Tasks
Step-by-step instructions for common jobs. For background on how a feature works before you configure it, see Concepts.
Connecting AI Tools
Connect Claude Code, Claude Desktop, Cursor, OpenAI Codex, or GitHub Copilot through AIControls.
Read more โ
Configure an Upstream
Add and route to an LLM provider.
Read more โ
Write a Policy
Author a CEL policy that matches tool calls or LLM requests.
Read more โ
Install a Policy Pack
Install a curated set of policies for anomaly detection, egress, approvals, content safety, cost, model access, or MCP tool access.
Read more โ
Assign Autonomy Tiers
Set an agent's T1โT4 autonomy tier from the UI or the API.
Read more โ
Cost Governance
Set a budget and reduce spend with context optimization.
Read more โ
Security & Compliance
Tune detection thresholds, set up the Shadow AI browser extension, govern skill risk, and generate a compliance report.
Read more โ
Validate LLM Responses
Write a response-phase policy to scan or block outbound LLM and MCP tool text, including streaming replies.
Read more โ
Restrict Network Egress
Limit which domains MCP tool traffic may reach, with scoped rules and exceptions.
Read more โ
Approve or Deny a Request
Decide on exception, model-access, and budget top-up requests, including multi-approver co-sign, and revoke a grant.
Read more โ
Request an Exception Inline
Ask for a time-boxed exception without leaving your AI tool โ reply to the denial, use a governance tool, or run /request-exception.
Read more โ
Request a Config-Target Exception
Request and approve a time-bounded exception against a budget cap or an egress allowlist.
Read more โ
Connect an MCP Server
Register and authenticate an MCP server with AIControls.
Read more โ
Enable Network Egress Filtering
Generate a CA, configure the egress proxy, and write your first egress policy.
Read more โ
Enable Runtime Guard
Install the Kyverno runtime sensor, turn on kernel-level observation, and verify coverage. Self-hosted Kubernetes only.
Read more โ
Admin Console SSO
Turn on admin console sign-in through the same identity provider you already use for the developer portal and AI clients.
Read more โ
Link Your Enterprise Identity
Enable Cross-App Access for PAT-authenticated tools like Claude Code.
Read more โ
Create a Team Access Binding
Map an IdP team to one or more MCP servers.
Read more โ
Control MCP Tool Access
Grant or deny individual tools per team, user, or agent โ with conditions and default-deny.
Read more โ
Manage Toolsets
Curate reusable tool sets across servers and attach them to bindings.
Read more โ
Rate-Limit MCP Tools
Cap tool call rates per user, agent, or team โ deny or warn on exceed.
Read more โ
Integrations
Configure webhook, Slack, Teams, S3 export, or Okta agent setup.
Read more โ
Export Traces
Push LLM and tool-call traces to Langfuse, Jaeger, or Tempo.
Read more โ
Manage Builder Portal Access
Control what developers can see and do in their own portal.
Read more โ
Configure GitHub Delivery Attribution
Connect GitHub so AIControls can ingest pull requests for the Outcomes dashboard.
Read more โ