPTERS.md.

Governance

Document Purpose
GOVERNANCE.md Decision-making, roles, contributor ladder
CHARTER.md Technical charter (LF Projects format)
MAINTAINERS.md Maintainers and organizations
SECURITY.md Vulnerability reporting and response SLAs
CODE_OF_CONDUCT.md Microsoft Open Source Code of Conduct
ANTITRUST.md Competition law guidelines for participants
TRADEMARKS.md Trademark usage policy

Important Notes

If you use the Agent Governance Toolkit to build applications that operate with third-party agent frameworks or services, you do so at your own risk. We recommend reviewing all data being shared with third-party services and being cognizant of third-party practices for retention and location of data.

Official Sources

The only official sources for the Agent Governance Toolkit are:

Resource Location
Source code github.com/microsoft/agent-governance-toolkit
Documentation microsoft.github.io/agent-governance-toolkit
Python packages pypi.org/user/agentgovtoolkit
npm packages @microsoft/agent-governance-sdk on npmjs.com
NuGet packages Microsoft.AgentGovernance.* on nuget.org
Rust crates agent-governance, agent-governance-mcp on crates.io

The project team does not maintain or endorse any third-party websites, packages, or documentation sites claiming to be official. If you encounter a suspicious site or package using the Agent Governance Toolkit name, please report it through the channels described in SECURITY.md.

License

This project is licensed under the MIT License.

Trademarks

This project may contain trademarks or logos for projects, products, or services. Authorized use of Microsoft trademarks or logos is subject to and must follow Microsoft's Trademark & Brand Guidelines. Use of Microsoft trademarks or logos in modified versions of this project must not cause confusion or imply Microsoft sponsorship. Any use of third-party trademarks or logos are subject to those third-party's policies.

View on GitHub

Recent activity

commits and pull requests

Releases and announcements

19 total
  1. v4.1.0v4.1.0Jun 9, 202652 downloads

    ## What's New in v4.1.0 ### Agent OS (Nexus) - Ed25519 signature verification for agent registration and deregistration - Escrow signing support in ProofOfOutcome - Crewai adapter fixes ### Policy Engine - Dynamic policy conditions with time-based and cost-aware rules - Updated Cedar policy versions - agt-policies 5.0.0 ### All Packages See [CHANGELOG](CHANGELOG.md) for full details.

  2. v4.0.0v4.0.0Jun 1, 202639 downloads

    # Agent Governance Toolkit v4.0.0 **Ship agents to production without losing sleep** -- now with consolidated packages, TEE key management, and Entra JWT verification across the mesh. ## Highlights ### Python Package Consolidation (Breaking) 45 Python packages consolidated into 5 clean distributions: | Distribution | What is included | |---|---| | agent-governance-toolkit-core | Policy engine, capability model, audit, MCP gateway, identity, trust scoring | | agent-governance-toolkit-runtime | Privilege rings, saga orchestration, termination control | | agent-governance-toolkit-sre | SLOs, error budgets, chaos engineering, circuit breakers | | agent-governance-toolkit-cli | agt CLI, OWASP verification, integrity checks, policy linting | | agent-governance-toolkit[full] | Meta-package installing all of the above | Old package names (agent-os-kernel, agentmesh-platform, etc.) remain as stub redirects for migration. ### New Capabilities - **TEE keystore abstraction** (ADR 0010): async key management with TEEKeyHandle, SoftwareKeyHandle, and attested key store adapters - **Entra-signed JWT verification** for mesh-relay WebSocket connections and mesh-regist

  3. v3.7.0v3.7.0May 18, 202682 downloads

    # Agent Governance Toolkit v3.7.0 **Release Date:** 2026-05-18 > [!IMPORTANT] > **Public Preview** - All packages published from this repository are > **Microsoft-signed public preview releases**. They are production-quality but > may have breaking changes before GA. ## Highlights ### Version Bump and Release Hygiene v3.7.0 opens the next development cycle with full release documentation for the v3.6.0 milestone that was previously undocumented. ### Tool Usage Policies (oracle/agent-spec) Contributed the `ToolPolicy` schema to the Agent Spec standard (PR #191), enabling declarative rate-limit, approval, and justification guards on tool invocations. AGT will adopt the ratified schema once merged upstream. ## Added - **v3.6.0 release notes** documenting the full scope of the previous release - **Presentation demos** committed to `examples/demos/presentation/` (6 offline scripts) - **EU AI Act demo** Windows UTF-8 fix - **StdoutAuditSink** overlapping merge fix - **Repo structure** simplified with layout guide - **Tutorials** reorganized into customer-centric categories ## Packages | Package | Version | |---------|---------| | `agent-governance-toolkit` (meta) | 3.7.0 | | `

