Folder-oriented governance for agentic AI: A policy-as-code pattern for secure enterprise agents
Due to problems and challenges with deploying agentic AI—such as data leakage, prompt injection, hallucination, and uncontrolled tool access and actions—theoretical governance is not practically effective. This study proposes a practical folder-oriented governance pattern for agentic AI using policy-as-code, runtime guardrails, and audit logging. A proof-of-concept SOC prototype was built to test whether explicit folder-level controls can constrain agent behavior while preserving useful automation. Three manual alert scenarios were executed to evaluate policy enforcement, human-review escalation, and runtime traceability. The results show that prohibited actions were blocked, high-risk alerts triggered review, and all steps were logged for inspection. The findings suggest that folder-governed design can provide bounded autonomy and practical accountability for secure enterprise agent deployments.
