1. Always Use fail_closed
The engine should DENY on internal errors, not allow ungoverned requests through:2. Sign and Verify Policy Bundles
Never load unsigned bundles in production. Verify Ed25519 signatures on every load:3. Set FREEZE Rules for Critical Safety Controls
FREEZE rules are your non-negotiable safety net. Set them for actions that must never happen:4. Require Agent Attestation
Verify agent identity cryptographically before evaluation:5. Enable Zero Standing Privilege
No agent should hold permanent elevated permissions:6. Bind Governance to Workload Identity
Tie the governance bundle to a specific platform workload identity:7. Monitor Tamper Attempts
Alert onTAMPER_ATTEMPT and FREEZE_TAMPER_ATTEMPT events — these indicate someone is trying to bypass governance:
8. Use Audit Redaction in Production
Never log raw prompts, completions, or PII in production audit trails:9. Enable TealProof for Non-Repudiation
Cryptographic receipts prove governance was enforced at a specific time:10. Restrict Bundle Sources
Only accept policy bundles from approved registries:Security Checklist
Related Documentation
Anti-Tamper Controls
Technical details of tamper prevention
Governance at Scale
Enterprise separation of duties model
NHI Governance
Agent identity and attestation
TealProof
Cryptographic evidence

