SanctumShield · Agentic Governance for the Other 99%

AI Agent Acceptable Use Policy — One-Pager Template

Audience: mid-market organizations (50–2,000 employees) with a 1–3 person security/IT team and no platform-engineering group.

What this is. A one-page, fill-in governance record you complete per AI agent or agent class (e.g., ChatGPT Team, Microsoft Copilot, a Salesforce agent). It is a *distillation* of the full SanctumShield AI Acceptable Use Policy §7 (AI Agent and Agentic Workflow Policy) — designed so a non-technical owner can complete it in under 30 minutes without buying any software. The full AUP remains the governing document; this page is the per-agent operational record §7.2 (Agent Identity Registration) asks you to keep.

The core idea (Cunningham): *the agent's job description IS the policy.* Everything the agent may touch is written down; everything else is prohibited by omission. Any action outside the job description is a reportable incident — detected from the first off-spec tool call, not after the fact.


How to use this template — in plain English

What this is: a one-page record you fill in for each AI tool or agent your organization uses, so everyone knows what it is allowed to do and who is responsible for it. If you can describe a job in a sentence, you can fill this in.

Why the wording is precise (and why that helps you): the fields and terms are exact on purpose — they line up with real AI-governance standards (like the CSA Agentic Trust Framework). That precision is what makes a completed page hold up in front of an auditor, a board, or an insurer. You do not need to be a security expert to use it: just answer each field honestly, in your own words.

How to fill it in (about 30 minutes):

  1. Make one copy for each AI tool or agent (ChatGPT Team, Microsoft Copilot, a Salesforce agent, and so on).
  2. Write its job in one sentence — that sentence is the rule. Anything outside it is off-limits.
  3. List exactly what it may touch (which data, which systems). Everything you don't list is prohibited.
  4. Say how it signs in — its own account or a shared password/key (a shared key is a weakness worth noting).
  5. Pick an autonomy level from the back page. New tools start at Intern (look-only).
  6. Name one accountable person — a name, not a team.
  7. Write 3–5 "never do this" lines, then sign it and set a review date.

What this is NOT (the honest limits):


FRONT OF PAGE — the record (one per agent)

FieldWhat to writeYour entry
Agent name & vendorWhat it is and who makes it.__________________________
Agent identity (non-human)How is this agent identified and authenticated to your systems — *separate from the person who owns it?* Does it have its own unique identity/credential, or a shared API key / login? Mature form: a machine identity (SPIFFE/SVID, Microsoft Entra Agent ID) or the identity your IdP / AI-governance platform assigns per agent. A shared key is a gap — note it and a plan to move to a unique identity.☐ Own unique identity: ______ ☐ Shared key/login (gap → plan: ______)
Job description (persona)One sentence: what was this deployed to do? *This sentence is the policy — write it as if it's the only rule.*__________________________
Tool envelopeExactly what it may touch — which data, which systems, which actions. Everything not listed here is prohibited.__________________________
Autonomy levelIntern / Junior / Senior / Principal (see back of page). New agents start at Intern.☐ Intern ☐ Junior ☐ Senior ☐ Principal
Named human ownerOne accountable person — a name, not a team, not a distribution list.__________________________
Prohibited actions (3–5 red lines)Explicit "never" list. Common examples: no outbound email; no credential/secret access; no bulk export or delete; no production writes; no spend without approval.1. ______ 2. ______ 3. ______
Off-spec = incidentConfirm: any action outside the job description above is reported through the same channel as a security event.☐ Acknowledged — reports to: __________
Review / re-certification dateQuarterly re-certification by the named owner.Next review: ____ / ____ / ______

Owner sign-off: Name __________ Signature __________ Date __________


BACK OF PAGE — the autonomy ladder (definitions)

Four levels of *earned* autonomy. Autonomy is granted, not assumed — every new agent starts as an Intern and is promoted only after it demonstrates it can be trusted at the next level (the curriculum's Autonomy Ladder module covers the promotion gates). Higher autonomy requires stronger controls and higher approval authority.

*Framework basis: the four-tier earned-autonomy model in the CSA Agentic Trust Framework (Feb 2026) and the autonomy levels in CSA's "Levels of Autonomy for Agentic AI"; persona/off-spec detection from Cunningham, Agentic Zero Trust v3.0 (May 2026). See Sources.*

LevelWhat it may doHuman involvementWho approves this level
InternRead-only. Access data, analyze, draft, summarize, recommend — but cannot change any external system. Worst case is a bad suggestion.Human does every action the agent proposes.Business owner
JuniorRecommend specific actions with reasoning; a human clicks "approve" before anything executes.Explicit human approval on every action.Owner + IT/security sign-off
SeniorExecute within defined guardrails and notify a human of what it did and why (real-time).Oversight after the fact; humans spot-check.Formal review (owner + security + a manager)
PrincipalBroad autonomy within its envelope; continuous validation instead of per-action approval.Continuous monitoring; humans intervene by exception.Executive authorization + documented risk acceptance

Rule of thumb: if you can't name the person who would be paged when this agent does something wrong, it is not ready to be anything above Intern.


WORKED EXAMPLE (so anyone can fill it in) — "ChatGPT Team, marketing use"

FieldExample entry
Agent name & vendorChatGPT Team (OpenAI)
Agent identity (non-human)☑ Shared Team workspace login via SSO — no per-agent machine identity. *Acceptable for a read-only Intern; revisit before it's given any tool/system access.*
Job description (persona)*Drafts and edits marketing copy from material our team provides; it does not touch customer data or company systems.*
Tool envelopeText the marketing team pastes in; web browsing for public research. No file connectors, no CRM, no email, no code execution.
Autonomy level☑ Intern (read/draft only — a person publishes everything)
Named human ownerDana Reyes, Marketing Manager
Prohibited actions1. No pasting customer PII or non-public financials. 2. No connecting company drives/CRM. 3. No sending anything externally.
Off-spec = incident☑ Acknowledged — reports to: IT helpdesk / security@ourco
Review dateQuarterly — next: 01 / 15 / 2027

*Second example to try on your own: Microsoft Copilot (Junior — proposes actions in email/docs, human approves) and a Salesforce agent (map its exact object/field permissions into the tool envelope).*


How this connects to the rest of SanctumShield

Guardrails honored

Sources

© PIGENAI LLC · SanctumShield · sanctumshield.com · This is an educational template, not legal advice or a compliance certification.