Insights

AI Governance

A Starter Kit for Agents Already in the Building

Founders already have agents running. The first move is smaller than a platform: inventory, ownership, decision records, a defensive tabletop, inbox hygiene, and a privilege matrix before anything acts in production. Six public Grok Bots are that kit.

September 15, 2026 · 7 min read

A Starter Kit for Agents Already in the Building

Tim Brown, CISO in Residence at Team8, has the cleanest line I know on this. It is easy to build a guardrail that is one hundred percent effective: unplug the agent and throw it in the ocean. Perfectly safe. Also useless. The hard part is the guardrail that keeps the utility and cuts the blast radius. Most teams have not built that part yet.

The field already told you where the fire is. Team8 asked 111 security executives at its latest CISO Village Summit: 97 percent had begun adopting AI agents, 80 percent were running them in production, and average confidence in securing them sat at 2.32 out of 5. That gap is not a missing dashboard. It is agents that plan, call tools, and act on production, that nobody inventoried.

Last Tuesday someone on your team wired a coding assistant into a repo that can see production data. It did not go through procurement, because nobody procured it. You cannot write an enforceable policy for an agent you have not named, and you cannot grant privilege you have not scoped. The failure mode is a missing record. A missing record is fixed with an artifact, not a subscription.

I published six public Grok Bot templates that walk that artifact. Import them. They do not connect to your production systems. They will not approve an agent. They are a starter kit: inventory, ownership, a board page, a decision log, a defensive tabletop, inbox hygiene, and a privilege matrix before anything acts. They are also in the Grok Bot Sharing Contest if you want to clone them from that thread. The useful part is still the work, not the contest.

Artifact over platform

Walk an expo floor and the answer on offer is a suite. Buy the agent-security platform, route everything through it, trust the dashboard. There is a place for that later. It is the wrong first move, because no purchase does the inventory for you.

The first move is smaller. Name what is already running. Name who owns it. Write down what it may do, by reversibility. Write the line it cannot cross alone. Keep a record of decisions, including where an agent may act unattended. Run a tabletop on prompt injection before you ship. Keep the inbox from eating the week you need for the rest.

The paper version of the privilege row lives in the AI Governance Toolkit. CC BY 4.0. Copy it, delete what does not apply. The Bots ask the same questions in order.

Six templates you can import

Each one is a public recipe. Anyone with the share link can read the configuration. Do not paste customer names, tokens, or internal URLs into them.

Agent Governance Officer

Agent Governance Officer walks the privilege matrix before an agent runs in production. Identity with a named owner. Highest data class. Allowed actions by reversibility. The exact HITL line. A tested stop. Then the sandbox as a trust boundary (filesystem, network, inherited credentials), not a scratch directory. Then how allow or deny happens on the next tool call, and where that decision is logged.

Use it when you are about to give an agent a token, or when you already did and never wrote the row down. I unpacked the row at length in Name the Agent Before It Calls a Tool. The Bot is the walkthrough.

Shadow IT Agent Finder

Shadow IT Agent Finder is the inventory pass. Undeclared coding assistants, Slack bots, automations, browser agents. You describe what you actually see on laptops and in channels. It turns blanks into ranked exposure: named versus unnamed, data class, whether a human owns it, whether it can act.

Use it before you buy anything, and before you write policy. Policy assumes a subject. This Bot hunts for subjects. The rows you cannot complete are the list of agents you should not pretend you govern.

Board AI Risk One-Pager

Board AI Risk One-Pager takes five questions and returns one page a CEO can walk into a board meeting with: situation, risk, ownership gaps, and a 30/60/90. Vague AI worry is not a board artifact. A named gap with an owner and a date is.

Use it the week before a board or a buyer security review, when someone asks "who owns the agent" and the honest answer is still nobody. The page is a starting note, not a risk register and not legal advice.

Meeting Decision Log

Meeting Decision Log turns notes or a transcript into decisions, owners, risks, and where an AI agent may act without a human. Unattended versus HITL is the column most meeting notes skip. If the room agreed the agent could close tickets overnight, that is authority. If nobody said it, the Bot should not invent it.

Use it after a product, security, or ops meeting where agents were in the room, even as a side comment. The log is the record. The missing HITL line is the finding.

Prompt Injection Tabletop

Prompt Injection Tabletop is defensive only. It maps blast radius, walks scenarios against your agent, and leaves a shipping checklist. No exploit steps. No payloads. No attack tooling. If a tool call can reach production data or send external mail, the tabletop should say so in plain language before you ship.

Use it before an agentic feature hits a customer, or after someone says "the model is aligned" as if that were a wall. Prompt is not a wall. The checklist is what you can actually test.

Fractional Inbox Triage

Fractional Inbox Triage is the unglamorous one, and it belongs in the kit. Vendor pitches get a polite decline. Roles below Director get a decline. Director and above, personal, and internal threads get flagged for a human. The point is not to automate judgment. The point is to stop the inbox from consuming the hours you need to fill the matrix.

Use it when the calendar is already full and the agents are still unnamed. Governance work dies in the same place every other priority dies: under a pile of mail nobody should have answered.

How to run them this week

Start with Shadow IT Agent Finder. You cannot govern a list you do not have. Then Agent Governance Officer on the two or three agents that can actually write or send. Then Meeting Decision Log on the last working session, so authority stops living in Slack. Board One-Pager if a review is on the calendar. Tabletop before anything customer-facing ships. Inbox triage so the rest of that sequence has a chance.

Do not paste secrets. Do not treat a filled row as a certificate. Do not skip the tested stop. If you cannot name how you halt the agent, it is not governed yet.

What this is not

This pack is not a platform, not a pentest, not a substitute for counsel, a BAA, or a security review. It will not watch production for you. The AI Governance Toolkit is still the paper you can fork. The Bots are how you fill the first page without staring at a blank table.

If you sell a live product whose deal stalls when procurement asks who owns security, this is the conversation they are already having. A named inventory plus a runtime decision log ends it faster than a policy binder. If you want help fitting that row to a product in public safety tech, fintech, or healthcare, that is the work.