Webinar
From Foundation to Guardrails: Writing AI Governance Policies
Thursday, October 1, 2026 | 8:00am – 8:45am PT
Session 1 covered who your users and agents are. This one covers what they can reach.
- Network, filesystem, and MCP policies, and how to set up each one
- Org vs team scope, and reading the audit log after a denial
- A live tour of Docker Sandboxes running an agent under real policy
What we’ll cover:
- The three control surfaces. Network, filesystem, and MCP. What each one governs, what a rule looks like, and which to reach for first.
- Setting them up. Allow and deny by domain, IP, or CIDR. Mount rules per path, read-only or read-write. Org scope versus team scope, and what happens when they disagree.
- Reading the audit log. Every policy decision gets recorded. We will trigger a denial live and then go find it.
- Best Practices. How to avoid the first-week mistakes, like blocking the package registry your agent needs, or a read-only mount that quietly breaks builds.
- Docker Sandboxes. Agents run in dedicated microVMs with their own kernel, filesystem, network stack, and private Docker daemon.
Register Now!
New to the series?
Thanks for registering for our webinar. You will receive a confirmation email shortly.