Register policy enforcement points
Register a Policy Enforcement Point (PEP) to enforce security policies for an AI agent. The PEP acts as the enforcement layer for agent traffic and actions, ensuring that the agents operate within their defined security, access, and communication policies.
Add enforcement point to an agent
In the AI Trust Manager menu, select Overview > Discovery > Network PEPs.
Select an agent from the list of discovered agents and select Register PEP under the Actions column.
Select a Verified cloud principal and then select Register Network PEP.
Select the Cloud platform where the agent or associated resources are hosted, such as AWS or GCP.
Specify the Principal (identity or entity) associated with the PEP for agent communications.
Define Scope, the environments to which the PEP applies.
Specify the following optional Advanced settings for the PEP and its network connectivity:
Attribution mode: how network traffic is attributed to the PEP.
Region: the cloud region where the PEP is deployed.
VPC ID: the VPC associated with the PEP.
Proxy endpoint: endpoint used by the PEP to proxy agent traffic.
Subnet IDs: comma-separated subnet IDs that the PEP can observe.
Locked subnet IDs: comma-separated subnet IDs pinned to this PEP. Traffic from these subnets is attributed only to this PEP.
Proxy NLB security group ID: the security group ID associated with the proxy Network Load Balancer (NLB).
Proxy client CIDR: the CIDR range allowed to connect to the proxy.
After providing all the required details for the PEP, select Register.
The verified cloud principal is successfully registered and associated with this network scope. It is now authorized to enforce the configured security policies for AI agents within the scope.
What happens next
The agent is ready to receive a security passport: