Every company running AI agents eventually needs written policies: what agents may do, who approves what, how data is handled, what happens in an incident. Writing them from scratch takes weeks and usually misses something. Here is what a complete policy pack actually contains.
The six policies every agent program needs¶
1. Data-handling policy. What data each agent may access, how PII is treated, retention rules, and where data may not go (personal accounts, unvetted third parties). This is the policy auditors ask for first.
2. Human-in-the-loop policy. Which actions need human approval, which can run freely, and who the approvers are. Tier it by blast radius: read-only actions flow freely; money, data deletion, and external messages need a gate.
3. Credential-handling policy. How API keys and secrets reach agents, rotation schedules, and what happens on suspected leak. One leaked key with broad scope is the most common agent incident pattern.
4. Tool-permission policy. Which tools each agent tier may use, how new tool grants get approved, and the ban on agents granting themselves permissions.
5. External-outreach policy. Rules for agents that contact customers, post publicly, or message third parties: approval chains, content boundaries, and disclosure that the sender is AI.
6. Exception policy. How to request a temporary exception (a grant extension, a tier re-classification, an emergency override) — with expiry dates, so exceptions don't become permanent.
Don't write them from scratch¶
Each of these exists as a complete, ready-to-adopt template: the Data-Handling Policy Template Pack ($19), Human-in-the-Loop Policy One-Pager ($19), Credential Handling Policy One-Pager ($19), Tool-Permission Inventory Checklist ($19), and Incident Communication Template Pack ($19). Or get the full governance system in the Studio Edition ($29).