  4. v3.6.0v3.6.0May 18, 202664 downloads

    # Agent Governance Toolkit v3.6.0 **Release Date:** 2026-05-12 > [!IMPORTANT] > **Public Preview** - All packages published from this repository are > **Microsoft-signed public preview releases**. They are production-quality but > may have breaking changes before GA. ## Highlights ### Formal Specifications Published v3.6.0 formalizes the governance architecture with six specification documents: - **AgentMesh Identity and Trust** v1.0 - DID lifecycle, Ed25519 signatures, trust scoring - **AgentMesh Trust and Coordination** v1.0 - handshake protocol, capability delegation - **Agent Hypervisor Execution Control** v1.0 - privilege rings, resource quotas, isolation - **Agent SRE Governance** v1.0 - SLOs, error budgets, anomaly detection - **MCP Security Gateway** v1.0 - tool allowlists, PII scanning, SSRF prevention - **Framework Adapter Contract** v1.0 - SPI for pluggable framework integration - **Audit and Compliance** v1.0 - Merkle-chained logs, retention, evidence export ### Security Hardening Sprint 319 fixes including: - Path traversal guards across SRE, signing, and spec modules - SSRF blocklist expansion (.NET OPA backend, TypeScript Cedar) - HMAC verification before non

  5. v3.5.0v3.5.0May 8, 202633 downloads

    ## Highlights **Citadel Integration** - Entra identity bridge and APIM policy fragment for enterprise-grade agent identity. Includes Phase 1 (docs, exporter, policy binding) and Phase 2 (Entra bridge, APIM fragment). **Multi-Agent Collective Policies** - evaluate constraints (rate limits, concurrent caps) across all agents in a workflow, not just individual agents. **Decision BOM Reconstructible View** - reconstruct the full decision lineage for any agent action from observability signals, with resilient partial reconstruction when sources are unavailable. **Intent-Based Authorization** - declare/approve/execute/verify lifecycle with drift detection for multi-agent orchestration. **Cost Governance** - tiered budgets (per-task, per-agent, org-wide), auto-throttle, kill switches, and anomaly detection. **Centralized Version Management** - single \VERSION\ file and \scripts/sync-version.py\ propagates version across Python, TypeScript, .NET, and Rust. ## Added - Citadel Phase 1 and Phase 2 (#1778, #1785) - Multi-agent collective policy evaluator (#1776) - Decision BOM reconstructible view (#1777) - Intent-Based Authorization (Tutorial 48, #1781) - Cost Governance (Tutorial 51,

