1. Purpose
This standard defines the mandatory operating controls for AI agents, prompts, grounding sources, connectors and generated outputs used by TFG.
2. Risk tiers
Tier
Description
Approval
Low
Internal drafting using non-sensitive approved information; no actions.
Manager / tool owner.
Moderate
Client-facing analysis, retrieval over client content, or automated workflow with reversible internal actions.
Business owner + AI/Product Owner + security/privacy review as applicable.
High
Sensitive data, external actions, regulated or financial decisions, production changes, or material client impact.
AI Governance Committee, Security/Privacy and senior business owner.
3. Agent register fields
Name, owner, purpose, status and intended users.
Models, hosting region/provider and version-management approach.
Sources, classification, legal/contractual permission and retention.
Identity, permissions, connectors, tools and external actions.
Evaluation results, known limitations and human approval points.
Logging, incident route, kill switch, recovery and retirement plan.
4. Prompt controls
System prompts and templates are version-controlled and access-restricted.
Prompts must not request or expose information outside the user’s authorised scope.
Sensitive values, secrets and credentials must use approved secret stores, never prompt text.
Prompt injection and malicious-source tests are required for agents using external or user-supplied content.
Outputs must distinguish evidence, inference and recommendation where the use case requires it.
5. Knowledge and retrieval controls
Source ownership and permission are confirmed before ingestion or connection.
Source freshness, quality, duplication and withdrawal routes are defined.
Security trimming must preserve source permissions where supported.
Cross-client content is separated through appropriate technical and logical controls.
Index, cache and derived-output deletion must follow the approved retention route.
6. Evaluation
Accuracy and groundedness against approved test cases.
Citation/source traceability and refusal when evidence is insufficient.
Privacy, confidentiality, prompt injection and data-exfiltration testing.
Bias, harmful output and brand/regulatory suitability where relevant.
Tool/action safety, authorisation, confirmation and rollback.
Regression testing after material model, prompt, source, connector or permissions change.
7. Deployment gate
A moderate or high-risk agent cannot move to live status until ownership, data permissions, security/privacy review, evaluation, logging, human oversight, support, incident handling and retirement controls are documented and approved.
8. Operational monitoring
Owners review usage, errors, access, source freshness, incidents, user feedback, model/provider change and risk at a frequency proportionate to the tier. Material change triggers reassessment.