AgentGuard inline tool-call controlEvery integrated agent can call Golem before executing a tool. Policy can allow, block, monitor or require approval.
Exact-call approval bindingHuman approval is cryptographically tied to the exact agent, session, tool, arguments, destination and resource. Change the call and the approval no longer applies.
MCP / tool descriptor integrityGolem fingerprints the trusted tool description and schema, detects descriptor drift / rug-pull behavior and carries the descriptor digest into signed evidence.
Security-graph reachAgent identity and requested resource can be resolved against privileged roles, code execution and DSPM-classified data rather than evaluated as prompt text alone.
Session escalation + kill switchDetects tool switching after a denial and can terminate a session so later evaluations are blocked.
Signed execution evidenceEvery gated call can produce a signed evidence bundle covering decision, policy, approval, argument digest, trusted descriptor digest and execution result.
AI-agent red teamingAuthorized live testing supports static jailbreaks plus adaptive PAIR, Best-of-N and TAP-style attack strategies with judge-model verdicts.
BYO model / data sovereigntyUse Bedrock, Azure OpenAI, Vertex AI, commercial APIs or a local/private model while keeping the platform, policies and security graph customer-controlled.