Secure AI Atlas mark Secure AI Atlas SECURITY & GOVERNANCE

Operational boundaries

Controls Catalogue

Control patterns that turn AI use into observable work: owners, boundaries, approvals, logs, exceptions, and evidence.

Input and Output Validation for AI Agent Components

Validate inputs to and outputs from AI agent tool calls, plugins, and retrieval pipelines to prevent injection attacks from crossing trust boundaries.

validationagentsinjection preventionMCP

Off-Agent Authorization for Tool Calls

A control pattern that enforces identity-bound authorization and policy decisions outside the agent runtime before tool calls execute.

authorizationaccess controlagentsMCPprompt injectiontool invocation

Approved AI Tool Register

A maintained record of approved AI tools, allowed use cases, owners, data limits, account requirements, and review status.

inventorygovernanceshadow AI

Data Classification Before AI Use

Classifying data before AI use defines what may be shared, transformed, summarized, retained, or logged.

data securityclassificationprivacy

Prompt and Output Logging

Prompt and output logging preserves enough interaction evidence to support review, monitoring, audit, and incident response.

loggingmonitoringaudit