Skip to content
AvadLabs
Version 1.0 · 2026-10-07

AvadLabs Agent Control Framework

The 12 controls we apply to every agent we put into production. Use them as a checklist for your own projects or to assess any vendor, including us.

Know what exists

Inventory and data: no agent without an owner, no data without a reason.

  1. AC-01

    Agent inventory

    Know which agents exist, who owns them and what they do.

    How we apply it
    • Record of each agent with owner, purpose, model, tools and data accessed
    • Inventory review on every relevant change
    Evidence

    Versioned inventory

  2. AC-12

    Data and retention

    The agent keeps only what is needed, for as long as needed.

    How we apply it
    • Minimization and masking of personal data
    • Defined retention period
    • Legal basis mapped (LGPD, GDPR where applicable)
    Evidence

    Agent data map

Limit what the agent does

Permissions, approval, isolation and secrets.

  1. AC-02

    Least privilege

    The agent accesses only what the process requires.

    How we apply it
    • A dedicated credential per agent, never a person’s
    • Separate read and write scopes
    • Tools enabled through an explicit allow list
    Evidence

    Versioned permission policy

  2. AC-03

    Human approval

    High-value, irreversible or externally visible actions wait for a person.

    How we apply it
    • Limits per action type: amount, recipient and volume
    • Approval queue with decision context
    • Denials recorded with a reason
    Evidence

    Record of approvals and denials

  3. AC-06

    Tool isolation

    A compromised tool cannot reach the rest of the environment.

    How we apply it
    • Isolated execution and restricted network access
    • Parameter validation before execution
    • Tool responses treated as untrusted data
    Evidence

    Architecture diagram and isolation tests

  4. AC-07

    Secrets out of code

    Credentials never appear in code, prompts or logs.

    How we apply it
    • Secret vault or protected variables
    • Periodic rotation
    • Automatic masking in logs
    Evidence

    Secret scanning of repository and logs

Withstand attacks and errors

Prompt injection, costs and unreviewed changes.

  1. AC-05

    Prompt injection defense

    External content never becomes an instruction for the agent.

    How we apply it
    • Separation between instructions and processed data
    • Sensitive tools unavailable while processing untrusted content
    • Adversarial testing before every release
    Evidence

    Adversarial test report

  2. AC-09

    Cost and volume limits

    A mistake never becomes an unexpected bill.

    How we apply it
    • Per-agent budget
    • Call limits per period
    • Alerts and automatic cut-off
    Evidence

    Cost dashboard and alert log

  3. AC-10

    Review before release

    No change goes live without testing and human review.

    How we apply it
    • Separate development, staging and production environments
    • Code and prompt review
    • Passing evaluation as a prerequisite
    Evidence

    Change log with approver

Prove and correct

Audit, continuous evaluation and incident response.

  1. AC-04

    Audit trail

    Reconstruct what the agent saw, decided and did.

    How we apply it
    • Structured log of inputs, tool calls, outputs and decisions
    • Tamper-protected records
    • Defined retention
    Evidence

    Trail lookup per session

  2. AC-08

    Continuous evaluation

    Quality is measured before and after every change.

    How we apply it
    • A suite of real cases with acceptance criteria
    • Runs on every model, prompt or tool change
    • Release blocked when evaluation fails
    Evidence

    Evaluation history

  3. AC-11

    Incident response

    Know how to stop, investigate and fix quickly.

    How we apply it
    • Immediate per-agent kill switch
    • Procedure with severities and response times
    • Post-incident review with recorded actions
    Evidence

    Incident procedure and reports

Want to apply the framework to your agents?

Agent Security Review assesses the agents and copilots you use against these 12 controls and delivers a prioritized remediation plan.

We reply within one business day.