About Guardian Agents

Important Guardian Agents are available in private preview. Details in this topic are based on pre-release designs and an early build, and are subject to change before general availability.

A Guardian Agent is a runtime system that monitors an AI agent's actions against its Contract, the combined set of rules that currently apply to that agent. Guardian evaluates each action the agent takes against the Contract and records a verdict.

Verdicts

Guardian records one of the following verdicts for each action it evaluates:

  • Allow: The action doesn't violate the Contract and executes normally. Allowed actions aren't shown in the issue log.
  • Deny: The action is blocked and does not execute.
  • Escalate: The Contract doesn't clearly cover the action, so it's logged for human review. Guardian is human-over-the-loop rather than human-in-the-loop, so the action isn't paused waiting for approval; review happens after the fact.
  • Flag: The action executes, but is logged as a violation for review.
  • Rewrite: The action's content is modified, for example to redact sensitive data, before it executes.

Note The verdict names and their exact behavior are based on an early build and may change before general availability. A dedicated review surface for Escalate verdicts, and a suggested-rule-change loop based on patterns across escalations, are both still being designed and aren't available in this private preview.

Guardian Agent log

For an AI Agent asset with Guardian enabled, the asset page's Guardian tab shows:

  • An Agent action pass rate over time chart: a stacked bar chart showing the daily proportion of the agent's actions that passed versus failed Guardian evaluation.
  • An Issue log table listing each action Guardian intervened on, with the date, verdict, the technical identifier of the issue (for example, block_email or redact_customer_email), the agent version involved, and the specific Contract rule that was violated. You can filter by agent version, agent deployment, verdict, date range, and status.

The same pass rate chart and issue log are also summarized across every agent with Guardian enabled, on the dedicated Guardian agents item in the AI Command Center sidebar navigation. That environment-level view adds an Agent column and filter, and its own summary cards for pass rate, open issues, and the number of agents using Guardian appear on the Agent Contracts page.

What's next