Agent Governance Toolkit

Rencore Agent Governance Toolkit monitors agent guardrail activity across 12 policies, 5 reports, and 9 inventories, detecting prompt injection, MCP tool poisoning, blocked tool calls, and policy deny spikes automatically.

Published For Head of IT, CISO, M365 Product Owner
AI & Agents
Definition

The Rencore Agent Governance Toolkit is a set of 12 policies, 5 reports, and 9 inventories that continuously audit agent guardrail activity for prompt injection, MCP tool poisoning, content violations, and blocked tool calls. It surfaces policy deny decisions, agent denial spikes, identity rejections, and escalation requests from the recent lookback window, and flags policies bound to no agents.

See Agent Governance Toolkit in Rencore

Step 1 of 3

33 governance capabilities: 9 inventories · 12 policies · 5 reports · 6 segments

Why govern Agent Governance Toolkit with Rencore

Monitor agent guardrail decisions

Track policy deny decisions, blocked tool calls, and agent denial spikes as they happen. Reports break decisions down by outcome and rank the top agents by deny decisions.

Detect agent attacks and violations

Surface prompt injection, MCP tool poisoning, and content violations detected in the last 24 hours so a compromised or misbehaving agent is caught early.

Govern agent identity and escalations

Flag identity rejections and escalation requests, and review identity rejections grouped by agent to see which agents are pushing against their guardrails.

Audit policy coverage

Find policies bound to no agents, agents that have hit a guardrail, and high-volume agents in the lookback window so guardrail coverage matches real activity.

What Rencore discovers

Rencore automatically inventories these Agent Governance Toolkit object types.

AGT Agent
Distinct agent DIDs observed in the Agent Governance Toolkit governance-event stream
AGT Policy
Distinct policy_name values observed in the AGT governance-event stream
AGT Policy Decision
Governance events where the AGT policy engine emitted an allow / deny / escalate / warn decision
AGT Tool Call Blocked
Governance events where AGT prevented a tool call before it executed
AGT Prompt Injection
Governance events flagged as prompt-injection attempts
AGT Identity Event
Governance events where AGT verified or rejected an agent identity assertion
Agent Governance Toolkit inventory card in Rencore

How the Agent Governance Toolkit works in Rencore

Rencore inventories agents, policies, policy decisions, blocked tool calls, prompt injection events, identity events, MCP tool poisoning events, content violations, and escalations from the toolkit. Policies evaluate this guardrail activity on every scan cycle and flag violations with severity and a recommended action.

The runtime agent risk challenge

Lifecycle and inventory controls show which agents exist, but they do not show how those agents behave once they run. Prompt injection, poisoned tool calls, and content violations happen at runtime and leave the picture incomplete without guardrail telemetry. The Agent Governance Toolkit brings that runtime activity into the same dashboard as the rest of your agent governance.

Who uses the Agent Governance Toolkit

Heads of IT use it to see which agents are hitting guardrails. CISOs rely on the prompt injection, tool poisoning, and content violation policies to catch agent attacks early. M365 product owners use the policy-usage reports to confirm guardrails cover the agents that matter.

Getting started

Connect the toolkit to Rencore. All 12 policies activate on the first scan, covering policy decisions, blocked tool calls, prompt injection, and escalations. Reports and segments populate as soon as the first inventory completes.

Policies

12 governance rules that detect violations and risks.

Agent Governance Toolkit policies card in Rencore
Prompt injection detected in last 24h
Detects PROMPT_INJECTION_DETECTED audit events emitted by AGT in the last 24 hours.
High Security
Content violation detected in last 24h
Detects CONTENT_VIOLATION audit events emitted in the last 24 hours.
High Security
MCP tool poisoning detected in last 24h
Detects MCP_TOOL_POISONING audit events raised by the AGT MCP Security Gateway in the last 24 hours.
High Security
Identity rejection in last 24h
Detects IDENTITY_REJECTED audit events in the last 24 hours.
High Security
Policy deny decision in last 24h
Surfaces policy_decision = deny rows from the AGT audit stream within the last day.
Medium Security
Agent denial spike (5+ denies in lookback window)
Detects agents with five or more policy_decision = deny rows within the configured lookback window.
Medium Security

Need a rule that isn't listed? Rencore's Policy Builder lets you create custom policies tailored to your organization.

Reports

5 analytics views and dashboards.

Decisions by outcome
Distribution of decision values (allow / deny / escalate / warn) over the lookback window.
Donut Chart · Operation
Top agents by deny decisions
Agents (by DID) with the most policy_decision = deny rows in the lookback window.
Bar Chart · Security
Blocked tool calls by action
Count of TOOL_CALL_BLOCKED events grouped by action.
Bar Chart · Security
Policy usage
Per-policy decision counts in the lookback window.
Bar Chart · Operation
Identity rejections by agent
Per-agent count of IDENTITY_REJECTED audit events.
Bar Chart · Security
Agent Governance Toolkit reports card in Rencore

Segments

6 data groupings for targeted filtering.

Policy decisions: denyPolicy decisions: warnIdentity rejectionsBlocked tool callsEscalations requestedActive agents

Frequently asked questions

How does Rencore govern AI agents beyond Microsoft Copilot?
Rencore connects to 15+ AI platforms including Claude, OpenAI, Gemini, GitHub Copilot, Cursor, Windsurf, AWS Bedrock, Azure AI Foundry, Glean, and LangDock. Each connector inventories users, workspaces, API keys, and costs with vendor-specific governance policies. Cross-vendor dashboards show total AI spend, access patterns, and policy violations from a single governance console.
What is Rencore governance?
Rencore governance is a SaaS platform that continuously monitors your Microsoft 365 tenant for policy violations, configuration drift, and security risks across SharePoint, Teams, Power Platform, Copilot, and AI Agents. It automates compliance evidence collection, surfaces oversharing and sprawl, and provides actionable remediation workflows, reducing manual audit effort by up to 80%.
How do Rencore policies work?
Rencore ships with hundreds of pre-built policies that detect governance violations across every connector, oversharing, sprawl, cost overruns, security risks, and compliance gaps. Policies run on a continuous schedule, evaluate each discovered object against configurable rules, and flag violations with severity (High, Medium, Low), category, and a recommended action.

Related guides

Trusted by

MAPALBAMVille de LuxembourgWACKERGRUNDFOSAMGENOsramLufthansaThyssenKruppSunrisePattern