グレー
ウェビナー

From Foundation to Guardrails: Writing AI Governance Policies

Thursday, October 1, 2026 | 8:00am – 8:45am PT

Session 1 covered who your users and agents are. This one covers what they can reach.

  • Network, filesystem, and MCP policies, and how to set up each one
  • Org vs team scope, and reading the audit log after a denial
  • A live tour of Docker Sandboxes running an agent under real policy

What we’ll cover:

  • The three control surfaces. Network, filesystem, and MCP. What each one governs, what a rule looks like, and which to reach for first.
  • Setting them up. Allow and deny by domain, IP, or CIDR. Mount rules per path, read-only or read-write. Org scope versus team scope, and what happens when they disagree.
  • Reading the audit log. Every policy decision gets recorded. We will trigger a denial live and then go find it.
  • Best Practices. How to avoid the first-week mistakes, like blocking the package registry your agent needs, or a read-only mount that quietly breaks builds.
  • Docker Sandboxes. Agents run in dedicated microVMs with their own kernel, filesystem, network stack, and private Docker daemon.

今すぐ登録!

New to the series?

ウェビナーへのご登録ありがとうございます。まもなく確認メールが届きます。