Define a security policy
Security policies in DigiCert® AI Trust Manager govern agent behavior, access, and interactions across your environment. Define rules that control what agents are allowed to do, which resources they can access, and how they can communicate with other systems. Apply policies consistently to enforce security requirements, prevent unauthorized actions, and maintain control over agent operations.
The Policies page lets you create and manage policies that define how AI agents are authorized, constrained, and audited within the environment. Policies help enforce approved behaviors and provide governance over agent activity.
Create a policy
In the AI Trust Manager main menu, select Governance > Policies > Create policy.
Fill in the information to configure policy behavior:
Enter a unique Name that identifies the policy.
Select a policy Type:
Authorization: Defines what an agent is allowed or denied to do, such as accessing resources, invoking tools, or communicating with other agents or services.
Constraint: Defines conditions and limits that an agent must follow, such as restricting actions based on environment, resource, network, or other security conditions.
Audit: Defines what agent activities should be recorded and monitored for
Set the Priority in which the policy is selected when multiple policies apply.
Provide a brief Descriptionof the policy's purpose and the behavior it governs.
Specify the Agent types to which the policy applies.
Specify the Namespaces in which the policy applies.
Enter the Policy Rego definition that specifies the conditions, rules, and enforcement logic for the policy.
Select Create policy.