The Agent Guardrails profile allows you to regulate and control the actions of an agent when accessing SaaS apps. You can configure profiles and then use them in Real-time Protection policies to prevent the agent from taking unintended actions.
To create an Agent Guardrails profile:
-
Go to Policies > Profiles > Agent Guardrails and click New.

-
Enter a Name and Description.
-
Predefined Categories: Depending on the policies in your organization, you can choose to restrict agents actions based on these category types: Intent, Access, and Risk Level.
Intent
Select the intent of the action the agent tries to perform:
-
Cost Exposure: Focuses on actions that could lead to excessive credit/cost consumption, like requesting extremely long outputs, or complex recursive tasks that drive up operational costs.
-
Source Code Changes: Monitors actions that attempt to write, modify, or delete underlying application code that could lead to software vulnerabilities.
-
Infra Updates: Flags attempts to influence the backend infrastructure, server settings, or deploy environments through natural language commands.
-
External Communications: Targets prompts that try to force the AI app to send emails, make API calls to unauthorized 3rd-parties, or leak data to external webhooks.
Access
Select the type of access you want Netskope to perform when detecting content in a prompt or response:
-
Intrusive: Categorizes prompts that actively seek to breach data privacy, access restricted databases, or probe the system’s memory for sensitive information.
-
Non-intrusive: Covers standard user interactions that do not attempt to bypass permissions or access restricted layers of the system architecture.
Risk Level
Select the type of risk level of the action that the agent tries to perform:
-
-
Click Create.
-
The View Pending Changes page opens. Review all pending profile changes, and then click Apply Changes.




