Local demonstration · Illustrative code
AI Agent Action Policy Demo
This example makes allow/block decisions from tool arguments. It performs no tool execution, network request or system change.
Try the example
Download the JavaScript example, then run it locally with Node.js:
node demo-action-policy.mjs
| Request | Sample decision |
|---|---|
| Export 20 records to internal-reporting | Allow |
| Export 20 records to external-upload | Block |
| Refund EUR 12 | Allow |
| Refund EUR 120 | Block |
The code rejects unknown tools, malformed counts and out-of-policy arguments. The supplied values are examples, not recommended limits for a real business.
What a production implementation still needs
Authenticated identities, resource-level authorisation, approval binding, validated tool execution, an unbypassable enforcement boundary, dependency failure handling and evidence controls are outside this example.
An argument check alone is not an AI security platform. Integration must be verified against the actual runtime, tool and access model.