Skip to main content

Tasks

Tasks

Step-by-step instructions for common jobs. For background on how a feature works before you configure it, see Concepts.

๐Ÿ› 
Connecting AI Tools
Connect Claude Code, Claude Desktop, Cursor, OpenAI Codex, or GitHub Copilot through AIControls.
Read more โ†’
๐Ÿ”Œ
Configure an Upstream
Add and route to an LLM provider.
Read more โ†’
๐Ÿ“œ
Write a Policy
Author a CEL policy that matches tool calls or LLM requests.
Read more โ†’
๐Ÿ“ฆ
Install a Policy Pack
Install a curated set of policies for anomaly detection, egress, approvals, content safety, cost, model access, or MCP tool access.
Read more โ†’
๐ŸŽš
Assign Autonomy Tiers
Set an agent's T1โ€“T4 autonomy tier from the UI or the API.
Read more โ†’
๐Ÿ’ฐ
Cost Governance
Set a budget and reduce spend with context optimization.
Read more โ†’
๐Ÿ›ก
Security & Compliance
Tune detection thresholds, set up the Shadow AI browser extension, govern skill risk, and generate a compliance report.
Read more โ†’
๐Ÿ“
Validate LLM Responses
Write a response-phase policy to scan or block outbound LLM and MCP tool text, including streaming replies.
Read more โ†’
๐ŸŒ
Restrict Network Egress
Limit which domains MCP tool traffic may reach, with scoped rules and exceptions.
Read more โ†’
โœ…
Approve or Deny a Request
Decide on exception, model-access, and budget top-up requests, including multi-approver co-sign, and revoke a grant.
Read more โ†’
๐Ÿ’ฌ
Request an Exception Inline
Ask for a time-boxed exception without leaving your AI tool โ€” reply to the denial, use a governance tool, or run /request-exception.
Read more โ†’
๐Ÿ”“
Request a Config-Target Exception
Request and approve a time-bounded exception against a budget cap or an egress allowlist.
Read more โ†’
๐Ÿงฉ
Connect an MCP Server
Register and authenticate an MCP server with AIControls.
Read more โ†’
๐Ÿ›ก๏ธ
Enable Network Egress Filtering
Generate a CA, configure the egress proxy, and write your first egress policy.
Read more โ†’
๐Ÿ›ฐ
Enable Runtime Guard
Install the Kyverno runtime sensor, turn on kernel-level observation, and verify coverage. Self-hosted Kubernetes only.
Read more โ†’
๐Ÿ”
Admin Console SSO
Turn on admin console sign-in through the same identity provider you already use for the developer portal and AI clients.
Read more โ†’
๐Ÿชช
Link Your Enterprise Identity
Enable Cross-App Access for PAT-authenticated tools like Claude Code.
Read more โ†’
๐Ÿ—๏ธ
Create a Team Access Binding
Map an IdP team to one or more MCP servers.
Read more โ†’
๐Ÿงฐ
Control MCP Tool Access
Grant or deny individual tools per team, user, or agent โ€” with conditions and default-deny.
Read more โ†’
๐Ÿงฉ
Manage Toolsets
Curate reusable tool sets across servers and attach them to bindings.
Read more โ†’
โฑ๏ธ
Rate-Limit MCP Tools
Cap tool call rates per user, agent, or team โ€” deny or warn on exceed.
Read more โ†’
๐Ÿ”—
Integrations
Configure webhook, Slack, Teams, S3 export, or Okta agent setup.
Read more โ†’
๐Ÿ“ก
Export Traces
Push LLM and tool-call traces to Langfuse, Jaeger, or Tempo.
Read more โ†’
๐Ÿง‘โ€๐Ÿ’ป
Manage Builder Portal Access
Control what developers can see and do in their own portal.
Read more โ†’
๐Ÿ“ˆ
Configure GitHub Delivery Attribution
Connect GitHub so AIControls can ingest pull requests for the Outcomes dashboard.
Read more โ†’