Commits per week

last 52 weeks
4010Week of 2025-08-02: 0 commitsWeek of 2025-08-09: 0 commitsWeek of 2025-08-16: 0 commitsWeek of 2025-08-23: 0 commitsWeek of 2025-08-30: 0 commitsWeek of 2025-09-06: 0 commitsWeek of 2025-09-13: 0 commitsWeek of 2025-09-20: 0 commitsWeek of 2025-09-27: 0 commitsWeek of 2025-10-04: 0 commitsWeek of 2025-10-11: 0 commitsWeek of 2025-10-18: 0 commitsWeek of 2025-10-25: 0 commitsWeek of 2025-11-01: 0 commitsWeek of 2025-11-09: 0 commitsWeek of 2025-11-16: 0 commitsWeek of 2025-11-23: 0 commitsWeek of 2025-11-30: 0 commitsWeek of 2025-12-07: 0 commitsWeek of 2025-12-14: 0 commitsWeek of 2025-12-21: 0 commitsWeek of 2025-12-28: 0 commitsWeek of 2026-01-04: 0 commitsWeek of 2026-01-11: 0 commitsWeek of 2026-01-18: 0 commitsWeek of 2026-01-25: 0 commitsWeek of 2026-02-01: 0 commitsWeek of 2026-02-08: 0 commitsWeek of 2026-02-15: 0 commitsWeek of 2026-02-22: 0 commitsWeek of 2026-03-01: 62 commitsWeek of 2026-03-08: 55 commitsWeek of 2026-03-15: 77 commitsWeek of 2026-03-22: 96 commitsWeek of 2026-03-29: 144 commitsWeek of 2026-04-05: 95 commitsWeek of 2026-04-12: 84 commitsWeek of 2026-04-19: 188 commitsWeek of 2026-04-26: 147 commitsWeek of 2026-05-03: 129 commitsWeek of 2026-05-10: 401 commitsWeek of 2026-05-17: 161 commitsWeek of 2026-05-24: 100 commitsWeek of 2026-05-31: 100 commitsWeek of 2026-06-07: 114 commitsWeek of 2026-06-14: 94 commitsWeek of 2026-06-21: 44 commitsWeek of 2026-06-28: 29 commitsWeek of 2026-07-05: 36 commitsWeek of 2026-07-12: 21 commitsWeek of 2026-07-19: 41 commitsWeek of 2026-07-26: 1 commitsAug 2, 2025Jul 26, 2026
2.2K commits in the last 52 weeks.

