microsoftSecurity & privacy
Agent Governance Toolkit
agent-governance-toolkit
A governance toolkit for AI agents that adds policy checks, identity, audit trails, sandboxing, and SRE controls across multiple agent frameworks.
- Security
- Backend
- DevOps
- Automation
- Monitoring / Observability
- CLI
- Library/framework
- IDE plugin
- Self-hostable
- Runs locally
- Docker supported
- Popularity
- 6.4k Stars
- GitHub stars
- Recent activity
- 10/1/2026
- Updated in the last 30 days
- License
- MIT
- Permissive
Why it matters
We look beyond stars: what problem it solves, whether it creates real utility, and what makes its approach worth noticing.
Problem
AI agents acting autonomously in production lack deterministic control over tool calls and data access, as prompt safety and basic IAM scopes cannot prevent destructive tool execution or satisfy audit requirements.
Practical value
Provides an application-layer governance kernel that intercepts tool calls deterministically via YAML policies before execution, supporting Python, TypeScript, .NET, Rust, and Go.
Innovation / differentiation
Shifts defense from prompt-level safety requests to deterministic code-level interception, making policy violations structurally impossible rather than merely unlikely.
Leverage potential
Enables rapid integration of policy checks, identities, and sandboxing into existing agent frameworks via lightweight function wrappers or client SDKs.
Why now
Aligns with the urgent industry push to move autonomous AI agents into production while meeting strict compliance and security auditing demands.
Community activity
In the last 90 days there were 144 new issues and 781 pull requests; the bounded issue/PR samples include 34 issue authors and 21 PR contributors, with 0 releases.
Maintainer responsiveness
The 100-issue window sample had a 75% close rate, and the 98-pull-request sample had a 69% merge rate. Maintainer-comment observations covered only 15% of that issue sample, so response rate and first-response speed are not reported.
Key highlights
- Evaluate policy before tool calls, messages, and delegations reach their targets
- Support allow, deny, approval, and auditable decision records
- Add identity, trust, runtime sandboxing, SRE, compliance, and MCP security components
Quick start
How it is installed, how hard it is, and where to start.
Where it runs
Runs locally
Difficulty
Medium — some setup needed
- 01Prepare Python 3.11+ and install the full Python toolkit with
pip install "agent-governance-toolkit[full]". - 02Run
agt doctorto check the installation, then write a YAML policy for the actions that need governance. - 03Wrap tool functions with
govern()and verify the allow, deny, and approval paths. - 04Before production, add audit, identity, container isolation, SRE, or MCP security components according to the risk profile.
Best for
- Teams that want data on their own servers
- Developers who want to try it on their machine
- People who prefer Docker deploys
Watch outs
- 2 inferred from materials — review under Sources below
More about it
Microsoft Agent Governance Toolkit (AGT) places agent tool calls, message sends, and delegations behind deterministic application-level policy checks. In the simplest Python flow, govern() wraps a tool function and evaluates a YAML policy before execution, allowing the host to permit, deny, or require approval while recording the decision.
The project expands into identity and trust, execution sandboxing, audit and compliance, SRE and kill switches, an MCP Security Gateway, and related governance components. SDKs are available for Python, TypeScript, .NET, Rust, and Go, with integrations for agent frameworks and developer surfaces such as Claude Code. The agt CLI covers installation checks, policy linting, compliance verification, and security-oriented validation.
The README explicitly labels the current release as Public Preview and warns that breaking changes may occur before GA. It also states that governance runs at the application middleware layer rather than providing OS-level isolation; separate containers are still recommended for production agent isolation.
Sources
Each field shows its status and source — expand to review.
14 · Expand
Sources
Each field shows its status and source — expand to review.
