šŸ‘¤
User Request
↓
šŸ¤–
AI Agent
↓
šŸ”Œ
MCP Server
↓
šŸ”§
Tool Execution
↓
šŸ—„ļø
Resource
Guardrail Layers
1
šŸ¢ Organizational Ready
Policies RBAC Approval Flows Audit Logs
2
šŸ¤– Agent Ready
Intent Analysis Prompt Filtering Scope Limits
3
šŸ”§ Tool Ready
Input Validation Sanitization Rate Limiting
4
šŸ”’ Protocol Ready
Authentication Encryption Schema Validation
šŸ¢ Organizational Layer
Purpose
Establishes governance policies, access controls, and approval workflows before requests reach technical systems.
Key Controls
  • Role-based access control (RBAC)
  • Data classification policies
  • Approval workflows for sensitive ops
  • Comprehensive audit logging
Example: Blocked Request
āœ— BLOCKED
User "intern" attempted to access
production database without approval
→ Requires manager approval