Not every agent needs every tool.
Explicit allow and block rules keyed on connectors, agents, or a single tool, evaluated before a call reaches the upstream connector, under an org posture of default allow or default deny.
Decided before the call leaves.
Governance runs first, ahead of guardrails and anomaly detection. A rule targets connectors, agents, or both, with an optional tool filter, and precedence runs explicit deny, then explicit allow, then your default posture. Rules sync to every device and every decision is written to the audit log.
Connectors, agents, or one tool
A rule targets named connectors, named agents, or both, and an optional tool filter narrows it to specific tools instead of everything on that connector. Set both connector and agent and the rule applies only where they meet.
Default allow, or default deny
Start permissive, where anything unmatched is allowed unless you block it, or flip the org to default deny and run an explicit allowlist instead.
Deny, then allow, then default
An explicit deny beats an explicit allow, and both beat the default posture. A block is applied before the call reaches the upstream connector, and the denial is recorded.
Org, workspace, or device
Write a rule org-wide, or narrow it to a workspace or a single device. Rules propagate to every device on their own, so there is nothing to redeploy.
Block a tool without leaving the inventory.
Block a whole connector from the Connectors page, or select tools and block them in bulk from the tool list. Each one becomes an ordinary governance rule you can review, edit, or lift later, and every decision it makes lands in the audit log.
One tool, not the whole connector.
Expand a connector to decide tool by tool. Leave the reads allowed, block the destructive ones, and the rest of the connector keeps working. A rule scoped to a single tool is the difference between governing an agent and switching it off.
Decide what your agents can reach.
Join the waitlist to get early access to Ultra's AI-native security and governance.