Microsoft Agent Governance Toolkit (framework self-assessment) v0.1.0
framework-agt · 1 sections
Metadata
Scales, categories & audiences
Scales: maturity5 (5 levels) · Categories: policy identity evidence · Audiences: lead owner exec
Edit these in the raw JSON editor below — they change rarely and carry structure (levels, signals, deep-dive wiring) that a form would mangle.
MS AGT elements core
Everyone answers these. The platform lead who owns the API gateway, the identity administrator, the security lead or vCISO, each agent’s human sponsor, and the governance lead who owns the register and controls library.
| Id | Question | Type | Category | Scale | |
|---|---|---|---|---|---|
| agt-1 | When one of your agents is about to call a tool or send something out, what happens in the moment before it does? Who or what can stop it, and could you show me where that rule is written down? | scored_text · scored | policy | maturity5 | |
| agt-2 | If the thing that checks your agents’ actions crashed or timed out this afternoon, would the agents stop or carry on? And how would you know today if one of them had started up with no rules loaded at all? | scored_text · scored | policy | maturity5 | |
| agt-3 | Which things do your agents have to ask a human before doing? When they ask, what does that person actually see on their screen, and who wrote what they see? | scored_text · scored | policy | maturity5 | |
| agt-4 | If I picked one of your agents at random, could you tell me its name in the directory, who in the business answers for it, and what happens if that person leaves? Has anyone ever switched one off from the directory? | scored_text · scored | identity | maturity5 | |
| agt-5 | Walk me through what happens between your agent asking for a tool and the tool answering. Who decides which tools it may use, and does anything look at what comes back before the agent reads it? | scored_text · scored | identity | maturity5 | |
| agt-6 | If one of your agents started doing something wrong at two in the morning, how would you stop it, how long would it take, and when did you last try? What is the most it could spend or send before anything noticed? | scored_text · scored | identity | maturity5 | |
| agt-7 | Draw me the path a request takes from your agent to the model, and from your agent to a tool. Are they the same path? Is there any way a tool gets called that skips the front door? | scored_text · scored | evidence | maturity5 | |
| agt-8 | What are your developers’ coding assistants allowed to run on their machines, and what stops one from running a script it just downloaded? Could you show me what one of them did yesterday? | scored_text · scored | evidence | maturity5 | |
| agt-9 | Pick any action an agent took last week. Could you show me why it was allowed, which rule said so, and who it was acting for? If someone altered that log, how would you know? | scored_text · scored | evidence | maturity5 |
+ Add question to “MS AGT elements”
Add section
Advanced — raw JSON
Full pack document, validated on save (schema yarn-pack/2). This is where scales, audiences, structured conditions and adaptive config live.