1. Separate Governance from Development
The governance team defines policy. The development team consumes it. These are separate roles.
Why: Separation of duties is a compliance requirement (SOC 2, ISO 42001). It also prevents accidental weakening of controls during development.
Related: Governance at Scale
2. Start with OWASP Policy Pack, Then Customize
Don’t author policies from scratch. Start with the pre-built OWASP Agentic Top 10 pack, observe behavior in MONITOR mode, then customize.3. Use FREEZE Rules for Non-Negotiable Safety
FREEZE rules are your last line of defense. Use them for actions that should never happen regardless of policy changes.4. Evaluate Before Every Action
Callengine.evaluate() before the agent executes any action — not after. Governance is pre-execution enforcement.
5. Handle All Decision Types
Your code must handle ALLOW, DENY, PENDING, and MODIFY. Don’t just check for ALLOW.6. Use Signed Bundles in Production
Never load unsigned policy bundles in production. Always verify bundle integrity.7. Register Agent Identities (NHI)
Every agent should have a registered Non-Human Identity with explicit scopes and environment constraints.8. Set Governance-Owned Cost Ceilings
Cost limits should be set by the governance team, not application code. Application code can be MORE restrictive but never LESS.9. Forward Evidence to SIEM
Governance decisions are security events. Forward them to your SIEM for correlation with other security signals.10. Test Policies in CI/CD
Run the policy test harness in your CI pipeline. Governance regressions should fail the build.Anti-Patterns to Avoid
Related Documentation
Governance at Scale
Enterprise operating model
OWASP Policy Pack
Zero-config governance
Configuration Reference
All configuration options
Anti-Patterns
Common mistakes in detail

