Governance by Construction for Generalist Agents

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Shlomov, Segev, Shoham, Iftach, Oved, Alon, Levy, Ido, Marreed, Sami, Ship, Harold, Akrabi, Offer, Zeltyn, Sergey, Yaeli, Avi, Mashkif, Nir
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866911700929740800
author Shlomov, Segev
Shoham, Iftach
Oved, Alon
Levy, Ido
Marreed, Sami
Ship, Harold
Akrabi, Offer
Zeltyn, Sergey
Yaeli, Avi
Mashkif, Nir
author_facet Shlomov, Segev
Shoham, Iftach
Oved, Alon
Levy, Ido
Marreed, Sami
Ship, Harold
Akrabi, Offer
Zeltyn, Sergey
Yaeli, Avi
Mashkif, Nir
contents Enterprise agents are increasingly expected to operate autonomously across tools and interfaces, yet production deployments require governance by construction. Systems must specify which actions are allowed, when human oversight is required, and what information may be exposed, without rebuilding the agent for each domain. This demo presents CUGA's policy system, a modular policy-as-code layer that composes with a generalist LLM agent to deliver predictable, auditable, and compliance-aware behavior in compound workflows without model fine-tuning. We present a runtime governance architecture that enforces policy interventions at every critical stage of execution. Rather than passively constraining behavior, policies intercept the agent at five structural checkpoints: upstream of planning (Intent Guard), within the system prompt to steer reasoning (Playbook), at the tool-call boundary to enforce proper usage (Tool Guide), outside the reasoning loop as a Human-in-the-Loop gate for high-risk actions (Tool Approvals), and at the output stage to filter and structure the final response (Output Formatter). Together, these stages embed governance continuously across the agent's execution pipeline rather than treating it as an afterthought. Using a healthcare scenario and a multi-layered enforcement intervention, the demo shows dynamic playbook injection for structured tool-sequence enforcement, intent guards that block malicious or accidental harmful requests, and human-in-the-loop tool approval checkpoints for potentially destructive actions. The artifact illustrates how typed governance primitives enable faster, safer deployment of enterprise agentic systems while improving policy adherence and execution consistency.
format Preprint
id arxiv_https___arxiv_org_abs_2605_20874
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Governance by Construction for Generalist Agents
Shlomov, Segev
Shoham, Iftach
Oved, Alon
Levy, Ido
Marreed, Sami
Ship, Harold
Akrabi, Offer
Zeltyn, Sergey
Yaeli, Avi
Mashkif, Nir
Artificial Intelligence
Software Engineering
Enterprise agents are increasingly expected to operate autonomously across tools and interfaces, yet production deployments require governance by construction. Systems must specify which actions are allowed, when human oversight is required, and what information may be exposed, without rebuilding the agent for each domain. This demo presents CUGA's policy system, a modular policy-as-code layer that composes with a generalist LLM agent to deliver predictable, auditable, and compliance-aware behavior in compound workflows without model fine-tuning. We present a runtime governance architecture that enforces policy interventions at every critical stage of execution. Rather than passively constraining behavior, policies intercept the agent at five structural checkpoints: upstream of planning (Intent Guard), within the system prompt to steer reasoning (Playbook), at the tool-call boundary to enforce proper usage (Tool Guide), outside the reasoning loop as a Human-in-the-Loop gate for high-risk actions (Tool Approvals), and at the output stage to filter and structure the final response (Output Formatter). Together, these stages embed governance continuously across the agent's execution pipeline rather than treating it as an afterthought. Using a healthcare scenario and a multi-layered enforcement intervention, the demo shows dynamic playbook injection for structured tool-sequence enforcement, intent guards that block malicious or accidental harmful requests, and human-in-the-loop tool approval checkpoints for potentially destructive actions. The artifact illustrates how typed governance primitives enable faster, safer deployment of enterprise agentic systems while improving policy adherence and execution consistency.
title Governance by Construction for Generalist Agents
topic Artificial Intelligence
Software Engineering
url https://arxiv.org/abs/2605.20874