Understand local agent context.
Review supported local AI agents and MCP context alongside covered AI traffic on managed devices.
Local agent visibility is available in selected rollouts. Inventory does not establish control over every tool action.
Check content at an agent checkpoint you control, then enforce the result in your application.
You choose the checkpoint. Your integration enforces.
Draft a reply to alex.morgan@example.invalid about account SAMPLE-104.
The example policy flags customer information in this text.
Your application keeps this text from the model. It can use a validated redacted version if configured.
Policy violation selected. Aona check: reject. Your application: Stop the model call.
Where Aona fits
Choose visibility on a managed device, evaluation inside your application, or both where supported.
Review supported local AI agents and MCP context alongside covered AI traffic on managed devices.
Local agent visibility is available in selected rollouts. Inventory does not establish control over every tool action.
Submit text to a framework or guardrail evaluation, or supported files to a framework evaluation.
Your application applies the verdict, returned redaction and failure policy. Calls outside the integration are outside that checkpoint.
Draft reply to [CUSTOMER] about account [ACCOUNT].
A reviewer makes the decision in your application.
Build around the checkpoint
Give the reviewer the target, proposed change and evidence for consequential decisions.
Your application owns permissions, approval and execution.
Give the agent only the tools, identity and access needed for its task. Enforce those limits in trusted systems.
For consequential actions, show a person the proposed target, action and evidence before approval.
Check generated outputs and actual system state before treating the task as complete. Preserve useful evidence.
Evaluation and evidence
A verdict describes the evaluation. It does not prove that a request was stopped, a tool was restricted or a person approved an action.
Stateless evaluations do not automatically create analytics events. Record the action your integration took, and keep evaluation APIs distinct from APIs that retrieve existing events.
Understand event APIs and webhooksTake it into your evaluation
Use these questions with your security team or an AI vendor. A “yes” on a feature list is only the start.
Which user, app, agent and input path does this control cover?
What risk and policy does the check address?
What happens when the check allows, rejects, times out or fails?
Who applies the decision, and can another path bypass it?
Where is data processed, stored and retained?
What evidence records the action actually taken?
Which allowed, prohibited and ambiguous examples will we test?
Questions
Walk through the content, evaluation and response your integration needs.