Free policy template

AI Agent Governance Policy Template

This template is a practical starting point, not legal advice. Replace bracketed choices with rules your teams can actually follow and verify.

1

1. Purpose and scope

“This policy defines how [Organisation] records, reviews, approves and monitors AI agents that access business data or tools. It applies to employees, contractors and service providers who build or operate those workflows.”

  • Define what your organisation treats as an AI agent.
  • State which environments, teams and third parties are covered.
  • Name the policy owner and review cadence.
2

2. Inventory and ownership

“Every active AI agent must have a current inventory record, a named business owner and a technical contact before production use.”

  • Record purpose, status, department and affected process.
  • List connected tools, data categories and effective permissions.
  • Review ownership when people or suppliers change.
  • Retire or reassign agents with no active owner.
3

3. Access and approval

“Agent access must be limited to the stated purpose. High-impact actions require an approval control unless a documented exception is active.”

  • Use separate credentials where practical.
  • Avoid broad write access when read access is sufficient.
  • Define approval for external, financial, destructive or legal actions.
  • Set amount, destination, rate or scope limits where relevant.
4

4. Logging, monitoring and stop controls

“Meaningful agent actions must be attributable and reviewable. Each business-critical workflow must have a documented way to pause execution and revoke access.”

  • Define which actions and decisions are logged.
  • Set retention and review responsibility.
  • Test the pause or kill procedure.
  • Document incident escalation and evidence preservation.
5

5. Risk review and exceptions

“Agents must be reviewed before production use and after material changes. Accepted risks require a justification, accountable approver and expiry date.”

  • Set review frequency based on business impact.
  • Track remediation in an owned action plan.
  • Do not hide accepted findings or reduce the raw score.
  • Review exceptions before they expire.
6

Practical advice

Keep the policy short enough to use. Put detailed technical standards in separate guidance and link them from the policy.

Test the policy against a real agent before approval. If the owner cannot provide the required record or approval evidence, simplify the process or make responsibility clearer.

FAQ

Questions people ask before a review

Connect policy rules to real agent records.

Use Roxea to document ownership, approval, exceptions and review evidence across your inventory.

Start an agent audit