Only read files in the approved support folder.
Read the customer’s ticket.
The requested path belongs to the support workspace.
Read production credentials.
The requested path points outside the approved folder.
Let agents do useful work with clear limits on the files, tools and destinations they can reach. Apply those rules through Oktsec Control at the configured integration.
The agent needs to resolve a ticket. Changing a file path, destination or message should not give it new authority.
Only read files in the approved support folder.
The requested path belongs to the support workspace.
The requested path points outside the approved folder.
Only send requests to the approved support system.
The request goes to an approved destination.
The ticket asks for a transfer to a domain outside the allowlist.
Block configured credential findings in visible content.
The message contains the case summary without detected credential findings.
The visible message matches a configured credential-blocking rule.
Illustrative policy decisions, not recorded test results. Configure and test the relevant integration before relying on a control.
Allow the tools needed for the task and constrain the parameters they receive.
Restrict routed traffic by domain. Encrypted HTTPS bodies remain outside content inspection.
Scan supported messages and tool traffic for configured credential and threat patterns.
Direct SDK calls, native shell access and unwrapped tools may bypass these controls. Include those paths in the evaluation.
Review Control’s architectureUse a legitimate task and a request that must be refused. Test both in the environment your agents will use.
Confirm the proposed policy allows the agent to finish its assigned work.
Change a path or destination. Check the decision and whether the request reached the next system.
Test bypass routes and inspect the records available for the integration.
AI agent data protection limits how agents access, use and transfer sensitive information. Oktsec Control applies configured tool, parameter, content and destination rules at supported integrations. Assessment tests the agreed workflow for exposure and bypass paths.
Supported MCP gateway integrations can apply allowed and blocked patterns to configured tool parameters. These rules govern the arguments presented to the gateway; filesystem permissions and the tool implementation remain part of the security boundary.
No. An HTTPS CONNECT tunnel can be governed by destination rules, but its encrypted body is not inspected. Content scanning requires a supported integration where Node can see the relevant message or request.
Coverage is scoped to the configured integrations and supported traffic. Direct network access, unwrapped tools or other bypass routes need separate controls and testing. Detection rules do not guarantee that every secret or sensitive record will be recognized.
Describe one agent workflow, the data it needs, the tools it uses and the destinations it should reach. Agree on allowed and denied cases, deployment coverage and expected evidence. Do not include credentials or customer data in the inquiry form.
We’ll identify the integration, the relevant controls and the allowed and denied cases to test.