capability tags
Verifiedsecurity, automation, monitoring
Source: manual_curated · Manually curated from the verified project README; no AI draft. · 8/17/2026
editor note
Verified{"en":"AGT addresses the layer after a model decides to use a tool: deterministic enforcement and audit before the action reaches the target, rather than another safety prompt. It is relevant once agents touch real data or write-capable tools, but the Public Preview status means integrations should allow for API change.","zh":"AGT 解决的是“模型已经决定要调用工具以后,谁来做确定性拦截和审计”这一层问题,而不是再加一段安全 Prompt。它适合开始把 Agent 接入真实数据和写操作的团队,但当前仍是 Public Preview,接口稳定性要留余量。"}
Source: manual_curated · Manually curated from the verified project README; no AI draft. · 8/17/2026
how to use
Verified{"steps":[{"en":"Prepare Python 3.11+ and install the full Python toolkit with `pip install \"agent-governance-toolkit[full]\"`.","zh":"准备 Python 3.11+,执行 `pip install \"agent-governance-toolkit[full]\"` 安装完整 Python 工具包。"},{"en":"Run `agt doctor` to check the installation, then write a YAML policy for the actions that need governance.","zh":"先运行 `agt doctor` 检查安装,再为需要治理的操作编写 YAML 策略。"},{"en":"Wrap tool functions with `govern()` and verify the allow, deny, and approval paths.","zh":"用 `govern()` 包装工具函数,验证允许、拒绝和审批路径是否符合预期。"},{"en":"Before production, add audit, identity, container isolation, SRE, or MCP security components according to the risk profile.","zh":"进入生产前再按风险需要增加审计、身份、容器隔离、SRE 或 MCP 安全组件。"}],"installAt":"local","difficulty":"medium"}
Source: manual_curated · Manually curated from the verified project README; no AI draft. · 8/17/2026
intro
Verified{"en":"Microsoft Agent Governance Toolkit (AGT) places agent tool calls, message sends, and delegations behind deterministic application-level policy checks. In the simplest Python flow, `govern()` wraps a tool function and evaluates a YAML policy before execution, allowing the host to permit, deny, or require approval while recording the decision.\n\nThe project expands into identity and trust, execution sandboxing, audit and compliance, SRE and kill switches, an MCP Security Gateway, and related governance components. SDKs are available for Python, TypeScript, .NET, Rust, and Go, with integrations for agent frameworks and developer surfaces such as Claude Code. The `agt` CLI covers installation checks, policy linting, compliance verification, and security-oriented validation.\n\nThe README explicitly labels the current release as Public Preview and warns that breaking changes may occur before GA. It also states that governance runs at the application middleware layer rather than providing OS-level isolation; separate containers are still recommended for production agent isolation.","zh":"Microsoft Agent Governance Toolkit(AGT)把 Agent 的工具调用、消息发送和委派操作放在确定性的应用层策略检查之后执行。最简单的 Python 用法可以用 `govern()` 包装一个工具函数,再通过 YAML 策略决定允许、拒绝或要求审批,并记录策略判定。\n\n项目进一步提供身份与信任、执行沙箱、审计与合规、SRE/kill switch、MCP Security Gateway 等组件,并有 Python、TypeScript、.NET、Rust 和 Go SDK,以及 Claude Code 等开发工具的接入方式。它也提供 `agt` CLI 用于安装检查、策略校验、合规验证和安全测试。\n\n当前 README 明确标注为 Public Preview,并提醒 GA 前可能有 breaking changes;同时文档说明治理发生在应用中间件层,并不等同于操作系统级隔离。生产环境仍建议将不同 Agent 放入独立容器。"}
Source: manual_curated · Manually curated from the verified project README; no AI draft. · 8/17/2026
Latest release
Verifiedv4.1.0
Source: GitHub API · latest_release=v4.1.0 · 10/1/2026
License
VerifiedMIT
Source: GitHub API · license.spdx_id=MIT · 10/1/2026
needs api key
VerifiedNo
Source: manual_curated · Manually curated from the verified project README; no AI draft. · 8/17/2026
One-liner
Verified{"en":"A governance toolkit for AI agents that adds policy checks, identity, audit trails, sandboxing, and SRE controls across multiple agent frameworks.","zh":"为 AI Agent 工具调用加入策略检查、身份、审计、沙箱与 SRE 控制的治理工具包,可接入多种 Agent 框架。"}
Source: manual_curated · Manually curated from the verified project README; no AI draft. · 8/17/2026
Category hint
Inferred from materialsai-apps
Source: Project README · hint=ai-apps · 8/13/2026
product forms
Verifiedcli, library_framework, ide_plugin
Source: manual_curated · Manually curated from the verified project README; no AI draft. · 8/17/2026
role tags
Verifiedsecurity, backend, devops
Source: manual_curated · Manually curated from the verified project README; no AI draft. · 8/17/2026
supports docker
VerifiedYes
Source: Repository file · dockerfile=true; compose=true · 10/1/2026
supports local
VerifiedYes
Source: manual_curated · Manually curated from the verified project README; no AI draft. · 8/17/2026
supports self host
Inferred from materialsYes
Source: Project README · matched self-host keywords · 8/13/2026
Related projects
Other verified projects matched by category, capabilities, and intended roles.
prismor
A self-hosted runtime security control plane for AI coding agents, providing real-time monitoring, blocking, and human-in-the-loop approval for tool calls.
fleet
A device-management platform for IT and security teams covering MDM, software deployment, patching, inventory queries, and compliance across desktop and mobile operating systems.
openbao
An open-source secrets management system for storing, distributing, rotating, and controlling access to secrets, certificates, and keys.
clusterfuzz
A scalable fuzzing infrastructure developed by Google for automating the discovery of security vulnerabilities and stability issues in software.
vault
An open-source security platform for centralized management, encryption, and auditing of sensitive credentials like API keys, passwords, and certificates.
osv.dev
Open source vulnerability database and triage service providing a unified query API and web interface