Free policy template
AI Agent Governance Policy Template
This template is a practical starting point, not legal advice. Replace bracketed choices with rules your teams can actually follow and verify.
1. Purpose and scope
“This policy defines how [Organisation] records, reviews, approves and monitors AI agents that access business data or tools. It applies to employees, contractors and service providers who build or operate those workflows.”
- Define what your organisation treats as an AI agent.
- State which environments, teams and third parties are covered.
- Name the policy owner and review cadence.
2. Inventory and ownership
“Every active AI agent must have a current inventory record, a named business owner and a technical contact before production use.”
- Record purpose, status, department and affected process.
- List connected tools, data categories and effective permissions.
- Review ownership when people or suppliers change.
- Retire or reassign agents with no active owner.
3. Access and approval
“Agent access must be limited to the stated purpose. High-impact actions require an approval control unless a documented exception is active.”
- Use separate credentials where practical.
- Avoid broad write access when read access is sufficient.
- Define approval for external, financial, destructive or legal actions.
- Set amount, destination, rate or scope limits where relevant.
4. Logging, monitoring and stop controls
“Meaningful agent actions must be attributable and reviewable. Each business-critical workflow must have a documented way to pause execution and revoke access.”
- Define which actions and decisions are logged.
- Set retention and review responsibility.
- Test the pause or kill procedure.
- Document incident escalation and evidence preservation.
5. Risk review and exceptions
“Agents must be reviewed before production use and after material changes. Accepted risks require a justification, accountable approver and expiry date.”
- Set review frequency based on business impact.
- Track remediation in an owned action plan.
- Do not hide accepted findings or reduce the raw score.
- Review exceptions before they expire.
Practical advice
Keep the policy short enough to use. Put detailed technical standards in separate guidance and link them from the policy.
Test the policy against a real agent before approval. If the owner cannot provide the required record or approval evidence, simplify the process or make responsibility clearer.
FAQ
Questions people ask before a review
Connect policy rules to real agent records.
Use Roxea to document ownership, approval, exceptions and review evidence across your inventory.