NIST AI RMF concepts
Intent, risk budgets, monitoring, traceability, human approval, and documented limitations can support governance workflows. Agent Guard is not NIST-certified.
Agent Guard can provide local technical controls and evidence. Organizations remain responsible for model risk, authorization, legal basis, policy design, human oversight, vendor review, retention, and incident response.
This page explains product practices and is not a certification or legal opinion.
| Topic | Product practice | Evidence and boundary |
|---|---|---|
| Authorization | Per-origin grants and optional permissions | Access is requested only for sites the user chooses to authorize. |
| Purpose and intent | Intent contracts | Define allowed sites, actions, data categories, destinations, expiry, and budgets. |
| Human oversight | Approval Gate and fresh-user-presence requirements | Pause supported high-impact actions before commit and require explicit approval. |
| Data minimization | Category-only persistent audit | Transient raw values are not intentionally retained; exports use redacted metadata. |
| Traceability | Local event timeline, lineage, session diff, and hash chaining | Support review of policy input, decision, approval, action, and result. |
| Administrative control | Managed policy and signed policy packs | Allow organizational defaults and constrained local overrides when deployed by administrators. |
| Fail-safe operation | Guard Health, profiles, risk budgets, Panic Lock | Expose coverage state and provide bounded controls for supported actions. |
| User control | Revocable permissions, rules, history, and grants | Users or administrators can remove access and clear local state. |
Intent, risk budgets, monitoring, traceability, human approval, and documented limitations can support governance workflows. Agent Guard is not NIST-certified.
Local policies, responsibilities, evidence, change review, and controls may support an AI management system. Certification applies to an organization and audited management system—not this extension alone.
Prompt injection, excessive agency, tool misuse, sensitive-data exposure, and inadequate monitoring are relevant design concerns. Coverage depends on supported browser-visible channels.
Category minimization and local storage can reduce exposure, but controllers and processors must separately determine lawful basis, notices, rights handling, retention, and vendor obligations.