When work happens

weekday and hour
SunMonTueWedThuFriSat036912151821Sun 0:00 — 5 commitsSun 1:00 — 2 commitsSun 2:00 — 8 commitsSun 3:00 — 1 commitsSun 4:00 — 7 commitsSun 5:00 — 4 commitsSun 6:00 — 0 commitsSun 7:00 — 3 commitsSun 8:00 — 1 commitsSun 9:00 — 7 commitsSun 10:00 — 9 commitsSun 11:00 — 15 commitsSun 12:00 — 19 commitsSun 13:00 — 65 commitsSun 14:00 — 29 commitsSun 15:00 — 17 commitsSun 16:00 — 19 commitsSun 17:00 — 11 commitsSun 18:00 — 19 commitsSun 19:00 — 16 commitsSun 20:00 — 10 commitsSun 21:00 — 4 commitsSun 22:00 — 10 commitsSun 23:00 — 1 commitsMon 0:00 — 4 commitsMon 1:00 — 19 commitsMon 2:00 — 1 commitsMon 3:00 — 1 commitsMon 4:00 — 2 commitsMon 5:00 — 3 commitsMon 6:00 — 5 commitsMon 7:00 — 10 commitsMon 8:00 — 29 commitsMon 9:00 — 12 commitsMon 10:00 — 10 commitsMon 11:00 — 48 commitsMon 12:00 — 22 commitsMon 13:00 — 36 commitsMon 14:00 — 47 commitsMon 15:00 — 21 commitsMon 16:00 — 20 commitsMon 17:00 — 35 commitsMon 18:00 — 8 commitsMon 19:00 — 7 commitsMon 20:00 — 13 commitsMon 21:00 — 12 commitsMon 22:00 — 35 commitsMon 23:00 — 3 commitsTue 0:00 — 4 commitsTue 1:00 — 1 commitsTue 2:00 — 16 commitsTue 3:00 — 2 commitsTue 4:00 — 7 commitsTue 5:00 — 0 commitsTue 6:00 — 3 commitsTue 7:00 — 5 commitsTue 8:00 — 75 commitsTue 9:00 — 13 commitsTue 10:00 — 45 commitsTue 11:00 — 105 commitsTue 12:00 — 30 commitsTue 13:00 — 26 commitsTue 14:00 — 9 commitsTue 15:00 — 50 commitsTue 16:00 — 41 commitsTue 17:00 — 22 commitsTue 18:00 — 17 commitsTue 19:00 — 14 commitsTue 20:00 — 13 commitsTue 21:00 — 39 commitsTue 22:00 — 32 commitsTue 23:00 — 5 commitsWed 0:00 — 1 commitsWed 1:00 — 3 commitsWed 2:00 — 1 commitsWed 3:00 — 3 commitsWed 4:00 — 3 commitsWed 5:00 — 1 commitsWed 6:00 — 1 commitsWed 7:00 — 4 commitsWed 8:00 — 23 commitsWed 9:00 — 14 commitsWed 10:00 — 24 commitsWed 11:00 — 16 commitsWed 12:00 — 21 commitsWed 13:00 — 27 commitsWed 14:00 — 21 commitsWed 15:00 — 28 commitsWed 16:00 — 21 commitsWed 17:00 — 10 commitsWed 18:00 — 2 commitsWed 19:00 — 17 commitsWed 20:00 — 12 commitsWed 21:00 — 23 commitsWed 22:00 — 14 commitsWed 23:00 — 19 commitsThu 0:00 — 3 commitsThu 1:00 — 3 commitsThu 2:00 — 2 commitsThu 3:00 — 2 commitsThu 4:00 — 1 commitsThu 5:00 — 2 commitsThu 6:00 — 13 commitsThu 7:00 — 1 commitsThu 8:00 — 10 commitsThu 9:00 — 16 commitsThu 10:00 — 11 commitsThu 11:00 — 36 commitsThu 12:00 — 15 commitsThu 13:00 — 14 commitsThu 14:00 — 9 commitsThu 15:00 — 15 commitsThu 16:00 — 19 commitsThu 17:00 — 8 commitsThu 18:00 — 20 commitsThu 19:00 — 5 commitsThu 20:00 — 6 commitsThu 21:00 — 19 commitsThu 22:00 — 8 commitsThu 23:00 — 0 commitsFri 0:00 — 5 commitsFri 1:00 — 8 commitsFri 2:00 — 6 commitsFri 3:00 — 2 commitsFri 4:00 — 0 commitsFri 5:00 — 2 commitsFri 6:00 — 3 commitsFri 7:00 — 2 commitsFri 8:00 — 8 commitsFri 9:00 — 23 commitsFri 10:00 — 9 commitsFri 11:00 — 22 commitsFri 12:00 — 50 commitsFri 13:00 — 33 commitsFri 14:00 — 6 commitsFri 15:00 — 22 commitsFri 16:00 — 14 commitsFri 17:00 — 5 commitsFri 18:00 — 6 commitsFri 19:00 — 8 commitsFri 20:00 — 11 commitsFri 21:00 — 13 commitsFri 22:00 — 6 commitsFri 23:00 — 1 commitsSat 0:00 — 3 commitsSat 1:00 — 1 commitsSat 2:00 — 1 commitsSat 3:00 — 2 commitsSat 4:00 — 3 commitsSat 5:00 — 0 commitsSat 6:00 — 1 commitsSat 7:00 — 1 commitsSat 8:00 — 8 commitsSat 9:00 — 12 commitsSat 10:00 — 11 commitsSat 11:00 — 7 commitsSat 12:00 — 4 commitsSat 13:00 — 20 commitsSat 14:00 — 29 commitsSat 15:00 — 11 commitsSat 16:00 — 10 commitsSat 17:00 — 8 commitsSat 18:00 — 11 commitsSat 19:00 — 11 commitsSat 20:00 — 15 commitsSat 21:00 — 18 commitsSat 22:00 — 14 commitsSat 23:00 — 3 commits
Commit volume by weekday and hour (UTC). Larger dots mean more commits.
DateListRankStars gained
Jul 30, 2026daily#7+46
Jul 29, 2026daily#7+46
  • public-apis/public-apis

    A collective list of free APIs

    454.9K stars · Python

  • donnemartin/system-design-primer

    Learn how to design large-scale systems. Prep for the system design interview. Includes Anki flashcards.

    362.2K stars · Python

  • practical-tutorials/project-based-learning

    Curated list of project-based tutorials

    277.2K stars · Python

  • affaan-m/ECC

    The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.

    238.5K stars · JavaScript

  • trimstray/the-book-of-secret-knowledge

    A collection of inspiring lists, manuals, cheatsheets, blogs, hacks, one-liners, cli/web tools and more.

    237.2K stars

  • affaan-m/ECC

    The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.

    234.7K stars · JavaScript